aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_hub_work_is_bounded.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/tests/test_hub_work_is_bounded.py')
-rw-r--r--packages/meshbay-hub/tests/test_hub_work_is_bounded.py51
1 files changed, 51 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_hub_work_is_bounded.py b/packages/meshbay-hub/tests/test_hub_work_is_bounded.py
new file mode 100644
index 0000000..40ea81d
--- /dev/null
+++ b/packages/meshbay-hub/tests/test_hub_work_is_bounded.py
@@ -0,0 +1,51 @@
+"""
+What an authenticated caller can make the hub do, bounded where it was not.
+
+An offer wrote an IP-log row — kept a year — before any check, for whatever
+string the caller named as a node, and carried an ICE list of any length to the
+node. A node could send `update_groups` as fast as it liked, each one a
+database read, with a list of any length.
+"""
+
+import pytest
+from meshbay_hub.db.models import IPLog
+from sqlalchemy import func, select
+from test_availability_between_members import _make_user
+
+
+def _offer(client, user, node_id, candidates):
+ return client.post(f"/v1/nodes/{node_id}/webrtc/offer",
+ json={"sdp": "v=0\r\n", "ice_candidates": candidates},
+ headers={"Authorization": f"Bearer {user['token']}"})
+
+
+@pytest.mark.asyncio
+async def test_an_offer_that_goes_nowhere_writes_no_log_row(client, db_session):
+ user = await _make_user(client, "offer_nowhere")
+ for i in range(5):
+ r = await _offer(client, user, f"not-a-node-{i}", [])
+ assert r.status_code == 404
+ rows = await db_session.scalar(
+ select(func.count()).select_from(IPLog).where(IPLog.event == "webrtc_offer"))
+ assert rows == 0
+
+
+@pytest.mark.asyncio
+async def test_the_ice_list_is_bounded(client):
+ from meshbay_hub.api.signaling import MAX_ICE_CANDIDATES
+ user = await _make_user(client, "offer_ice")
+ one = {"candidate": "candidate:1 1 udp 2122260223 192.0.2.1 50000 typ host",
+ "sdpMid": "0", "sdpMLineIndex": 0}
+ assert (await _offer(client, user, "nowhere", [one] * MAX_ICE_CANDIDATES)).status_code == 404
+ too_many = [one] * (MAX_ICE_CANDIDATES + 1)
+ assert (await _offer(client, user, "nowhere", too_many)).status_code == 422
+ big = {"candidate": "x" * 40_000}
+ assert (await _offer(client, user, "nowhere", [big])).status_code == 422
+
+
+def test_a_node_reloading_is_budgeted():
+ from meshbay_hub.api.revocation import UPDATE_GROUPS_BURST, _update_budget, _update_window
+ _update_window.clear()
+ assert all(_update_budget("node-a") for _ in range(UPDATE_GROUPS_BURST))
+ assert not _update_budget("node-a")
+ assert _update_budget("node-b"), "one node's budget is not another's"