diff options
Diffstat (limited to 'packages/meshbay-hub/tests/test_upload_controls_hidden.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_upload_controls_hidden.py | 30 |
1 files changed, 26 insertions, 4 deletions
diff --git a/packages/meshbay-hub/tests/test_upload_controls_hidden.py b/packages/meshbay-hub/tests/test_upload_controls_hidden.py index 6316e44..947ba75 100644 --- a/packages/meshbay-hub/tests/test_upload_controls_hidden.py +++ b/packages/meshbay-hub/tests/test_upload_controls_hidden.py @@ -231,7 +231,7 @@ def test_the_notice_also_answers_the_operators_own_request(): def test_changing_a_root_is_signed(): transport = transport_source() - for method in ("updateRoot", "ejectRoot", "plugRoot"): + for method in ("ejectRoot", "plugRoot", "removeRoot"): body = transport[transport.index(f"async {method}("):] body = body[:body.index("\n async ", 1)] assert "admin_challenge" in body and "_authorizeAdminOp" in body, ( @@ -261,12 +261,34 @@ def test_the_operator_is_offered_it_on_the_web_too(): "the shared directories section still requires a local node") table = _component(source, "SharedDirectoriesTable") - for call in ("transport.updateRoot", "transport.ejectRoot", - "transport.plugRoot", "transport.removeRoot", - "transport.addRoot"): + for call in ("transport.ejectRoot", "transport.plugRoot", "transport.removeRoot"): assert call in table, f"{call} has no MNP route from the table" +def test_what_widens_the_sharing_never_crosses_mnp(): + """ + Adding a directory and switching `writable` or `removable` are done on the + node's own machine (MNP 6.0). Over MNP they were signed ops, and a signature + proves that the operator's key signed: in a browser that key is driven by + code the hub serves. The list stays visible from anywhere; those controls + are read-only there. + """ + transport = transport_source() + for method in ("addRoot", "updateRoot", "attachGroup"): + assert f"async {method}(" not in transport, f"{method} is an MNP call again" + for mtype in ("'root_add'", "'root_update'", "'group_attach'"): + assert mtype not in transport, f"{mtype} is sent or expected again" + + table = _component(GROUP_SETTINGS.read_text(encoding="utf-8"), + "SharedDirectoriesTable") + assert "platform.node.op('addRoot'" in table + assert "platform.node.op('updateRoot'" in table + assert "const canWiden = isLocal || onNodeMachine;" in table + assert table.count("!canWiden") >= 3, ( + "a writable or removable switch is live where it cannot be honoured") + assert "settings_node.roots_local_only_hint" in table + + def test_the_roots_shown_come_from_the_live_connection_when_there_is_one(): """ The loopback list is a second source, and the two drift: it is read once on |