diff options
Diffstat (limited to 'packages/meshbay-node/tests/test_root_writable_policy.py')
| -rw-r--r-- | packages/meshbay-node/tests/test_root_writable_policy.py | 38 |
1 files changed, 5 insertions, 33 deletions
diff --git a/packages/meshbay-node/tests/test_root_writable_policy.py b/packages/meshbay-node/tests/test_root_writable_policy.py index 0cd9af8..0dc5d6d 100644 --- a/packages/meshbay-node/tests/test_root_writable_policy.py +++ b/packages/meshbay-node/tests/test_root_writable_policy.py @@ -12,8 +12,9 @@ The properties this holds: A member with an old tab open, or one speaking MNP directly, gets the same answer. That half is pinned in `test_security_regressions.py`, next to the overwrite properties it belongs with; -* the setting is changed by a **signed** operator instruction, or it is a - suggestion any member can undo; +* the setting is changed **on the node's own machine** — the desktop + application over loopback, or the CLI — and never over MNP, where a signature + proves only that the operator's key signed (`test_sharing_is_local_only.py`); * it is stored on the **node**, never the hub. A hub that could decide who writes to the operator's disk would have authority over the node. @@ -26,7 +27,7 @@ from pathlib import Path import pytest from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey -from meshbay_common.adminop import OP_ROOT_EJECT, OP_ROOT_PLUG, OP_ROOT_UPDATE +from meshbay_common.adminop import OP_ROOT_EJECT, OP_ROOT_PLUG from meshbay_common.crypto import generate_gek from meshbay_common.protocol import MNP from meshbay_node.indexer.group_index import GroupIndex @@ -163,34 +164,6 @@ def _capture_challenges(session) -> list[tuple[str, str]]: return issued -async def test_changing_a_roots_flags_needs_a_signature(tmp_path): - """The flags are not applied by the request — only by the signed response.""" - session = _session(tmp_path, "the-operator", operator="the-operator") - issued = _capture_challenges(session) - - session._do_root_update({"group_id": "g" * 32, "root_name": "shared", - "writable": False}) - - assert [op for op, _ in issued] == [OP_ROOT_UPDATE] - assert session._ctx["roots"].roots[0].writable is True, ( - "applied before it was signed") - - -async def test_the_subject_names_the_outcome_not_the_operation(tmp_path): - """ - The operator is shown the subject before signing, so it has to say what will - be true afterwards. "shared" alone would have them authorize a change they - cannot see the direction of. - """ - session = _session(tmp_path, "op", operator="op") - issued = _capture_challenges(session) - - session._do_root_update({"group_id": "g" * 32, "root_name": "shared", - "writable": True, "removable": True}) - - assert issued == [(OP_ROOT_UPDATE, "shared:rw=on,rem=on")] - - async def test_eject_and_plug_are_signed_too(tmp_path): """ Hiding a group's whole library from every member is not a lesser act than @@ -214,8 +187,7 @@ async def test_a_request_with_nobody_to_authorize_it_is_refused(tmp_path): issued = _capture_challenges(session) session._has_admin_authority = lambda: False - session._do_root_update({"group_id": "g" * 32, "root_name": "shared", - "writable": True}) + session._do_root_eject({"group_id": "g" * 32, "root_name": "shared"}) assert issued == [] assert [m for m in session.sent if m.get("type") == "error"] |