From 0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 21:04:39 +0200 Subject: fix(hub): the pepper and a device key take the passphrase, not a token POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key. A refreshed or lifted token could otherwise fetch the pepper, or register a device whose every sign-in carries it. Both callers have just been given the passphrase. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/static/group-page.js | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/static/group-page.js') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js index 4510848..fe858b2 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js @@ -257,10 +257,11 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs, setError(''); try { // Same derivation as sign-in — the token is already ours, only the key - // that opens node bundles is missing here, and the pepper that goes into - // it is asked for with that token. Persisted so this browser is set up - // from now on. - const { pepper, version } = await window.MeshBayKeys.fetchBundlePepper(token); + // that opens node bundles is missing here. The hub hands the pepper that + // goes into it only against the passphrase proof, never the token alone. + // Persisted so this browser is set up from now on. + const authKey = await window.MeshBayKeys.deriveAuthKey(pass, username); + const { pepper, version } = await window.MeshBayKeys.fetchBundlePepper(token, authKey); session.bundleKey = await window.MeshBayKeys.sessionBundleKey( pass, username, userId, pepper, version); await _storeBundleKey(session.bundleKey); -- cgit v1.2.3