From 0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 21:04:39 +0200 Subject: fix(hub): the pepper and a device key take the passphrase, not a token POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key. A refreshed or lifted token could otherwise fetch the pepper, or register a device whose every sign-in carries it. Both callers have just been given the passphrase. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/static/profile-page.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/static/profile-page.js') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js b/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js index 7c36951..1800d72 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/profile-page.js @@ -147,7 +147,8 @@ export function ProfilePage({ user, onLogout }) { // In the desktop application both are kept by its main process, the new // one set aside until the hub has accepted the change. const K = window.MeshBayKeys; - const { pepper, version } = await K.fetchBundlePepper(user.token); + const oldAuthKey = await K.deriveAuthKey(cpOld, user.username); + const { pepper, version } = await K.fetchBundlePepper(user.token, oldAuthKey); const oldKey = await K.sessionBundleKey( cpOld, user.username, user.userId, pepper, version); const newKey = await K.sessionBundleKey( @@ -160,7 +161,6 @@ export function ProfilePage({ user, onLogout }) { bundleKey: oldKey, newBundleKey: newKey, onProgress: setCpProgress, }); - const oldAuthKey = await window.MeshBayKeys.deriveAuthKey(cpOld, user.username); const newAuthKey = await window.MeshBayKeys.deriveAuthKey(cpNew, user.username); resp = await hubFetch('/v1/users/password', { method: 'POST', token: user.token, -- cgit v1.2.3