From 0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 21:04:39 +0200 Subject: fix(hub): the pepper and a device key take the passphrase, not a token POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key. A refreshed or lifted token could otherwise fetch the pepper, or register a device whose every sign-in carries it. Both callers have just been given the passphrase. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/tests/test_account_deletion.py | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) (limited to 'packages/meshbay-hub/tests/test_account_deletion.py') diff --git a/packages/meshbay-hub/tests/test_account_deletion.py b/packages/meshbay-hub/tests/test_account_deletion.py index a31aaff..632c133 100644 --- a/packages/meshbay-hub/tests/test_account_deletion.py +++ b/packages/meshbay-hub/tests/test_account_deletion.py @@ -140,7 +140,8 @@ async def test_deletion_clears_device_keys(client, db_session): select(User.id).where(User.username == "devicer_test"))).scalar_one() r = await client.post("/v1/users/devices", headers=headers, - json={"pk_auth_ed25519": _device_pk(), "label": "desktop"}) + json={"pk_auth_ed25519": _device_pk(), "label": "desktop", + "auth_key": _auth_key(password, "devicer_test")}) assert r.status_code == 201, r.text # Present before, or the emptiness asserted below proves nothing. @@ -166,15 +167,19 @@ async def test_a_new_account_can_reuse_the_deleted_accounts_device(client): """ pk = _device_pk() token, password = await _register(client, "firstlife") - r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk}, + r = await client.post("/v1/users/devices", + json={"pk_auth_ed25519": pk, + "auth_key": _auth_key(password, "firstlife")}, headers={"Authorization": f"Bearer {token}"}) assert r.status_code == 201, r.text await client.request("DELETE", "/v1/users/me", headers={"Authorization": f"Bearer {token}"}, json={"auth_key": _auth_key(password, "firstlife")}) - token2, _ = await _register(client, "secondlife") - r = await client.post("/v1/users/devices", json={"pk_auth_ed25519": pk}, + token2, password2 = await _register(client, "secondlife") + r = await client.post("/v1/users/devices", + json={"pk_auth_ed25519": pk, + "auth_key": _auth_key(password2, "secondlife")}, headers={"Authorization": f"Bearer {token2}"}) assert r.status_code == 201, r.text -- cgit v1.2.3