From 0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 21:04:39 +0200 Subject: fix(hub): the pepper and a device key take the passphrase, not a token POST /me/bundle-pepper (was GET) and POST /users/devices require auth_key. A refreshed or lifted token could otherwise fetch the pepper, or register a device whose every sign-in carries it. Both callers have just been given the passphrase. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/tests/test_password_reset.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-hub/tests/test_password_reset.py') diff --git a/packages/meshbay-hub/tests/test_password_reset.py b/packages/meshbay-hub/tests/test_password_reset.py index b07f77c..f285c1d 100644 --- a/packages/meshbay-hub/tests/test_password_reset.py +++ b/packages/meshbay-hub/tests/test_password_reset.py @@ -159,7 +159,8 @@ async def test_reset_revokes_sessions_and_wipes_devices(client, db_session): sk = Ed25519PrivateKey.generate() dev = await client.post( "/v1/users/devices", - json={"pk_auth_ed25519": pk_to_b64(sk.public_key()), "label": "laptop"}, + json={"pk_auth_ed25519": pk_to_b64(sk.public_key()), "label": "laptop", + "auth_key": "erin_test" + "a" * 40}, headers={"Authorization": f"Bearer {token}"}) assert dev.status_code == 201, dev.text -- cgit v1.2.3