From 6260825bf6d8340549de53905de3bd0b84d97d0a Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Sat, 12 Sep 2026 12:14:15 +0200 Subject: fix(hub): the mail server is not a relay MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The previous commit metered the paths that send mail. It was not enough, and saying it was would have been wrong: a 60-second cooldown per account still allows one stranger a minute — 1440 a day — and registration is open, so "per account" is a bound an attacker buys more of. And there was a third door nobody had counted. POST /v1/users/register an address nobody has verified PATCH /v1/users/me an address nobody has verified, signed in POST /v1/users/password/reset only the address already on file POST /v1/groups/{id}/invite-notify only a registered member's address The widest was the register *resend* branch: no token, no captcha, and the username and address are the caller's own from a moment ago — registering a victim's address once bought the right to mail them at the endpoint's rate limit for as long as the account stayed pending. So the bound moves into `mail.py`, where every message passes one function. `purpose` is keyword-required and checked against a closed list, so a helper that names anything else does not send and one that names nothing is a TypeError rather than an unrestricted send. Under it: - a bound per **recipient**, across every purpose, account and endpoint — what a person being mail-bombed actually experiences, and the only bound that describes it. Keyed on a hash, because this would otherwise be the one place in the hub holding plaintext addresses in memory (S2) - an instance-wide hourly ceiling, which cannot be bought with more accounts - a cooldown on the resend branch, a cooldown and a daily ceiling on the address change, and the IP-log entry that endpoint never wrote — alone among the ones that mail The ceiling on address changes counts IP-log rows, not EmailVerification: the handler deletes this account's unverified rows before writing a new one, so counting those counts one, always. Which is what the first version of it did. Refusals never carry the address: that line goes to the journal. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01T4YmK41VsEURWFdop4EEeT --- packages/meshbay-hub/tests/test_recovery_email.py | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) (limited to 'packages/meshbay-hub/tests/test_recovery_email.py') diff --git a/packages/meshbay-hub/tests/test_recovery_email.py b/packages/meshbay-hub/tests/test_recovery_email.py index e4288a1..c6dab97 100644 --- a/packages/meshbay-hub/tests/test_recovery_email.py +++ b/packages/meshbay-hub/tests/test_recovery_email.py @@ -31,7 +31,12 @@ def _skip_email_verification(monkeypatch): run so the e-mail is actually built. Capture it instead of sending. """ sent = [] - monkeypatch.setattr("meshbay_hub.mail._send", lambda msg: sent.append(msg) or True) + # `**_` swallows the `purpose` keyword `_send` now requires — the gate + # that keeps this hub off the open-relay list. What this module is + # about is the body of the message, so the gate is stubbed away with + # the socket; `test_mail_is_not_a_relay.py` is where it is exercised. + monkeypatch.setattr("meshbay_hub.mail._send", + lambda msg, **_: sent.append(msg) or True) return sent @@ -84,7 +89,7 @@ async def test_the_recovery_key_is_not_persisted( def test_mail_body_with_and_without_the_key(monkeypatch): captured = [] monkeypatch.setattr("meshbay_hub.mail._send", - lambda msg: captured.append(msg) or True) + lambda msg, **_: captured.append(msg) or True) mail.send_verification_code("x@example.com", "123456", recovery_key="MY-RECOVERY-KEY") -- cgit v1.2.3