1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
|
"""
What an authenticated caller can make the hub do, bounded where it was not.
An offer wrote an IP-log row — kept a year — before any check, for whatever
string the caller named as a node, and carried an ICE list of any length to the
node. A node could send `update_groups` as fast as it liked, each one a
database read, with a list of any length.
"""
import pytest
from meshbay_hub.db.models import IPLog
from sqlalchemy import func, select
from test_availability_between_members import _make_user
def _offer(client, user, node_id, candidates):
return client.post(f"/v1/nodes/{node_id}/webrtc/offer",
json={"sdp": "v=0\r\n", "ice_candidates": candidates},
headers={"Authorization": f"Bearer {user['token']}"})
@pytest.mark.asyncio
async def test_an_offer_that_goes_nowhere_writes_no_log_row(client, db_session):
user = await _make_user(client, "offer_nowhere")
for i in range(5):
r = await _offer(client, user, f"not-a-node-{i}", [])
assert r.status_code == 404
rows = await db_session.scalar(
select(func.count()).select_from(IPLog).where(IPLog.event == "webrtc_offer"))
assert rows == 0
@pytest.mark.asyncio
async def test_the_ice_list_is_bounded(client):
from meshbay_hub.api.signaling import MAX_ICE_CANDIDATES
user = await _make_user(client, "offer_ice")
one = {"candidate": "candidate:1 1 udp 2122260223 192.0.2.1 50000 typ host",
"sdpMid": "0", "sdpMLineIndex": 0}
assert (await _offer(client, user, "nowhere", [one] * MAX_ICE_CANDIDATES)).status_code == 404
too_many = [one] * (MAX_ICE_CANDIDATES + 1)
assert (await _offer(client, user, "nowhere", too_many)).status_code == 422
big = {"candidate": "x" * 40_000}
assert (await _offer(client, user, "nowhere", [big])).status_code == 422
def test_a_node_reloading_is_budgeted():
from meshbay_hub.api.revocation import UPDATE_GROUPS_BURST, _update_budget, _update_window
_update_window.clear()
assert all(_update_budget("node-a") for _ in range(UPDATE_GROUPS_BURST))
assert not _update_budget("node-a")
assert _update_budget("node-b"), "one node's budget is not another's"
|