aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-node/tests/test_device_linking.py
blob: 6d50580053c66c6e2ec025ddf431b64ea0628689 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
"""
One person, several devices on one node.

Identity keys are per node, so a browser and a desktop client are two keys on
one account. Admitting the second must not need an operator — that friction is
what would make "the native client must not prevent web use" fail — and must not
be something the hub or the node itself can do.

The controls, and the tests that hold them:

  * **A key the node already pinned countersigns.** The hub has stored no user
    keys since 2026-08-14, so it cannot produce that signature.
  * **The code is hashed together with the requesting keys**, so the node cannot
    answer an approver with a substituted key: the approver recomputes the hash
    and finds nothing.
  * **Nothing rests on a human comparing digits.** Phase 12.1 dropped that
    ritual as "correct, unusable as the default"; it must not come back here.

Everything below is written as "this does not work".
"""

import base64
import time
from pathlib import Path

import pytest
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey

from conftest import one_root
from meshbay_common.crypto import pk_to_b64
from meshbay_common.device import (
    device_add_transcript,
    device_code_hash,
    device_request_transcript,
)
from meshbay_common.join import ROLE_MEMBER
from meshbay_common.protocol import MNP
from meshbay_node.indexer.group_index import GroupIndex
from meshbay_node.roster import generate_code, normalize_code, open_roster
from meshbay_node.transport.webrtc_server import WebRTCPeerSession

GROUP = "g" * 32
NONCE = b"\x11" * 32


@pytest.fixture
async def roster(tmp_path):
    r = await open_roster(tmp_path)
    yield r
    await r.close()


def _keys():
    sk_ed = Ed25519PrivateKey.generate()
    sk_x = Ed25519PrivateKey.generate()          # stand-in; only its b64 is used
    return sk_ed, pk_to_b64(sk_ed.public_key()), pk_to_b64(sk_x.public_key())


async def _session(tmp_path: Path, roster, user_id: str = "alice"):
    shared = tmp_path / "shared"
    shared.mkdir(exist_ok=True)
    index = GroupIndex(group_id=GROUP, sk_node=Ed25519PrivateKey.generate())

    session = WebRTCPeerSession.__new__(WebRTCPeerSession)
    session._ctx = {
        "roots": one_root(shared), "index": index, "sk_node": index.sk_node,
        "roster": roster, "device_request_ttl": 3600,
        "groups": {GROUP: {"gek": b"\x01" * 32, "index": index,
                           "roots": one_root(shared), "join_policy": "invite"}},
    }
    session._group_id = GROUP
    session._user_id = user_id
    session._username = user_id
    session._pk_user = ""
    session._pinned_pk = ""
    session._uploads = {}
    session._nonce_node = NONCE
    session._remote_ip = ""
    session.sent = []
    session._send = session.sent.append
    session._audit = lambda *a, **k: None
    return session


async def test_device_messages_need_an_authenticated_session(tmp_path, roster):
    """
    Filing a device is not a pre-proof message, and must not become one.

    The pre-proof window exists for what a peer needs *in order to* prove
    possession of the group key, and adding a device is not that: the request is
    countersigned later by a device already pinned, so nothing is lost by
    requiring the caller to finish its own handshake first. Left in the window it
    would be a second thing a hub that forges a JWT could reach.

    Driven through the real dispatcher, because this is a property of the order
    of its branches and of nothing else.
    """
    session = await _session(tmp_path, roster)
    session._user_id = None            # challenged, has not proved anything yet
    _sk, pk_ed, pk_x = _keys()

    for mtype in ("device_add_request", "device_hello", "device_lookup",
                  "device_add", "device_list", "device_revoke"):
        session.sent.clear()
        session._dispatch_message({"type": mtype, "pk_ed25519": pk_ed,
                                   "pk_x25519": pk_x})
        assert _last(session) == {"type": "error",
                                  "detail": "Handshake required"}, mtype


def _last(session):
    return session.sent[-1] if session.sent else {}


async def _file_request(session, sk_new, pk_ed, pk_x, code):
    """A new device asks to be added, signing over its own keys."""
    code_hash = device_code_hash(normalize_code(code), pk_ed, pk_x)
    ts = int(time.time())
    transcript = device_request_transcript(
        node_pk_b64=session._node_pk_b64(), user_id=session._user_id,
        pk_ed25519_b64=pk_ed, pk_x25519_b64=pk_x, code_hash=code_hash,
        nonce_node=NONCE, ts=ts)
    await session._do_device_request({
        "pk_ed25519": pk_ed, "pk_x25519": pk_x, "code_hash": code_hash,
        "ts": ts, "sig": base64.b64encode(sk_new.sign(transcript)).decode(),
    })
    return code_hash


async def _approve(session, sk_signer, pk_ed, pk_x, code_hash=""):
    ts = int(time.time())
    transcript = device_add_transcript(
        node_pk_b64=session._node_pk_b64(), user_id=session._user_id,
        pk_ed25519_b64=pk_ed, pk_x25519_b64=pk_x, nonce_node=NONCE, ts=ts)
    await session._do_device_add({
        "pk_ed25519": pk_ed, "pk_x25519": pk_x, "ts": ts,
        "code_hash": code_hash,
        "sig": base64.b64encode(sk_signer.sign(transcript)).decode(),
    })


async def _match_by_code(session, code):
    """
    What an approving client does: list what is pending and recompute.

    The code never reaches the node. The client hashes it against each
    candidate's keys and keeps the row that matches — so a node offering
    fabricated keys produces no match, having no way to compute a hash over a
    code it does not know.
    """
    await session._do_device_lookup({})
    listed = _last(session)
    if listed.get("type") != MNP.DEVICE_LOOKUP_RESULT:
        return None
    for req in listed.get("requests", []):
        expect = device_code_hash(normalize_code(code), req["pk_ed25519"],
                                  req["pk_x25519"])
        if expect == req["code_hash"]:
            return req
    return None


# ── The happy path, so the refusals mean something ───────────────────────────

async def test_an_existing_device_admits_a_new_one(tmp_path, roster):
    sk_old, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_new, pk_new_ed, pk_new_x = _keys()

    session = await _session(tmp_path, roster)
    code = generate_code()
    await _file_request(session, sk_new, pk_new_ed, pk_new_x, code)
    assert _last(session)["type"] == MNP.DEVICE_REQUEST_ACK

    match = await _match_by_code(session, code)
    assert match is not None, "the approver could not find the pending request"
    assert match["pk_ed25519"] == pk_new_ed

    await _approve(session, sk_old, pk_new_ed, pk_new_x,
                   code_hash=match["code_hash"])

    assert _last(session)["type"] == MNP.DEVICE_ADD_ACK
    devices = await roster.list_devices("alice")
    assert {d["pk_ed25519"] for d in devices} == {pk_old_ed, pk_new_ed}
    added = next(d for d in devices if d["pk_ed25519"] == pk_new_ed)
    assert added["added_by_pk"] == pk_old_ed, "provenance is not recorded"


async def test_both_devices_then_open_the_group(tmp_path, roster):
    """The point of the whole exercise: web and native at the same time."""
    sk_old, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    await roster.set_member(GROUP, "alice", ROLE_MEMBER, "active", "grenet")
    _, pk_new_ed, pk_new_x = _keys()
    await roster.pin_identity("alice", "alice", pk_new_ed, pk_new_x, "device",
                              added_by_pk=pk_old_ed)

    for pk in (pk_old_ed, pk_new_ed):
        assert await roster.find_device("alice", pk) is not None
    assert await roster.is_authorized(GROUP, "alice")


# ── What must not work ───────────────────────────────────────────────────────

async def test_the_request_alone_admits_nothing(tmp_path, roster):
    """Filing is inert. A node that pinned here would let anyone with a hub
    token join any account that has ever used it."""
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_new, pk_new_ed, pk_new_x = _keys()

    session = await _session(tmp_path, roster)
    await _file_request(session, sk_new, pk_new_ed, pk_new_x, generate_code())

    assert await roster.find_device("alice", pk_new_ed) is None
    assert [d["pk_ed25519"] for d in await roster.list_devices("alice")] == \
        [pk_old_ed]


async def test_the_new_device_cannot_approve_itself(tmp_path, roster):
    """
    Otherwise anyone the hub can mint a token for walks in: the request is
    self-signed by construction, so self-approval would be no control at all.
    """
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_new, pk_new_ed, pk_new_x = _keys()

    session = await _session(tmp_path, roster)
    await _file_request(session, sk_new, pk_new_ed, pk_new_x, generate_code())
    await _approve(session, sk_new, pk_new_ed, pk_new_x)

    assert _last(session)["type"] == "error"
    assert await roster.find_device("alice", pk_new_ed) is None


async def test_a_stranger_cannot_approve(tmp_path, roster):
    """A key belonging to somebody else, or to nobody, is not this account's."""
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_bob, pk_bob_ed, pk_bob_x = _keys()
    await roster.pin_identity("bob", "bob", pk_bob_ed, pk_bob_x, "code")
    _, pk_new_ed, pk_new_x = _keys()

    session = await _session(tmp_path, roster)
    await _approve(session, sk_bob, pk_new_ed, pk_new_x)

    assert _last(session)["type"] == "error"
    assert await roster.find_device("alice", pk_new_ed) is None


async def test_a_revoked_device_cannot_admit_its_replacement(tmp_path, roster):
    """
    The lost laptop. Marking rather than deleting is what makes this hold: a
    deleted row is a key the node would pin again on the next device-add.
    """
    sk_lost, pk_lost_ed, pk_lost_x = _keys()
    _, pk_keep_ed, pk_keep_x = _keys()
    await roster.pin_identity("alice", "alice", pk_lost_ed, pk_lost_x, "code")
    await roster.pin_identity("alice", "alice", pk_keep_ed, pk_keep_x, "device")
    await roster.revoke_device("alice", pk_lost_ed)

    _, pk_new_ed, pk_new_x = _keys()
    session = await _session(tmp_path, roster)
    await _approve(session, sk_lost, pk_new_ed, pk_new_x)

    assert _last(session)["type"] == "error"
    assert await roster.find_device("alice", pk_new_ed) is None


async def test_an_account_with_no_device_here_cannot_file(tmp_path, roster):
    """The first device is admitted by an operator's invitation code. Letting
    this path serve that purpose would bypass the roster entirely."""
    sk_new, pk_new_ed, pk_new_x = _keys()
    session = await _session(tmp_path, roster, user_id="nobody")

    await _file_request(session, sk_new, pk_new_ed, pk_new_x, generate_code())

    assert _last(session)["type"] == "error"
    assert "invitation code" in _last(session)["detail"]


async def test_a_signature_by_the_wrong_key_is_not_a_request(tmp_path, roster):
    """Proof of possession: the request must be signed by the keys it presents."""
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_other, _, _ = _keys()
    _, pk_new_ed, pk_new_x = _keys()

    session = await _session(tmp_path, roster)
    await _file_request(session, sk_other, pk_new_ed, pk_new_x, generate_code())

    assert _last(session)["type"] == "error"
    assert "signature" in _last(session)["detail"].lower()


# ── The code binds the keys ──────────────────────────────────────────────────

async def test_the_node_cannot_substitute_the_keys(tmp_path, roster):
    """
    The load-bearing property. The hash covers the code **and** the requesting
    keys, so an approver looking a request up with different keys finds nothing
    — and never signs. This is what replaces "compare these digits".
    """
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_new, pk_new_ed, pk_new_x = _keys()
    _, pk_evil_ed, pk_evil_x = _keys()

    session = await _session(tmp_path, roster)
    code = generate_code()
    await _file_request(session, sk_new, pk_new_ed, pk_new_x, code)

    # A node that answered with keys of its own choosing would have to produce a
    # hash matching sha256(code ‖ those keys) — over a code it never receives.
    forged = device_code_hash(normalize_code(code), pk_evil_ed, pk_evil_x)
    real = (await _match_by_code(session, code))["code_hash"]

    assert forged != real, "substituted keys produced a matching hash"
    # And the client's own matching would reject the substitution outright.
    await session._do_device_lookup({})
    offered = _last(session)["requests"]
    assert all(r["pk_ed25519"] != pk_evil_ed for r in offered)


async def test_a_wrong_code_finds_nothing(tmp_path, roster):
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_new, pk_new_ed, pk_new_x = _keys()

    session = await _session(tmp_path, roster)
    await _file_request(session, sk_new, pk_new_ed, pk_new_x, generate_code())

    assert await _match_by_code(session, generate_code()) is None


async def test_a_code_is_spent_once(tmp_path, roster):
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    sk_new, pk_new_ed, pk_new_x = _keys()

    sk_old_signer, pk_old_ed2, pk_old_x2 = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed2, pk_old_x2, "device")
    session = await _session(tmp_path, roster)
    code = generate_code()
    await _file_request(session, sk_new, pk_new_ed, pk_new_x, code)

    match = await _match_by_code(session, code)
    await _approve(session, sk_old_signer, pk_new_ed, pk_new_x,
                   code_hash=match["code_hash"])
    assert _last(session)["type"] == MNP.DEVICE_ADD_ACK

    # Spent: the same approval cannot be replayed.
    await _approve(session, sk_old_signer, pk_new_ed, pk_new_x,
                   code_hash=match["code_hash"])
    assert _last(session)["type"] == "error"


async def test_another_account_cannot_redeem_your_code(tmp_path, roster):
    """Scoped to the account as well as to the keys."""
    _, pk_a_ed, pk_a_x = _keys()
    await roster.pin_identity("alice", "alice", pk_a_ed, pk_a_x, "code")
    _, pk_b_ed, pk_b_x = _keys()
    await roster.pin_identity("bob", "bob", pk_b_ed, pk_b_x, "code")
    sk_new, pk_new_ed, pk_new_x = _keys()

    alice = await _session(tmp_path, roster, user_id="alice")
    code = generate_code()
    await _file_request(alice, sk_new, pk_new_ed, pk_new_x, code)

    bob = await _session(tmp_path, roster, user_id="bob")

    # Scoped to the account: Bob is not offered Alice's pending request at all,
    # so the code buys him nothing even if he has it.
    assert await _match_by_code(bob, code) is None


async def test_guessing_is_bounded_on_a_connection(tmp_path, roster):
    _, pk_old_ed, pk_old_x = _keys()
    await roster.pin_identity("alice", "alice", pk_old_ed, pk_old_x, "code")
    session = await _session(tmp_path, roster)

    sk_new, pk_new_ed, pk_new_x = _keys()
    for _ in range(8):
        await _file_request(session, sk_new, pk_new_ed, pk_new_x, generate_code())

    assert "Too many device attempts" in _last(session)["detail"]


# ── Limits and revocation ────────────────────────────────────────────────────

async def test_the_device_ceiling_holds(tmp_path, roster):
    """
    A chain of devices inherits the weakness of its weakest ancestor, so the
    answer to "how many" is a ceiling and visibility, not cryptography.
    """
    sk_first, pk_first_ed, pk_first_x = _keys()
    await roster.pin_identity("alice", "alice", pk_first_ed, pk_first_x, "code")
    for _ in range(roster.MAX_DEVICES_PER_USER - 1):
        _, pk_ed, pk_x = _keys()
        await roster.pin_identity("alice", "alice", pk_ed, pk_x, "device")

    session = await _session(tmp_path, roster)
    sk_new, pk_new_ed, pk_new_x = _keys()
    await _file_request(session, sk_new, pk_new_ed, pk_new_x, generate_code())

    assert _last(session)["type"] == "error"
    assert "limit" in _last(session)["detail"]


async def test_your_last_device_cannot_be_revoked(tmp_path, roster):
    """Removing it would need an operator's code to come back, and doing that
    to yourself by accident is not a mistake worth allowing."""
    sk_only, pk_only_ed, pk_only_x = _keys()
    await roster.pin_identity("alice", "alice", pk_only_ed, pk_only_x, "code")
    session = await _session(tmp_path, roster)

    ts = int(time.time())
    transcript = device_add_transcript(
        node_pk_b64=session._node_pk_b64(), user_id="alice",
        pk_ed25519_b64=pk_only_ed, pk_x25519_b64=pk_only_x,
        nonce_node=NONCE, ts=ts)
    await session._do_device_revoke({
        "pk_ed25519": pk_only_ed, "ts": ts,
        "sig": base64.b64encode(sk_only.sign(transcript)).decode()})

    assert _last(session)["type"] == "error"
    assert await roster.find_device("alice", pk_only_ed) is not None


async def test_unpinning_an_account_takes_every_device(tmp_path, roster):
    """`member unpin` is what an operator runs when someone must start over.
    Leaving one device would let them walk back in with a forgotten key."""
    for _ in range(3):
        _, pk_ed, pk_x = _keys()
        await roster.pin_identity("alice", "alice", pk_ed, pk_x, "device")

    assert len(await roster.list_devices("alice")) == 3
    await roster.unpin("alice")
    assert await roster.list_devices("alice") == []