Close unconfirmed transfer paths and reject binary signalling envelopes
This commit is contained in:
@@ -51,7 +51,7 @@ test('auth on open, hello with opaque peer id, bad secret is closed', async () =
|
||||
expect(hub.isOnline('dev_000000000000000b')).toBe(false);
|
||||
});
|
||||
|
||||
test('signals are relayed between online peers only; close drops presence', async () => {
|
||||
test('legacy unconfirmed signalling is refused; close drops presence', async () => {
|
||||
const hub = createP2pHub({ getDevice: p2pDb.getDevice });
|
||||
const a = fakeWs({ budget: [] });
|
||||
const b = fakeWs({ budget: [] });
|
||||
@@ -60,11 +60,12 @@ test('signals are relayed between online peers only; close drops presence', asyn
|
||||
await hub.websocket.message(a, JSON.stringify({ type: 'auth', device: 'dev_000000000000000a', secret: SECRET_A }));
|
||||
await hub.websocket.message(b, JSON.stringify({ type: 'auth', device: 'dev_000000000000000b', secret: SECRET_B }));
|
||||
await hub.websocket.message(a, JSON.stringify({ type: 'signal', to: b.data.peer, data: { sdp: 'x' } }));
|
||||
expect(b.sent.at(-1)).toEqual({ type: 'signal', from: a.data.peer, data: { sdp: 'x' } });
|
||||
expect(a.sent.at(-1)).toMatchObject({ type: 'error', error: 'use a confirmed direct-transfer invitation' });
|
||||
expect(b.sent.some(m => m.type === 'signal')).toBe(false);
|
||||
hub.websocket.close(b);
|
||||
expect(hub.isOnline('dev_000000000000000b')).toBe(false);
|
||||
await hub.websocket.message(a, JSON.stringify({ type: 'signal', to: b.data.peer, data: {} }));
|
||||
expect(a.sent.at(-1)).toMatchObject({ type: 'error', error: 'peer offline' });
|
||||
expect(a.sent.at(-1)).toMatchObject({ type: 'error', error: 'use a confirmed direct-transfer invitation' });
|
||||
expect(hub.send('dev_000000000000000a', { type: 'ping' })).toBe(true);
|
||||
expect(hub.send('dev_000000000000000b', { type: 'ping' })).toBe(false);
|
||||
});
|
||||
@@ -119,3 +120,10 @@ test('direct directory and invitations are restricted to authorized profile sock
|
||||
await hub.websocket.message(b, JSON.stringify({ type: 'direct', action: 'request', to: peerIdOf('dev_000000000000000a'), id: 'localSong' }));
|
||||
expect(a.sent.at(-1).action).toBe('request');
|
||||
});
|
||||
|
||||
test('binary websocket payloads cannot serve as signalling envelopes', async () => {
|
||||
const hub = createP2pHub({ getDevice: p2pDb.getDevice });
|
||||
const ws = fakeWs({ budget: [] });
|
||||
await hub.websocket.message(ws, Buffer.from(JSON.stringify({ type: 'auth', device: 'dev_000000000000000a', secret: SECRET_A })));
|
||||
expect(ws.sent).toEqual([]); expect(ws.data.authed).not.toBe(true);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user