package access import ( "testing" "git.smesh.lol/smesh/pkg/nostr/event" "git.smesh.lol/smesh/pkg/nostr/kind" "git.smesh.lol/smesh/pkg/nostr/tag" ) // accEvent builds a bare event: CanSee only reads Kind, Pubkey and the tag // list, so no signature is needed. func accEvent(k uint16, pub []byte, tags *tag.S) (ev *event.E) { return &event.E{Kind: k, Pubkey: pub, Tags: tags} } func accDash() (s *tag.S) { return tag.NewS(tag.NewFromBytesSlice([]byte("-"))) } // TestIsMLS pins exactly which kinds the relay treats as MLS: the three MLS // kinds plus the gift-wrap that can carry a Welcome. GiftWrapWithKind4 is a // separate kind and must not be swept in. func TestIsMLS(t *testing.T) { // IsMLS compares against kind package pointers; they are nil until // ensureKinds runs. Production callers reach here after Ensure. kind.Ensure() if !IsMLS(443) { t.Fatal("MLSKeyPackage (443) must be MLS") } if !IsMLS(444) { t.Fatal("MLSWelcome (444) must be MLS") } if !IsMLS(445) { t.Fatal("MLSGroupEvent (445) must be MLS") } if !IsMLS(1059) { t.Fatal("GiftWrap (1059) must be MLS") } if IsMLS(1060) { t.Fatal("GiftWrapWithKind4 (1060) must not be MLS") } if IsMLS(1) { t.Fatal("kind 1 must not be MLS") } if IsMLS(0) { t.Fatal("kind 0 must not be MLS") } } // TestCanSeePrivilege covers the privileged-kind gate with every combination of // auth and marmotOpen. Only MLS kinds are exempted by marmotOpen; a privileged // non-MLS kind still requires auth. func TestCanSeePrivilege(t *testing.T) { // Force the kind table before any package pointer is read. kind.Ensure() pk := []byte("authed-pubkey-32-bytes-long-000") evPlain := accEvent(1, pk, nil) evPriv := accEvent(4, pk, nil) // EncryptedDirectMessage evMLS := accEvent(443, pk, nil) // MLSKeyPackage evMLS2 := accEvent(1059, pk, nil) // GiftWrap if !CanSee(false, nil, evPlain, false, false) { t.Fatal("non-privileged event must be visible unauthenticated") } if CanSee(false, nil, evPriv, false, false) { t.Fatal("privileged event must be hidden from an unauthenticated reader") } if !CanSee(true, pk, evPriv, false, false) { t.Fatal("privileged event must be visible to an authenticated reader") } if !CanSee(false, nil, evMLS, false, true) { t.Fatal("MLS kind must pass with marmotOpen") } if CanSee(false, nil, evMLS, false, false) { t.Fatal("MLS kind must be gated when marmotOpen is off") } if !CanSee(false, nil, evMLS2, false, true) { t.Fatal("GiftWrap must pass with marmotOpen") } if CanSee(false, nil, evPriv, false, true) { t.Fatal("marmotOpen must not exempt a non-MLS privileged kind") } } // TestCanSeeNIP70 covers the "-" protected tag: the event reaches only its own // author, and only when authenticated. Every other combination is denied. func TestCanSeeNIP70(t *testing.T) { kind.Ensure() author := []byte("author-pubkey-32-bytes-long-0000") other := []byte("other-pubkey-32-bytes-long-00000") ev := accEvent(1, author, accDash()) evBare := accEvent(1, author, tag.NewS(tag.NewFromBytesSlice([]byte("t"), []byte("x")))) if !CanSee(false, nil, ev, false, false) { t.Fatal("nip70 off must not filter the protected tag") } if CanSee(false, nil, ev, true, false) { t.Fatal("protected event must be hidden from an unauthenticated reader") } if !CanSee(true, author, ev, true, false) { t.Fatal("protected event must reach its authenticated author") } if CanSee(true, other, ev, true, false) { t.Fatal("protected event must not reach a different authenticated pubkey") } if CanSee(true, nil, ev, true, false) { t.Fatal("protected event must not reach an auth with no pubkey") } if !CanSee(false, nil, evBare, true, false) { t.Fatal("a tagless event must pass nip70 filtering") } // Tags present but no "-" tag: still delivered. evNoDash := accEvent(1, author, tag.NewS(tag.NewFromBytesSlice([]byte("e"), []byte("x")))) if !CanSee(false, nil, evNoDash, true, false) { t.Fatal("an event without the '-' tag must pass nip70 filtering") } if !CanSee(false, nil, accEvent(1, author, nil), true, false) { t.Fatal("nil tags must pass nip70 filtering") } } // TestWriteExempt pins the write-auth exemptions: NIP-46 connect only when the // bypass flag is set, and MLS kinds only when marmotOpen. func TestWriteExempt(t *testing.T) { kind.Ensure() if !WriteExempt(24133, true, false) { t.Fatal("NostrConnect must be exempt when nip46BypassAuth is on") } if WriteExempt(24133, false, false) { t.Fatal("NostrConnect must not be exempt when the bypass is off") } if WriteExempt(1, true, false) { t.Fatal("kind 1 must not be exempt via the NIP-46 bypass") } if !WriteExempt(443, false, true) { t.Fatal("MLSKeyPackage must be exempt when marmotOpen") } if !WriteExempt(444, false, true) { t.Fatal("MLSWelcome must be exempt when marmotOpen") } if !WriteExempt(445, false, true) { t.Fatal("MLSGroupEvent must be exempt when marmotOpen") } if !WriteExempt(1059, false, true) { t.Fatal("GiftWrap must be exempt when marmotOpen") } if WriteExempt(443, false, false) { t.Fatal("MLS must not be exempt when marmotOpen is off") } if WriteExempt(1060, false, true) { t.Fatal("GiftWrapWithKind4 must not be exempt") } if WriteExempt(1, true, true) { t.Fatal("kind 1 must never be write-exempt") } }