Page MenuHomePhabricator

[identity] Forbid registering multiple devices with the same ID
ClosedPublic

Authored by bartek on Jun 7 2024, 3:59 AM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Nov 16, 4:20 AM
Unknown Object (File)
Sat, Nov 16, 4:17 AM
Unknown Object (File)
Fri, Nov 1, 5:30 PM
Unknown Object (File)
Sun, Oct 27, 2:26 PM
Unknown Object (File)
Oct 13 2024, 6:36 AM
Unknown Object (File)
Oct 13 2024, 6:36 AM
Unknown Object (File)
Oct 13 2024, 6:36 AM
Unknown Object (File)
Oct 13 2024, 6:36 AM
Subscribers

Details

Summary

Addresses ENG-8383.
We don't want to allow registering multiple users with the same device ID.
However, if given device ID belongs to the same user, we can allow that (details in Linear task).

Depends on D12349

Test Plan

Commtest: called register_user_device() twice with the same device keys. Second call failed due to Status::AlreadyExists

Diff Detail

Repository
rCOMM Comm
Lint
No Lint Coverage
Unit
No Test Coverage

Event Timeline

bartek held this revision as a draft.
bartek published this revision for review.Jun 9 2024, 11:52 PM
bartek added 1 blocking reviewer(s): varun.
This revision is now accepted and ready to land.Jun 12 2024, 8:56 AM

in the login RPCs, don't we need to check that the device ID doesn't belong to a different user if it already exists?

varun requested changes to this revision.Jun 12 2024, 9:05 AM
This revision now requires changes to proceed.Jun 12 2024, 9:05 AM

Verify if device ID belongs to the same user

services/identity/src/client_service.rs
1107

I'm going to rebase on @varun's stack (when it's landed) before landing this and add a constant for this message

services/identity/src/client_service.rs
1107

thanks, will land my stack ASAP

This revision is now accepted and ready to land.Jun 17 2024, 10:26 AM

Add constant for Tonic status code