mirror of
https://github.com/juanfont/headscale.git
synced 2026-10-10 08:40:07 +09:00
policy/v2: send an empty SSH policy when no rule applies
Nil SSHPolicy means "unchanged" to clients; removed rules stayed live. Match SaaS: "rules":[]. Fixes #3508
This commit is contained in:
committed by
Kristoffer Dalby
parent
82df3e088a
commit
2a0823ca41
@@ -458,7 +458,7 @@ func TestSSHPolicyRules(t *testing.T) {
|
||||
}
|
||||
]
|
||||
}`,
|
||||
wantSSH: &tailcfg.SSHPolicy{Rules: nil},
|
||||
wantSSH: &tailcfg.SSHPolicy{Rules: []*tailcfg.SSHRule{}},
|
||||
},
|
||||
{
|
||||
name: "invalid-action",
|
||||
|
||||
@@ -261,13 +261,15 @@ func (pol *Policy) compileSSHPolicy(
|
||||
node types.NodeView,
|
||||
nodes views.Slice[types.NodeView],
|
||||
) (*tailcfg.SSHPolicy, error) {
|
||||
if pol == nil || pol.SSHs == nil || len(pol.SSHs) == 0 {
|
||||
return nil, nil //nolint:nilnil // intentional: no SSH policy when none configured
|
||||
// Never nil: clients read a nil SSHPolicy as "keep the previous
|
||||
// rules", so revoked access would stay. SaaS sends "rules":[].
|
||||
if pol == nil || len(pol.SSHs) == 0 {
|
||||
return &tailcfg.SSHPolicy{Rules: []*tailcfg.SSHRule{}}, nil
|
||||
}
|
||||
|
||||
log.Trace().Caller().Msgf("compiling SSH policy for node %q", node.Hostname())
|
||||
|
||||
var rules []*tailcfg.SSHRule
|
||||
rules := []*tailcfg.SSHRule{}
|
||||
|
||||
for index, rule := range pol.SSHs {
|
||||
var autogroupSelfDests, otherDests []Alias
|
||||
|
||||
@@ -618,7 +618,7 @@ func TestCompileSSHPolicy_UserMapping(t *testing.T) {
|
||||
},
|
||||
},
|
||||
},
|
||||
want: &tailcfg.SSHPolicy{},
|
||||
want: &tailcfg.SSHPolicy{Rules: []*tailcfg.SSHRule{}},
|
||||
},
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user