mirror of
https://github.com/juanfont/headscale.git
synced 2026-10-03 05:13:36 +09:00
state: accept advertise-tags subset of a pre-auth key's tags
tailscale client's OAuth authkey flow re-advertises the key's tags. Reject only tags the key lacks, for new nodes and re-registrations.
This commit is contained in:
@@ -3234,8 +3234,8 @@ func TestTagsAuthKeyWithoutUserInheritsTags(t *testing.T) {
|
||||
}
|
||||
|
||||
// TestTagsAuthKeyWithoutUserRejectsAdvertisedTags tests that when an auth key without
|
||||
// a user (tags-only) is used WITH --advertise-tags, the registration is rejected.
|
||||
// PreAuthKey registrations do not allow client-requested tags.
|
||||
// a user (tags-only) is used WITH --advertise-tags naming a tag the key lacks, the
|
||||
// registration is rejected. Only a subset of the key's own tags may be advertised.
|
||||
//
|
||||
// Test 5.2: Auth key without user, with --advertise-tags (should be rejected)
|
||||
// Setup: Run `tailscale up --advertise-tags="tag:second" --auth-key AUTH_KEY_WITH_TAGS_NO_USER`
|
||||
|
||||
Reference in New Issue
Block a user