state: accept advertise-tags subset of a pre-auth key's tags

tailscale client's OAuth authkey flow re-advertises the key's tags.
Reject only tags the key lacks, for new nodes and re-registrations.
This commit is contained in:
Kristoffer Dalby
2026-06-27 10:12:29 +00:00
parent 69e84c356d
commit 61a626eab7
3 changed files with 249 additions and 12 deletions
+2 -2
View File
@@ -3234,8 +3234,8 @@ func TestTagsAuthKeyWithoutUserInheritsTags(t *testing.T) {
}
// TestTagsAuthKeyWithoutUserRejectsAdvertisedTags tests that when an auth key without
// a user (tags-only) is used WITH --advertise-tags, the registration is rejected.
// PreAuthKey registrations do not allow client-requested tags.
// a user (tags-only) is used WITH --advertise-tags naming a tag the key lacks, the
// registration is rejected. Only a subset of the key's own tags may be advertised.
//
// Test 5.2: Auth key without user, with --advertise-tags (should be rejected)
// Setup: Run `tailscale up --advertise-tags="tag:second" --auth-key AUTH_KEY_WITH_TAGS_NO_USER`