db: accept tskey-client- prefix for OAuth client auth

The upstream tailscale client only runs its OAuth client-credentials exchange
for secrets prefixed tskey-client-, so accept it as an alias for hskey-client-.
The prefix is only a label sliced off before lookup, so the same stored client
authenticates under either; lets the official client and GitHub Action mint auth
keys against headscale.
This commit is contained in:
Kristoffer Dalby
2026-06-27 10:12:08 +00:00
parent c5dc3d4385
commit 69e84c356d
3 changed files with 62 additions and 1 deletions
+8
View File
@@ -11,6 +11,14 @@ const (
// hskey-client-<clientID>-<secret>.
OAuthClientPrefix = "hskey-client-" //nolint:gosec // prefix, not a credential
// TailscaleOAuthClientPrefix is an accepted alias for [OAuthClientPrefix].
// The tailscale client only runs its OAuth client-credentials exchange
// (feature/oauthkey) for secrets with this prefix, so accepting it lets the
// stock client and GitHub Action mint auth keys against headscale. The
// prefix is only a label, cut before lookup; the same stored client
// authenticates under either.
TailscaleOAuthClientPrefix = "tskey-client-" //nolint:gosec // prefix, not a credential
// AccessTokenPrefix prefixes an OAuth access token:
// hskey-oauthtok-<prefix>-<secret>. The v2 auth middleware dispatches a
// scope-limited token from an all-access admin key on this prefix alone, so