tests: preserve SSH regressions after combining policy fixes

Updates #3517
This commit is contained in:
Kristoffer Dalby
2026-10-07 09:36:25 +00:00
parent b7aa328e0c
commit b8146aa7cd
2 changed files with 6 additions and 5 deletions
+5 -4
View File
@@ -914,7 +914,7 @@ func newSSHVerdictFixture(t *testing.T) *sshVerdictFixture {
}`, user.Name+"@"))
require.NoError(t, err)
period, checkFound := app.state.SSHCheckParams(ids[0], ids[1])
period, checkFound := app.state.SSHCheckParams(ids[0], ids[1], sshTestLocalUser)
require.True(t, checkFound, "test setup: pair must be subject to a check")
require.Zero(t, period, "test setup: checkPeriod must be always")
@@ -1053,12 +1053,13 @@ func TestSSHActionFollowUp_ConsumedVerdictNotReplayed(t *testing.T) {
_, err := f.ns.headscale.state.SetPolicy([]byte(`{}`))
require.NoError(t, err)
_, checkFound := f.ns.headscale.state.SSHCheckParams(f.src, f.dst)
_, checkFound := f.ns.headscale.state.SSHCheckParams(f.src, f.dst, sshTestLocalUser)
require.False(t, checkFound, "test setup: pair must no longer be subject to a check")
rec := f.followUp(t, authID)
assert.Equal(t, http.StatusBadRequest, rec.Code,
"replay without a check must be refused, body=%s", rec.Body.String())
action := sshActionFromRecorder(t, rec)
assert.True(t, action.Reject, "replay without a check must be refused")
assert.False(t, action.Accept, "replay without a check must never approve access")
})
}
}
+1 -1
View File
@@ -2713,7 +2713,7 @@ func TestUnregisteredUsersAreNoOp(t *testing.T) {
continue
}
period, ok := pm.SSHCheckParams(n.ID, p.ID)
period, ok := pm.SSHCheckParams(n.ID, p.ID, "alice")
got[n.Hostname+"->"+p.Hostname+" via"] = pm.ViaRoutesForPeer(nv, p.View())
got[n.Hostname+"->"+p.Hostname+" check"] = checkParams{period, ok}
}