Commit Graph

3 Commits

Author SHA1 Message Date
Kristoffer Dalby 957a332d5d policy/v2: match the login user in SSHCheckParams
The client picks the check rule by login user; the server took the
first rule for the node pair, so a root login could get a 12h
localpart period instead of "always", or be approved after its rule
was removed while another user's rule remained. Hold URLs now carry
the concrete user: tailssh never expanded the encoded $LOCAL_USER.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby dceb584c89 noise: reject SSH checks the policy no longer requires
A stale check rule still held and accepted after login. Deny with a 200
Reject (tailssh retries errors); re-check after the verdict.

Updates #3508
2026-10-08 10:29:23 +02:00
kloba 71a4ce3c9f noise: re-delegate SSH check when the auth session is missing (#3306) 2026-06-10 11:48:02 +02:00