mirror of
				https://github.com/juanfont/headscale.git
				synced 2025-11-01 05:27:44 +09:00 
			
		
		
		
	
		
			Some checks failed
		
		
	
	Build / build-nix (push) Waiting to run
				
			Build / build-cross (GOARCH=386   GOOS=linux) (push) Waiting to run
				
			Build / build-cross (GOARCH=amd64 GOOS=darwin) (push) Waiting to run
				
			Build / build-cross (GOARCH=amd64 GOOS=linux) (push) Waiting to run
				
			Build / build-cross (GOARCH=arm   GOOS=linux GOARM=5) (push) Waiting to run
				
			Build / build-cross (GOARCH=arm   GOOS=linux GOARM=6) (push) Waiting to run
				
			Build / build-cross (GOARCH=arm   GOOS=linux GOARM=7) (push) Waiting to run
				
			Build / build-cross (GOARCH=arm64 GOOS=darwin) (push) Waiting to run
				
			Build / build-cross (GOARCH=arm64 GOOS=linux) (push) Waiting to run
				
			Tests / test (push) Waiting to run
				
			update-flake-lock / lockfile (push) Has been cancelled
				
			GitHub Actions Version Updater / build (push) Has been cancelled
				
			* add dedicated http error to propagate to user Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com> * classify user errors in http handlers Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com> * move validation of pre auth key out of db This move separates the logic a bit and allow us to write specific errors for the caller, in this case the web layer so we can present the user with the correct error codes without bleeding web stuff into a generic validate. Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com> * update changelog Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com> --------- Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>
		
			
				
	
	
		
			193 lines
		
	
	
		
			5.0 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
			
		
		
	
	
			193 lines
		
	
	
		
			5.0 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
| package hscontrol
 | |
| 
 | |
| import (
 | |
| 	"bytes"
 | |
| 	_ "embed"
 | |
| 	"html/template"
 | |
| 	"net/http"
 | |
| 	textTemplate "text/template"
 | |
| 
 | |
| 	"github.com/gofrs/uuid/v5"
 | |
| 	"github.com/gorilla/mux"
 | |
| 	"github.com/juanfont/headscale/hscontrol/templates"
 | |
| )
 | |
| 
 | |
| // WindowsConfigMessage shows a simple message in the browser for how to configure the Windows Tailscale client.
 | |
| func (h *Headscale) WindowsConfigMessage(
 | |
| 	writer http.ResponseWriter,
 | |
| 	req *http.Request,
 | |
| ) {
 | |
| 	writer.Header().Set("Content-Type", "text/html; charset=utf-8")
 | |
| 	writer.WriteHeader(http.StatusOK)
 | |
| 	writer.Write([]byte(templates.Windows(h.cfg.ServerURL).Render()))
 | |
| }
 | |
| 
 | |
| // AppleConfigMessage shows a simple message in the browser to point the user to the iOS/MacOS profile and instructions for how to install it.
 | |
| func (h *Headscale) AppleConfigMessage(
 | |
| 	writer http.ResponseWriter,
 | |
| 	req *http.Request,
 | |
| ) {
 | |
| 	writer.Header().Set("Content-Type", "text/html; charset=utf-8")
 | |
| 	writer.WriteHeader(http.StatusOK)
 | |
| 	writer.Write([]byte(templates.Apple(h.cfg.ServerURL).Render()))
 | |
| }
 | |
| 
 | |
| func (h *Headscale) ApplePlatformConfig(
 | |
| 	writer http.ResponseWriter,
 | |
| 	req *http.Request,
 | |
| ) {
 | |
| 	vars := mux.Vars(req)
 | |
| 	platform, ok := vars["platform"]
 | |
| 	if !ok {
 | |
| 		httpError(writer, NewHTTPError(http.StatusBadRequest, "no platform specified", nil))
 | |
| 		return
 | |
| 	}
 | |
| 
 | |
| 	id, err := uuid.NewV4()
 | |
| 	if err != nil {
 | |
| 		httpError(writer, err)
 | |
| 		return
 | |
| 	}
 | |
| 
 | |
| 	contentID, err := uuid.NewV4()
 | |
| 	if err != nil {
 | |
| 		httpError(writer, err)
 | |
| 		return
 | |
| 	}
 | |
| 
 | |
| 	platformConfig := AppleMobilePlatformConfig{
 | |
| 		UUID: contentID,
 | |
| 		URL:  h.cfg.ServerURL,
 | |
| 	}
 | |
| 
 | |
| 	var payload bytes.Buffer
 | |
| 
 | |
| 	switch platform {
 | |
| 	case "macos-standalone":
 | |
| 		if err := macosStandaloneTemplate.Execute(&payload, platformConfig); err != nil {
 | |
| 			httpError(writer, err)
 | |
| 			return
 | |
| 		}
 | |
| 	case "macos-app-store":
 | |
| 		if err := macosAppStoreTemplate.Execute(&payload, platformConfig); err != nil {
 | |
| 			httpError(writer, err)
 | |
| 			return
 | |
| 		}
 | |
| 	case "ios":
 | |
| 		if err := iosTemplate.Execute(&payload, platformConfig); err != nil {
 | |
| 			httpError(writer, err)
 | |
| 			return
 | |
| 		}
 | |
| 	default:
 | |
| 		httpError(writer, NewHTTPError(http.StatusBadRequest, "platform must be ios, macos-app-store or macos-standalone", nil))
 | |
| 		return
 | |
| 	}
 | |
| 
 | |
| 	config := AppleMobileConfig{
 | |
| 		UUID:    id,
 | |
| 		URL:     h.cfg.ServerURL,
 | |
| 		Payload: payload.String(),
 | |
| 	}
 | |
| 
 | |
| 	var content bytes.Buffer
 | |
| 	if err := commonTemplate.Execute(&content, config); err != nil {
 | |
| 		httpError(writer, err)
 | |
| 		return
 | |
| 	}
 | |
| 
 | |
| 	writer.Header().
 | |
| 		Set("Content-Type", "application/x-apple-aspen-config; charset=utf-8")
 | |
| 	writer.WriteHeader(http.StatusOK)
 | |
| 	writer.Write(content.Bytes())
 | |
| }
 | |
| 
 | |
| type AppleMobileConfig struct {
 | |
| 	UUID    uuid.UUID
 | |
| 	URL     string
 | |
| 	Payload string
 | |
| }
 | |
| 
 | |
| type AppleMobilePlatformConfig struct {
 | |
| 	UUID uuid.UUID
 | |
| 	URL  string
 | |
| }
 | |
| 
 | |
| var commonTemplate = textTemplate.Must(
 | |
| 	textTemplate.New("mobileconfig").Parse(`<?xml version="1.0" encoding="UTF-8"?>
 | |
| <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
 | |
| <plist version="1.0">
 | |
|   <dict>
 | |
|     <key>PayloadUUID</key>
 | |
|     <string>{{.UUID}}</string>
 | |
|     <key>PayloadDisplayName</key>
 | |
|     <string>Headscale</string>
 | |
|     <key>PayloadDescription</key>
 | |
|     <string>Configure Tailscale login server to: {{.URL}}</string>
 | |
|     <key>PayloadIdentifier</key>
 | |
|     <string>com.github.juanfont.headscale</string>
 | |
|     <key>PayloadRemovalDisallowed</key>
 | |
|     <false/>
 | |
|     <key>PayloadType</key>
 | |
|     <string>Configuration</string>
 | |
|     <key>PayloadVersion</key>
 | |
|     <integer>1</integer>
 | |
|     <key>PayloadContent</key>
 | |
|     <array>
 | |
|     {{.Payload}}
 | |
|     </array>
 | |
|   </dict>
 | |
| </plist>`),
 | |
| )
 | |
| 
 | |
| var iosTemplate = textTemplate.Must(textTemplate.New("iosTemplate").Parse(`
 | |
|     <dict>
 | |
|         <key>PayloadType</key>
 | |
|         <string>io.tailscale.ipn.ios</string>
 | |
|         <key>PayloadUUID</key>
 | |
|         <string>{{.UUID}}</string>
 | |
|         <key>PayloadIdentifier</key>
 | |
|         <string>com.github.juanfont.headscale</string>
 | |
|         <key>PayloadVersion</key>
 | |
|         <integer>1</integer>
 | |
|         <key>PayloadEnabled</key>
 | |
|         <true/>
 | |
| 
 | |
|         <key>ControlURL</key>
 | |
|         <string>{{.URL}}</string>
 | |
|     </dict>
 | |
| `))
 | |
| 
 | |
| var macosAppStoreTemplate = template.Must(template.New("macosTemplate").Parse(`
 | |
|     <dict>
 | |
|         <key>PayloadType</key>
 | |
|         <string>io.tailscale.ipn.macos</string>
 | |
|         <key>PayloadUUID</key>
 | |
|         <string>{{.UUID}}</string>
 | |
|         <key>PayloadIdentifier</key>
 | |
|         <string>com.github.juanfont.headscale</string>
 | |
|         <key>PayloadVersion</key>
 | |
|         <integer>1</integer>
 | |
|         <key>PayloadEnabled</key>
 | |
|         <true/>
 | |
|         <key>ControlURL</key>
 | |
|         <string>{{.URL}}</string>
 | |
|     </dict>
 | |
| `))
 | |
| 
 | |
| var macosStandaloneTemplate = template.Must(template.New("macosStandaloneTemplate").Parse(`
 | |
|     <dict>
 | |
|         <key>PayloadType</key>
 | |
|         <string>io.tailscale.ipn.macsys</string>
 | |
|         <key>PayloadUUID</key>
 | |
|         <string>{{.UUID}}</string>
 | |
|         <key>PayloadIdentifier</key>
 | |
|         <string>com.github.juanfont.headscale</string>
 | |
|         <key>PayloadVersion</key>
 | |
|         <integer>1</integer>
 | |
|         <key>PayloadEnabled</key>
 | |
|         <true/>
 | |
|         <key>ControlURL</key>
 | |
|         <string>{{.URL}}</string>
 | |
|     </dict>
 | |
| `))
 |