From a572a725475efc31988e619235ce3ef60258aec1 Mon Sep 17 00:00:00 2001 From: Simon Rozet Date: Tue, 15 Aug 2023 22:20:34 +0200 Subject: [PATCH] don't set webauth headers for tagged nodes --- tsproxy.go | 14 ++++++++++++-- tsproxy_test.go | 18 ++++++++++++++++-- 2 files changed, 28 insertions(+), 4 deletions(-) diff --git a/tsproxy.go b/tsproxy.go index aa5ba19..d7c04ae 100644 --- a/tsproxy.go +++ b/tsproxy.go @@ -38,17 +38,27 @@ func newReverseProxy(logger *slog.Logger, lc tailscaleLocalClient, url *url.URL) return } - // TODO(sr) Forbid access to tagged users (i.e. machines)? + if whois.Node == nil { + http.Error(w, http.StatusText(http.StatusInternalServerError), http.StatusInternalServerError) + logger.Error("tailscale whois", slog.String("err", "node missing")) + return + } + if whois.UserProfile == nil { http.Error(w, http.StatusText(http.StatusInternalServerError), http.StatusInternalServerError) logger.Error("tailscale whois", slog.String("err", "user profile missing")) return } + // Proxy requests from tagged nodes as is. + if whois.Node.IsTagged() { + rproxy.ServeHTTP(w, r) + return + } + req := r.Clone(r.Context()) req.Header.Set("X-Webauth-User", whois.UserProfile.LoginName) req.Header.Set("X-Webauth-Name", whois.UserProfile.DisplayName) - rproxy.ServeHTTP(w, req) }) } diff --git a/tsproxy_test.go b/tsproxy_test.go index 46eca3c..0676bc0 100644 --- a/tsproxy_test.go +++ b/tsproxy_test.go @@ -114,9 +114,23 @@ func TestReverseProxy(t *testing.T) { want: http.StatusInternalServerError, }, { - name: "tailscale whois ok", + name: "tailscale whois no node", whois: func(_ context.Context, _ string) (*apitype.WhoIsResponse, error) { - return &apitype.WhoIsResponse{UserProfile: &tailcfg.UserProfile{LoginName: "login", DisplayName: "name"}}, nil + return &apitype.WhoIsResponse{UserProfile: &tailcfg.UserProfile{LoginName: "login"}}, nil + }, + want: http.StatusInternalServerError, + }, + { + name: "tailscale whois ok (tagged node)", + whois: func(_ context.Context, _ string) (*apitype.WhoIsResponse, error) { + return &apitype.WhoIsResponse{UserProfile: &tailcfg.UserProfile{LoginName: "tagged-devices"}, Node: &tailcfg.Node{Tags: []string{"foo"}}}, nil + }, + want: http.StatusOK, + }, + { + name: "tailscale whois ok (user)", + whois: func(_ context.Context, _ string) (*apitype.WhoIsResponse, error) { + return &apitype.WhoIsResponse{UserProfile: &tailcfg.UserProfile{LoginName: "login", DisplayName: "name"}, Node: &tailcfg.Node{Name: "login.ts.net"}}, nil }, want: http.StatusOK, wantHeaders: map[string]string{ -- 2.51.2