Enforces disable networks

This commit is contained in:
riccardom
2026-06-08 18:06:02 +02:00
parent 6355a24deb
commit 01a4c245a7
3 changed files with 21 additions and 4 deletions
+16 -1
View File
@@ -1699,7 +1699,7 @@ func (s *Server) GetFeatures(ctx context.Context, msg *proto.GetFeaturesRequest)
features := &proto.GetFeaturesResponse{
DisableProfiles: s.checkProfilesDisabled(),
DisableUpdateSettings: s.checkUpdateSettingsDisabled(),
DisableNetworks: s.networksDisabled,
DisableNetworks: s.checkNetworksDisabled(),
}
// MDM kill switch: read the value from the active policy on the
@@ -1746,6 +1746,21 @@ func (s *Server) checkProfilesDisabled() bool {
return false
}
func (s *Server) checkNetworksDisabled() bool {
// CLI flag set at service install time wins.
if s.networksDisabled {
return true
}
// MDM kill switch: either source can disable the feature; neither
// can re-enable a switch the other has set.
if s.config != nil {
if v, ok := s.config.Policy().GetBool(mdm.KeyDisableNetworks); ok && v {
return true
}
}
return false
}
func (s *Server) checkUpdateSettingsDisabled() bool {
// CLI flag set at service install time wins.
if s.updateSettingsDisabled {