Refactor owner to be daemon-wide

This commit is contained in:
Theodor S. Midtlien
2026-07-25 18:31:39 +02:00
parent ae9ee15501
commit 14917dbc22
10 changed files with 338 additions and 73 deletions
+1 -1
View File
@@ -73,7 +73,7 @@ func (i *Interceptor) authorize(ctx context.Context, fullMethod string) error {
}
// These RPCs authorize themselves in the handler (target-profile check) or are
// connection-lifecycle actions any authenticated local user may perform; they
// connection-lifecycle actions any authenticated local user may perform. They
// bypass the active-profile gate. Still audit the C/H ones on allow.
if handlerAuthorizedMethods[fullMethod] {
i.auditAllow(id, fullMethod)
+10 -9
View File
@@ -21,15 +21,15 @@ type ProfilePolicy interface {
// handlerAuthorizedMethods bypass the active-profile gate. Peer identity is
// still required to reach them. Two groups:
//
// - Per-user / per-target-profile operations whose handler does its own
// authorization bound to the caller identity: AddProfile, ListProfiles,
// GetActiveProfile, RemoveProfile, RenameProfile, and SwitchProfile (gated
// on the TARGET profile's ownership via authorizeTargetProfile).
// - Connection-lifecycle operations on the single shared daemon connection
// that any authenticated local user may perform: Down. Gating these on the
// ACTIVE profile's owner would trap a user behind another user's profile —
// they could neither disconnect nor switch to their OWN profile. SwitchProfile
// is bounded by its target check; Down only tears the connection down.
// - Per-user or per-target-profile ops that self-authorize in the handler,
// bound to the caller identity: AddProfile, ListProfiles, GetActiveProfile,
// RemoveProfile, RenameProfile, and SwitchProfile (target ownership checked
// via authorizeTargetProfile).
// - Connection-lifecycle ops any authenticated local user may run on the shared
// daemon connection: Down and Status. Gating these on the active profile's
// owner would trap a user behind another user's profile, unable to disconnect
// or switch to their own. SwitchProfile is bounded by its target check, Down
// and Status only read or tear down the connection.
var handlerAuthorizedMethods = map[string]bool{
servicePath + "AddProfile": true,
servicePath + "ListProfiles": true,
@@ -38,6 +38,7 @@ var handlerAuthorizedMethods = map[string]bool{
servicePath + "RenameProfile": true,
servicePath + "SwitchProfile": true,
servicePath + "Down": true,
servicePath + "Status": true,
}
// auditMethods are worth an audit log line. Denials are always logged.