mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-04 20:49:06 +02:00
[management] Scope the change to the private-capability check
The PR grew past its purpose. What it needs to do is refuse to bootstrap an agent network endpoint onto a cluster that cannot serve it, which is the private capability check on the picked cluster. Everything that accreted around it — canonicalising proxy addresses at connect, refusing another account's cluster or a host another account pinned, withdrawing a claim lost to a concurrent one, folding casing on migrated settings rows — is security work in its own right and moves to follow-up PRs, where each can be reviewed against its own threat rather than as a rider on this one. This restores main's version of every file outside that purpose and reduces the validation to: a cluster the account can see must have a live embedded proxy, and a cluster management holds no row for stays pinnable (address-first). The e2e test and the fixture seeds are unchanged. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sa3DsBDP3VciAi4PPG17L6
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
4ed71f8987
commit
5502ea08ac
@@ -315,32 +315,6 @@ func (s *SqlStore) GetAllAgentNetworkSettings(ctx context.Context, lockStrength
|
||||
return settings, nil
|
||||
}
|
||||
|
||||
// HasGatewayPinnedByOtherAccount reports whether an account other than the
|
||||
// given one has its agent network gateway pinned to this host.
|
||||
//
|
||||
// A pin is a claim on the host, the same way a proxy row is: the pinned
|
||||
// endpoint is served by whichever proxy declares that address, and an
|
||||
// account-scoped proxy only ever receives its own account's mappings. A proxy
|
||||
// from a different account taking the address therefore cannot serve the pin
|
||||
// and silently strands it. The pin is immutable, so the account that holds it
|
||||
// cannot move out of the way — the later claimant is the one to refuse.
|
||||
//
|
||||
// Both sides are canonical (settings normalize on write, proxy addresses
|
||||
// canonicalize at connect), so the match is exact and uses the proxy_address
|
||||
// index.
|
||||
func (s *SqlStore) HasGatewayPinnedByOtherAccount(ctx context.Context, host, accountID string) (bool, error) {
|
||||
var count int64
|
||||
result := s.db.
|
||||
Model(&agentNetworkTypes.Settings{}).
|
||||
Where("proxy_address = ? AND account_id != ?", host, accountID).
|
||||
Count(&count)
|
||||
if result.Error != nil {
|
||||
log.WithContext(ctx).Errorf("failed to check agent network gateway pins by proxy address: %v", result.Error)
|
||||
return false, status.Errorf(status.Internal, "check agent network gateway pins")
|
||||
}
|
||||
return count > 0, nil
|
||||
}
|
||||
|
||||
// GetAgentNetworkSettingsByProxyAddress returns every Settings row whose
|
||||
// gateway is served by the proxy declaring the given cluster address. Used by
|
||||
// cluster-scoped synthesis to find the accounts a shared proxy serves.
|
||||
|
||||
Reference in New Issue
Block a user