Address Sonar findings and move noise to direct dependency

This commit is contained in:
Viktor Liu
2026-05-21 17:55:27 +02:00
parent ee348ba007
commit 5e67febf57
4 changed files with 35 additions and 27 deletions
@@ -64,17 +64,7 @@ func applyResolvedRuleToState(
state.sshEnabled = true
cb.collectSSHUsers(rule, state.authorizedUsers)
case rule.Protocol == PolicyRuleProtocolNetbirdVNC:
// VNC bidirectional rules grant access in both directions.
if !peerInDestinations && !(rule.Bidirectional && peerInSources) {
return
}
cb.collectVNCUsers(rule, state.vncAuthorizedUsers)
if rule.SessionPubKey != "" && rule.AuthorizedUser != "" {
state.vncSessionPubKeys = append(state.vncSessionPubKeys, VNCSessionPubKey{
PubKey: rule.SessionPubKey,
UserID: rule.AuthorizedUser,
})
}
cb.handleVNCRule(rule, peerInSources, peerInDestinations, state)
case policyRuleImpliesLegacySSH(rule) && targetPeerSSHEnabled:
if !peerInDestinations {
return
@@ -84,6 +74,21 @@ func applyResolvedRuleToState(
}
}
// handleVNCRule collects VNC authorized users and session pubkeys for a VNC
// policy rule. Bidirectional rules grant access in both directions.
func (cb ruleAuthCallbacks) handleVNCRule(rule *PolicyRule, peerInSources, peerInDestinations bool, state *peerConnResolveState) {
if !peerInDestinations && !(rule.Bidirectional && peerInSources) {
return
}
cb.collectVNCUsers(rule, state.vncAuthorizedUsers)
if rule.SessionPubKey != "" && rule.AuthorizedUser != "" {
state.vncSessionPubKeys = append(state.vncSessionPubKeys, VNCSessionPubKey{
PubKey: rule.SessionPubKey,
UserID: rule.AuthorizedUser,
})
}
}
func mergeWildcardUsers(dst map[string]map[string]struct{}, users map[string]struct{}) {
if dst[auth.Wildcard] == nil {
dst[auth.Wildcard] = make(map[string]struct{})