mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-01 11:09:15 +02:00
[client] Profile ownership console user tofu (#7529)
* Add consoleuser and stamp default profile on known username in migration * Refactor consoleuser to verify Id, fix seats on linux and default stamp * Add default profile claim * Add disable auto-claim of default profile and always fail close * Add disable auto-claim flag to migration * Adding timeout to console user on Linux and close library load on darwin * Fixed failed close test * Close both Dlopen for darwin * Replace RegisterFunc with purego.Dlsym to avoid possible panic * Fix freebsd tty enumeration * Fix active profile migration logic and add test * Log defaultClaimDisabled error once * Guard against panicking console user lookup. * Fix merge conflict * Fix broken tests
This commit is contained in:
@@ -289,3 +289,73 @@ func TestMigrate_SkipsAProfileItCannotStamp(t *testing.T) {
|
||||
assert.Equal(t, "null", string(data), "the profile it could not stamp is untouched")
|
||||
})
|
||||
}
|
||||
|
||||
// TestTakesActiveAccountOwner pins which profiles migration hands the active
|
||||
// account's principal to.
|
||||
func TestTakesActiveAccountOwner(t *testing.T) {
|
||||
for _, tc := range []struct {
|
||||
name string
|
||||
dir string
|
||||
profile Profile
|
||||
disabled bool
|
||||
want bool
|
||||
}{
|
||||
{
|
||||
name: "profile in the account's own directory",
|
||||
dir: "alice",
|
||||
profile: Profile{ID: "work", LegacyUserDir: "alice"},
|
||||
want: true,
|
||||
},
|
||||
{
|
||||
name: "profile in another account's directory",
|
||||
dir: "alice",
|
||||
profile: Profile{ID: "work", LegacyUserDir: "bob"},
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "default profile",
|
||||
dir: "alice",
|
||||
profile: Profile{ID: defaultProfileName},
|
||||
want: true,
|
||||
},
|
||||
{
|
||||
name: "default profile with the claim disabled",
|
||||
dir: "alice",
|
||||
profile: Profile{ID: defaultProfileName},
|
||||
disabled: true,
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "default profile when the account has no directory name",
|
||||
dir: "",
|
||||
profile: Profile{ID: defaultProfileName},
|
||||
want: true,
|
||||
},
|
||||
{
|
||||
name: "default profile when the account has no directory name and the claim is disabled",
|
||||
dir: "",
|
||||
profile: Profile{ID: defaultProfileName},
|
||||
disabled: true,
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "shared-directory profile when the account has no directory name",
|
||||
dir: "",
|
||||
profile: Profile{ID: "work"},
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "profile in a real directory when the account has no directory name",
|
||||
dir: "",
|
||||
profile: Profile{ID: "work", LegacyUserDir: "alice"},
|
||||
want: false,
|
||||
},
|
||||
} {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
if tc.disabled {
|
||||
t.Setenv(EnvDisableDefaultProfileClaim, "true")
|
||||
}
|
||||
assert.Equal(t, tc.want, takesActiveAccountOwner(&tc.profile, tc.dir))
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user