fix authorized user groups for ssh + fix ignoring disabled policies + fix ignore invalid router

This commit is contained in:
pascal
2026-08-12 17:43:43 +02:00
parent 9bb1db28c3
commit 931598e593
5 changed files with 54 additions and 26 deletions
@@ -105,7 +105,7 @@ func (nmd *NetworkMapData) GetPeerNetworkMapComponents(peerID string, peersCusto
}
for _, policy := range policies {
if policy == nil || len(policy.Rules) == 0 || policy.Rules[0] == nil {
if policy == nil || !policy.Enabled || len(policy.Rules) == 0 || policy.Rules[0] == nil {
continue
}
if addSourcePeers {
@@ -147,7 +147,7 @@ func (nmd *NetworkMapData) GetPeerNetworkMapComponents(peerID string, peersCusto
}
for _, rule := range policy.Rules {
if rule == nil {
if rule == nil || !rule.Enabled {
continue
}
for _, srcGroupID := range rule.Sources {
@@ -171,15 +171,21 @@ func (nmd *NetworkMapData) GetPeerNetworkMapComponents(peerID string, peersCusto
if addSourcePeers {
components.RoutersMap[resource.NetworkID] = networkRoutingPeers
for peerIDKey := range networkRoutingPeers {
if p := nmd.Peers[peerIDKey]; p != nil {
if _, exists := components.RouterPeers[peerIDKey]; !exists {
components.RouterPeers[peerIDKey] = p
}
if _, exists := components.Peers[peerIDKey]; !exists {
if _, validated := nmd.ValidatedPeers[peerIDKey]; validated {
components.Peers[peerIDKey] = p
}
}
p := nmd.Peers[peerIDKey]
if p == nil {
continue
}
// An unapproved peer must not carry traffic, so it is kept out of
// RouterPeers as well: the envelope encoder indexes that map into
// the wire peer table, from which the client restores every entry.
if _, validated := nmd.ValidatedPeers[peerIDKey]; !validated {
continue
}
if _, exists := components.RouterPeers[peerIDKey]; !exists {
components.RouterPeers[peerIDKey] = p
}
if _, exists := components.Peers[peerIDKey]; !exists {
components.Peers[peerIDKey] = p
}
}
components.NetworkResources = append(components.NetworkResources, resource)
@@ -1103,8 +1103,9 @@ func TestGetPeerNetworkMapComponents_NetworkResources_SourceSide(t *testing.T) {
assert.Equal(t, []*nmdata.NetworkResource{res}, c.NetworkResources)
assert.Equal(t, map[string][]*nmdata.Policy{"res-1": {rp}}, c.ResourcePoliciesMap)
assert.Equal(t, map[string]map[string]*nmdata.NetworkRouter{"net-1": routers}, c.RoutersMap)
assert.ElementsMatch(t, []string{routerOK.ID, routerUnval.ID}, peerIDSet(c.RouterPeers),
"RouterPeers carries all routing peers regardless of validation")
assert.ElementsMatch(t, []string{routerOK.ID}, peerIDSet(c.RouterPeers),
"an unvalidated routing peer is withheld from RouterPeers too, since the envelope encoder "+
"indexes that map into the wire peer table and the client restores every entry from it")
assert.ElementsMatch(t, []string{targetID, routerOK.ID}, peerIDSet(c.Peers),
"only validated routing peers are connected")
assert.ElementsMatch(t, []string{"g-clients", "g-resource"}, groupIDSet(c.Groups))
@@ -819,7 +819,7 @@ func (c *NetworkMapComponents) processResourcePolicies(
var routes []*nmdata.Route
for _, policy := range c.ResourcePoliciesMap[resource.ID] {
if policy == nil || len(policy.Rules) == 0 || policy.Rules[0] == nil {
if policy == nil || !policy.Enabled || len(policy.Rules) == 0 || policy.Rules[0] == nil {
continue
}
peers := c.getResourcePolicyPeers(policy)