mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-11 07:59:08 +02:00
Read user certificates only from the session of the active profile's owner
This commit is contained in:
+15
-1
@@ -2515,9 +2515,23 @@ func (s *Server) checkDisableAdvancedView() *bool {
|
||||
return nil
|
||||
}
|
||||
|
||||
// profileOwnerOption passes the OS account of the active profile to the connect client,
|
||||
// which reads that account's certificate store for user certificate posture checks.
|
||||
func (s *Server) profileOwnerOption() []internal.ConnectClientOption {
|
||||
if s.profileManager == nil {
|
||||
return nil
|
||||
}
|
||||
activeProf, err := s.profileManager.GetActiveProfileState()
|
||||
if err != nil {
|
||||
log.Debugf("no active profile owner for certificate posture: %v", err)
|
||||
return nil
|
||||
}
|
||||
return []internal.ConnectClientOption{internal.WithProfileOwner(activeProf.Username)}
|
||||
}
|
||||
|
||||
func (s *Server) connect(ctx context.Context, config *profilemanager.Config, statusRecorder *peer.Status, runningChan chan struct{}) error {
|
||||
log.Tracef("running client connection")
|
||||
client := internal.NewConnectClient(ctx, config, statusRecorder)
|
||||
client := internal.NewConnectClient(ctx, config, statusRecorder, s.profileOwnerOption()...)
|
||||
client.SetUpdateManager(s.updateManager)
|
||||
client.SetSyncResponsePersistence(s.persistSyncResponse)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user