Read user certificates only from the session of the active profile's owner

This commit is contained in:
Viktor Liu
2026-10-02 12:32:27 +02:00
parent e0b6a38aa2
commit a91fe94ada
10 changed files with 196 additions and 40 deletions
+15 -1
View File
@@ -2515,9 +2515,23 @@ func (s *Server) checkDisableAdvancedView() *bool {
return nil
}
// profileOwnerOption passes the OS account of the active profile to the connect client,
// which reads that account's certificate store for user certificate posture checks.
func (s *Server) profileOwnerOption() []internal.ConnectClientOption {
if s.profileManager == nil {
return nil
}
activeProf, err := s.profileManager.GetActiveProfileState()
if err != nil {
log.Debugf("no active profile owner for certificate posture: %v", err)
return nil
}
return []internal.ConnectClientOption{internal.WithProfileOwner(activeProf.Username)}
}
func (s *Server) connect(ctx context.Context, config *profilemanager.Config, statusRecorder *peer.Status, runningChan chan struct{}) error {
log.Tracef("running client connection")
client := internal.NewConnectClient(ctx, config, statusRecorder)
client := internal.NewConnectClient(ctx, config, statusRecorder, s.profileOwnerOption()...)
client.SetUpdateManager(s.updateManager)
client.SetSyncResponsePersistence(s.persistSyncResponse)