Merge remote-tracking branch 'origin/main' into fix/pkce-flow-session-extend

# Conflicts:
#	shared/management/proto/management.pb.go
This commit is contained in:
Zoltán Papp
2026-10-07 13:54:40 +02:00
213 changed files with 9278 additions and 8536 deletions
+4
View File
@@ -130,6 +130,10 @@ func NewClient(cfgFile, stateFile, cacheDir, logFilePath, deviceName string, osV
// SetConfigFromJSON stores the JSON config that later loads resolve instead of the config file (tvOS).
func (c *Client) SetConfigFromJSON(jsonStr string) error {
// Parsed only to reject an unreadable document early; the JSON itself is
// what is stored, and every load re-parses it. A document carrying no peer
// identity is readable and accepted: that is a logged-out profile, and the
// login that follows provisions the keys.
if _, err := profilemanager.ConfigFromJSON(jsonStr); err != nil {
log.Errorf("SetConfigFromJSON: failed to parse config JSON: %v", err)
return err
+29
View File
@@ -379,6 +379,35 @@ func (a *Auth) SetConfigFromJSON(jsonStr string) error {
}
func (a *Auth) setBaseConfig(base *profilemanager.Config) error {
// A logged-out profile carries no keys: the mobile logout clears them in
// place so the next login registers a new peer instead of resurrecting the
// old one. This is that login, and auth.NewAuth parses the WireGuard key
// before the SSO flow even starts, so an absent identity fails the login on
// key size rather than asking the user to sign in.
//
// Minted on the base config, which is the one GetConfigJSON hands back for
// the caller to store — the overlaid copy below is runtime-only.
generated, err := base.EnsureIdentity()
if err != nil {
return fmt.Errorf("ensure profile identity: %w", err)
}
if generated {
if a.cfgPath != "" {
// Non-atomic, like NewAuth's own write: the tvOS App Group sandbox
// blocks the temp-file-and-rename an atomic write needs.
if err := profilemanager.DirectWriteOutConfig(a.cfgPath, base); err != nil {
return fmt.Errorf("write out profile config: %w", err)
}
} else {
// No file to write to — this is the tvOS path, where the profile
// lives in the caller's own store. It persists the new identity by
// calling GetConfigJSON once the login completes; until then the
// keys exist only here, and a login that never completes leaves
// nothing behind.
log.Infof("provisioned a peer identity for a config with no file on disk")
}
}
overlaid, err := copyConfig(base)
if err != nil {
return err
+7 -7
View File
@@ -49,7 +49,7 @@ func (p *Preferences) GetManagementURL() (string, error) {
return p.configInput.ManagementURL, nil
}
cfg, err := profilemanager.ReadConfig(p.configInput.ConfigPath)
cfg, err := profilemanager.ReadConfigOrDefault(p.configInput.ConfigPath)
if err != nil {
return "", err
}
@@ -67,7 +67,7 @@ func (p *Preferences) GetAdminURL() (string, error) {
return p.configInput.AdminURL, nil
}
cfg, err := profilemanager.ReadConfig(p.configInput.ConfigPath)
cfg, err := profilemanager.ReadConfigOrDefault(p.configInput.ConfigPath)
if err != nil {
return "", err
}
@@ -89,7 +89,7 @@ func (p *Preferences) HasPreSharedKey() (bool, error) {
return *p.configInput.PreSharedKey != "", nil
}
cfg, err := profilemanager.ReadConfig(p.configInput.ConfigPath)
cfg, err := profilemanager.ReadConfigOrDefault(p.configInput.ConfigPath)
if err != nil {
return false, err
}
@@ -115,7 +115,7 @@ func (p *Preferences) GetRosenpassEnabled() (bool, error) {
return *p.configInput.RosenpassEnabled, nil
}
cfg, err := profilemanager.ReadConfig(p.configInput.ConfigPath)
cfg, err := profilemanager.ReadConfigOrDefault(p.configInput.ConfigPath)
if err != nil {
return false, err
}
@@ -136,7 +136,7 @@ func (p *Preferences) GetRosenpassPermissive() (bool, error) {
return *p.configInput.RosenpassPermissive, nil
}
cfg, err := profilemanager.ReadConfig(p.configInput.ConfigPath)
cfg, err := profilemanager.ReadConfigOrDefault(p.configInput.ConfigPath)
if err != nil {
return false, err
}
@@ -149,7 +149,7 @@ func (p *Preferences) GetDisableIPv6() (bool, error) {
return *p.configInput.DisableIPv6, nil
}
cfg, err := profilemanager.ReadConfig(p.configInput.ConfigPath)
cfg, err := profilemanager.ReadConfigOrDefault(p.configInput.ConfigPath)
if err != nil {
return false, err
}
@@ -168,7 +168,7 @@ func (p *Preferences) GetRemoteJobsAllowed() (bool, error) {
return *p.configInput.RemoteJobsAllowed, nil
}
cfg, err := profilemanager.ReadConfig(p.configInput.ConfigPath)
cfg, err := profilemanager.ReadConfigOrDefault(p.configInput.ConfigPath)
if err != nil {
return false, err
}