Address CodeRabbit VNC review feedback

This commit is contained in:
Viktor Liu
2026-05-21 18:09:07 +02:00
parent e2127b45f8
commit d06ed64e59
9 changed files with 59 additions and 29 deletions
@@ -2,6 +2,7 @@ package peers
import (
"context"
"encoding/base64"
"encoding/json"
"fmt"
"net/http"
@@ -518,6 +519,15 @@ func (h *Handler) CreateTemporaryAccess(w http.ResponseWriter, r *http.Request)
policy.Rules[0].AuthorizedUser = userAuth.UserId
}
if protocol == types.PolicyRuleProtocolNetbirdVNC && req.SessionPubKey != nil {
pub, err := base64.StdEncoding.DecodeString(*req.SessionPubKey)
if err != nil {
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "session_pub_key is not valid base64: %v", err), w)
return
}
if len(pub) != 32 {
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "session_pub_key must decode to 32 bytes, got %d", len(pub)), w)
return
}
policy.Rules[0].SessionPubKey = *req.SessionPubKey
}
+4 -4
View File
@@ -89,10 +89,10 @@ type PolicyRule struct {
// AuthorizedUser is a list of userIDs that are authorized to access local resources via ssh
AuthorizedUser string
// SessionPubKey is the base64 Ed25519 public key the AuthorizedUser
// will sign session-binding challenges with. Set together with
// AuthorizedUser when the rule was created via temporary-access for
// a VNC scope; empty otherwise.
// SessionPubKey is the base64 X25519 public key used with Noise_IK to
// bind a VNC session to the AuthorizedUser. Set together with
// AuthorizedUser when the rule was created via temporary-access for a
// VNC scope; empty otherwise.
SessionPubKey string
}