mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-02 11:39:06 +02:00
Address CodeRabbit VNC review feedback
This commit is contained in:
@@ -2,6 +2,7 @@ package peers
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/http"
|
||||
@@ -518,6 +519,15 @@ func (h *Handler) CreateTemporaryAccess(w http.ResponseWriter, r *http.Request)
|
||||
policy.Rules[0].AuthorizedUser = userAuth.UserId
|
||||
}
|
||||
if protocol == types.PolicyRuleProtocolNetbirdVNC && req.SessionPubKey != nil {
|
||||
pub, err := base64.StdEncoding.DecodeString(*req.SessionPubKey)
|
||||
if err != nil {
|
||||
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "session_pub_key is not valid base64: %v", err), w)
|
||||
return
|
||||
}
|
||||
if len(pub) != 32 {
|
||||
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "session_pub_key must decode to 32 bytes, got %d", len(pub)), w)
|
||||
return
|
||||
}
|
||||
policy.Rules[0].SessionPubKey = *req.SessionPubKey
|
||||
}
|
||||
|
||||
|
||||
@@ -89,10 +89,10 @@ type PolicyRule struct {
|
||||
// AuthorizedUser is a list of userIDs that are authorized to access local resources via ssh
|
||||
AuthorizedUser string
|
||||
|
||||
// SessionPubKey is the base64 Ed25519 public key the AuthorizedUser
|
||||
// will sign session-binding challenges with. Set together with
|
||||
// AuthorizedUser when the rule was created via temporary-access for
|
||||
// a VNC scope; empty otherwise.
|
||||
// SessionPubKey is the base64 X25519 public key used with Noise_IK to
|
||||
// bind a VNC session to the AuthorizedUser. Set together with
|
||||
// AuthorizedUser when the rule was created via temporary-access for a
|
||||
// VNC scope; empty otherwise.
|
||||
SessionPubKey string
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user