[client] Do not refuse a caller's upload URL that an MDM policy overrides anyway

The privilege gate ran on the URL the caller named before the resolver applied
the MDM policy, so on a managed device an unprivileged `netbird debug bundle -U
--upload-bundle-url <host>` was refused with "requires root" — even though the
policy would have discarded that URL and uploaded to the pinned destination.
Gating a value that has no effect only turns a working bundle into a denial.

Read the policy before the gate and tell the gate the destination is pinned, so
it skips the caller-URL branch. --upload-bundle-insecure stays gated either way:
relaxing TLS towards the pinned host is a real weakening, and that one is the
caller's doing.

Reported by cubic on #7514.
This commit is contained in:
riccardom
2026-09-29 14:29:27 +02:00
parent 5fb4cdc2f7
commit d5a9f5b0ff
3 changed files with 48 additions and 20 deletions
+10 -1
View File
@@ -52,7 +52,16 @@ func uiLogOpener(id ipcauth.Identity, identified bool) debug.LogOpener {
// for a self-hosted server. It weakens a root-privileged upload, so it is
// refused for an unprivileged caller regardless of the host. upload says whether
// the request asks for an upload at all; without one there is nothing to weaken.
func requirePrivilegeForUploadURL(ctx context.Context, rawURL string, insecure, upload bool) error {
//
// mdmPinned says an MDM policy already fixes the destination. The caller's URL
// is then discarded before the upload, so gating on it would only turn a bundle
// that was going to the pinned host anyway into a refusal. Transport security
// still is gated: relaxing TLS towards the pinned host is a real weakening.
func requirePrivilegeForUploadURL(ctx context.Context, rawURL string, insecure, upload, mdmPinned bool) error {
if mdmPinned {
rawURL = ""
}
if rawURL == "" {
// An empty URL with upload requested is not "no upload": the daemon then
// resolves the destination the management server published. Relaxing TLS