mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-28 09:39:05 +02:00
Merge remote-tracking branch 'origin/reverse-proxy-allow-match-or' into reverse-proxy-crowdsec-appsec
This commit is contained in:
@@ -830,7 +830,8 @@ func restrictionsFromAPI(r *api.AccessRestrictions) (AccessRestrictions, error)
|
||||
res.CrowdSecMode = string(*r.CrowdsecMode)
|
||||
}
|
||||
if r.AllowMatch != nil {
|
||||
if !r.AllowMatch.Valid() {
|
||||
// Empty is the default (all), the same as omitting the field.
|
||||
if *r.AllowMatch != "" && !r.AllowMatch.Valid() {
|
||||
return AccessRestrictions{}, fmt.Errorf("invalid allow_match %q", *r.AllowMatch)
|
||||
}
|
||||
res.AllowMatch = string(*r.AllowMatch)
|
||||
|
||||
@@ -1444,6 +1444,18 @@ func TestRestrictions_AllowMatch_EmptyDefaultsToAll(t *testing.T) {
|
||||
assert.Nil(t, apiOut.AllowMatch, "empty allow_match is omitted from the API response")
|
||||
}
|
||||
|
||||
func TestRestrictions_AllowMatch_ExplicitEmptyIsAccepted(t *testing.T) {
|
||||
// A client echoing back an empty allow_match means the default, the same as
|
||||
// omitting it, and must not be rejected as an invalid enum value.
|
||||
empty := api.AccessRestrictionsAllowMatch("")
|
||||
model, err := restrictionsFromAPI(&api.AccessRestrictions{
|
||||
AllowedCidrs: &[]string{"203.0.113.0/24"},
|
||||
AllowMatch: &empty,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
assert.Empty(t, model.AllowMatch, "explicit empty allow_match stays empty, meaning all")
|
||||
}
|
||||
|
||||
func TestRestrictions_AllowMatchOnly_Preserved(t *testing.T) {
|
||||
// allow_match set without any list must not be dropped by the emptiness
|
||||
// guards, so it round-trips through both the API and proto conversions.
|
||||
|
||||
Reference in New Issue
Block a user