mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-11 17:29:07 +02:00
Collect auth requirements for bidirectional source peers and fix follow-up review findings
This commit is contained in:
@@ -362,26 +362,34 @@ func (nmd *NetworkMapData) getPeersGroupsPoliciesRoutes(
|
||||
}
|
||||
}
|
||||
|
||||
// Both marker protocols resolve authorized users the same way,
|
||||
// so a VNC rule needs the same inputs an SSH rule does. Leaving
|
||||
// VNC out here strips the group mapping and the allowed-user set
|
||||
// from the components, and the rule then reaches the resolver
|
||||
// with nobody authorized.
|
||||
if rule.Protocol == string(types.PolicyRuleProtocolNetbirdSSH) ||
|
||||
rule.Protocol == string(types.PolicyRuleProtocolNetbirdVNC) {
|
||||
switch {
|
||||
case len(rule.AuthorizedGroups) > 0:
|
||||
for groupID := range rule.AuthorizedGroups {
|
||||
authReqs.neededGroupIDs[groupID] = struct{}{}
|
||||
}
|
||||
case rule.AuthorizedUser != "":
|
||||
// Carries its own user; no lookup inputs needed.
|
||||
default:
|
||||
authReqs.needAllowedUserIDs = true
|
||||
}
|
||||
|
||||
// Collected for whichever side the resolver will actually authorize:
|
||||
// a bidirectional rule grants access in both directions, so a peer
|
||||
// that appears only in Sources is authorized too. Gating this on
|
||||
// peerInDestinations alone leaves that peer's rule reaching the
|
||||
// resolver with none of the inputs it needs to name a user.
|
||||
//
|
||||
// Both marker protocols resolve users the same way, so VNC needs
|
||||
// exactly what SSH needs.
|
||||
receivingPeer := peerInDestinations || (rule.Bidirectional && peerInSources)
|
||||
if !receivingPeer {
|
||||
continue
|
||||
}
|
||||
if rule.Protocol == string(types.PolicyRuleProtocolNetbirdSSH) ||
|
||||
rule.Protocol == string(types.PolicyRuleProtocolNetbirdVNC) {
|
||||
switch {
|
||||
case len(rule.AuthorizedGroups) > 0:
|
||||
for groupID := range rule.AuthorizedGroups {
|
||||
authReqs.neededGroupIDs[groupID] = struct{}{}
|
||||
}
|
||||
} else if nmdata.PolicyRuleImpliesLegacySSH(rule) && peerSSHEnabled {
|
||||
case rule.AuthorizedUser != "":
|
||||
// Carries its own user; no lookup inputs needed.
|
||||
default:
|
||||
authReqs.needAllowedUserIDs = true
|
||||
}
|
||||
} else if nmdata.PolicyRuleImpliesLegacySSH(rule) && peerSSHEnabled {
|
||||
authReqs.needAllowedUserIDs = true
|
||||
}
|
||||
}
|
||||
if policyRelevant {
|
||||
|
||||
@@ -961,12 +961,23 @@ func TestGetPeerNetworkMapComponents_SSHRequirements(t *testing.T) {
|
||||
mutateRule: func(r *nmdata.PolicyRule) { r.Ports = []string{"443"} },
|
||||
sshEnabled: true,
|
||||
},
|
||||
// A bidirectional rule grants access both ways, so the peer is
|
||||
// authorized from the sources side too and needs the same inputs.
|
||||
{
|
||||
name: "netbird-ssh only counts on the destination side",
|
||||
name: "netbird-ssh on the source side of a bidirectional rule",
|
||||
mutateRule: func(r *nmdata.PolicyRule) {
|
||||
r.Protocol = string(nbtypes.PolicyRuleProtocolNetbirdSSH)
|
||||
},
|
||||
targetInSrc: true,
|
||||
wantAllowed: true,
|
||||
},
|
||||
{
|
||||
name: "netbird-ssh on the source side of a one-way rule",
|
||||
mutateRule: func(r *nmdata.PolicyRule) {
|
||||
r.Protocol = string(nbtypes.PolicyRuleProtocolNetbirdSSH)
|
||||
r.Bidirectional = false
|
||||
},
|
||||
targetInSrc: true,
|
||||
},
|
||||
|
||||
// VNC resolves authorized users exactly the way SSH does, so it needs
|
||||
@@ -995,11 +1006,20 @@ func TestGetPeerNetworkMapComponents_SSHRequirements(t *testing.T) {
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "netbird-vnc only counts on the destination side",
|
||||
name: "netbird-vnc on the source side of a bidirectional rule",
|
||||
mutateRule: func(r *nmdata.PolicyRule) {
|
||||
r.Protocol = string(nbtypes.PolicyRuleProtocolNetbirdVNC)
|
||||
},
|
||||
targetInSrc: true,
|
||||
wantAllowed: true,
|
||||
},
|
||||
{
|
||||
name: "netbird-vnc on the source side of a one-way rule",
|
||||
mutateRule: func(r *nmdata.PolicyRule) {
|
||||
r.Protocol = string(nbtypes.PolicyRuleProtocolNetbirdVNC)
|
||||
r.Bidirectional = false
|
||||
},
|
||||
targetInSrc: true,
|
||||
},
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user