Compare commits

...

1 Commits

Author SHA1 Message Date
Zoltán Papp
4429f5cf7b [client] Send the login hint from the desktop UI's session extend
RequestExtend left the hint empty and relied on the daemon's
GetLoginHint fallback. That fallback reads the per-profile state file
from the calling process's user config dir, so the root-owned daemon
looks under /root/.config/netbird and never finds the file the UI wrote
under the user's own config dir. Every session extend therefore went out
without a login_hint, leaving the IdP to guess the account.

Resolve it in the UI instead, which runs as the logged-in user and
already reads the same file for Profiles.List. Mirrors what the CLI's
extend path does.
2026-08-15 01:02:42 +02:00
2 changed files with 9 additions and 0 deletions

View File

@@ -165,6 +165,11 @@ func (pm *ProfileManager) setActiveProfileState(id ID) error {
}
// GetLoginHint retrieves the email from the active profile to use as login_hint.
//
// TODO: only works when called as the logged-in user; the root-owned daemon
// resolves the state file under /root/.config/netbird and always gets "".
// Every caller now fills the hint itself, so dropping this and the daemon-side
// fallbacks in client/server/server.go is the suggested fix.
func GetLoginHint() string {
pm := NewProfileManager()
activeProf, err := pm.GetActiveProfile()

View File

@@ -9,6 +9,7 @@ import (
"google.golang.org/grpc/codes"
gstatus "google.golang.org/grpc/status"
"github.com/netbirdio/netbird/client/internal/profilemanager"
"github.com/netbirdio/netbird/client/proto"
)
@@ -60,6 +61,9 @@ func (s *Session) RequestExtend(ctx context.Context, p ExtendStartParams) (Exten
// a request from the UI implies a graphical session, which the daemon cannot detect itself
req := &proto.RequestExtendAuthSessionRequest{HasGraphicalSession: true}
if p.Hint == "" {
p.Hint = profilemanager.GetLoginHint()
}
if p.Hint != "" {
h := p.Hint
req.Hint = &h