Files
netbird/management/server/permissions
mlsmaycon c995d89830 Redact provider connection config for read-only viewers and canonicalize Bedrock ids in setup
The provider read grant now serves usage_viewer the display surface only:
the manager blanks upstream URL, operator-typed header values, identity
header names, and the TLS override for callers holding read without
update. The me/setup model intersection compares declared ids through the
same normalization the proxy's parser applies, so a Bedrock declaration
in region/version form still advertises when its canonical id is
allowlisted. Docs and comments now say account-wide for the logs
exclusion and describe the real group source shared with enforcement.
2026-08-27 08:07:20 +00:00
..