mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-03 20:19:07 +02:00
Cluster targets dial the upstream via the host network stack, so an
empty Host leaves the proxy with nothing to dial and DirectUpstream=false
would route the request through the embedded NetBird client (wrong
network for a cluster address). Validate() and validateTargetReferences
now reject both shapes.
Tests:
- TestValidate_HTTPClusterTarget / _RequiresTargetId /
TestValidate_Private_{AcceptsClusterTargetWithAccessGroups,
RequiresAccessGroups, RejectsBearerAuth} updated to populate Host and
DirectUpstream so they exercise the path past the new gates.
- TestValidate_HTTPClusterTarget_RequiresHost and _RequiresDirectUpstream
pin the two new error paths.
- TestValidateTargetReferences_ClusterTargetSkipsLookup updated to set
DirectUpstream on its fixture; new _ClusterTargetRequiresDirectUpstream
test covers the store-side rejection.
Drive-bys (no behavior change beyond what existing tests cover):
- proxy/proxy.go: shortened the Capabilities.Private / Cluster.Private
doc comments.
- users/manager.go: moved the GetUserWithGroups doc from the interface
to the impl.
- proxy/cmd/proxy/cmd/root.go: removed unused NewRootCmd.
- tunnel_cache.go: bumped tunnelCacheTTL from 30s to 300s (matches the
"5 minutes" target documented on the constant; existing TTL-expiry
test uses the constant directly so the bump is picked up automatically).
83 lines
2.4 KiB
Go
83 lines
2.4 KiB
Go
package users
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
|
|
"github.com/netbirdio/netbird/management/server/store"
|
|
"github.com/netbirdio/netbird/management/server/types"
|
|
)
|
|
|
|
type Manager interface {
|
|
GetUser(ctx context.Context, userID string) (*types.User, error)
|
|
GetUserWithGroups(ctx context.Context, userID string) (*types.User, []*types.Group, error)
|
|
}
|
|
|
|
type managerImpl struct {
|
|
store store.Store
|
|
}
|
|
|
|
type managerMock struct {
|
|
}
|
|
|
|
func NewManager(store store.Store) Manager {
|
|
return &managerImpl{
|
|
store: store,
|
|
}
|
|
}
|
|
|
|
func (m *managerImpl) GetUser(ctx context.Context, userID string) (*types.User, error) {
|
|
return m.store.GetUserByUserID(ctx, store.LockingStrengthNone, userID)
|
|
}
|
|
|
|
// GetUserWithGroups returns the user and the *types.Group records for the user's AutoGroups, in the same order as
|
|
// AutoGroups. Group ids that don't resolve to a stored group are skipped from the returned slice (the parallel id list is
|
|
// derivable from the returned User). Wraps two store calls today; can be optimised to a single JOIN later if needed.
|
|
func (m *managerImpl) GetUserWithGroups(ctx context.Context, userID string) (*types.User, []*types.Group, error) {
|
|
user, err := m.store.GetUserByUserID(ctx, store.LockingStrengthNone, userID)
|
|
if err != nil {
|
|
return nil, nil, err
|
|
}
|
|
if len(user.AutoGroups) == 0 {
|
|
return user, nil, nil
|
|
}
|
|
groupsMap, err := m.store.GetGroupsByIDs(ctx, store.LockingStrengthNone, user.AccountID, user.AutoGroups)
|
|
if err != nil {
|
|
return user, nil, err
|
|
}
|
|
groups := make([]*types.Group, 0, len(user.AutoGroups))
|
|
for _, id := range user.AutoGroups {
|
|
if g, ok := groupsMap[id]; ok && g != nil {
|
|
groups = append(groups, g)
|
|
}
|
|
}
|
|
return user, groups, nil
|
|
}
|
|
|
|
func NewManagerMock() Manager {
|
|
return &managerMock{}
|
|
}
|
|
|
|
func (m *managerMock) GetUser(ctx context.Context, userID string) (*types.User, error) {
|
|
switch userID {
|
|
case "adminUser":
|
|
return &types.User{Id: userID, Role: types.UserRoleAdmin}, nil
|
|
case "regularUser":
|
|
return &types.User{Id: userID, Role: types.UserRoleUser}, nil
|
|
case "ownerUser":
|
|
return &types.User{Id: userID, Role: types.UserRoleOwner}, nil
|
|
case "billingUser":
|
|
return &types.User{Id: userID, Role: types.UserRoleBillingAdmin}, nil
|
|
default:
|
|
return nil, errors.New("user not found")
|
|
}
|
|
}
|
|
|
|
func (m *managerMock) GetUserWithGroups(ctx context.Context, userID string) (*types.User, []*types.Group, error) {
|
|
user, err := m.GetUser(ctx, userID)
|
|
if err != nil {
|
|
return nil, nil, err
|
|
}
|
|
return user, nil, nil
|
|
}
|