headscale/hscontrol
Kristoffer Dalby b2ab5ac1ad
resolve user identifier to stable ID
currently, the policy approach node to user matching
with a quite naive approach looking at the username
provided in the policy and matched it with the username
on the nodes. This worked ok as long as usernames were
unique and did not change.

As usernames are no longer guarenteed to be unique in
an OIDC environment we cant rely on this.

This changes the mechanism that matches the user string
(now user token) with nodes:

- first find all potential users by looking up:
  - database ID
  - provider ID (OIDC)
  - username/email

If more than one user is matching, then the query is
rejected, and zero matching nodes are returned.

When a single user is found, the node is matched against
the User database ID, which are also present on the actual
node.

This means that from this commit, users can use the following
to identify users in the policy:
- provider identity (iss + sub)
- username
- email
- database id

There are more changes coming to this, so it is not recommended
to start using any of these new abilities, with the exception
of email, which will not change since it includes an @.

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>
2024-11-19 09:50:53 +01:00
..
assets update flake, fix prettier lint 2023-09-05 08:47:43 +02:00
db resolve user identifier to stable ID 2024-11-19 09:50:53 +01:00
derp feat: derpmap field in config (#1823) 2024-10-17 05:34:20 -06:00
mapper resolve user identifier to stable ID 2024-11-19 09:50:53 +01:00
notifier Fix slow shutdown (#2113) 2024-09-09 14:10:22 +02:00
policy resolve user identifier to stable ID 2024-11-19 09:50:53 +01:00
templates Feature tvos documentation (#2226) 2024-11-07 14:56:18 +00:00
types add new user fields to grpc and list command (#2202) 2024-10-18 14:20:03 +00:00
util #2177 Added conversion of 'Hostname' to 'givenName' in a node with FQDN rules applied (#2198) 2024-10-15 18:33:03 +02:00
app.go resolve user identifier to stable ID 2024-11-19 09:50:53 +01:00
auth.go Redo OIDC configuration (#2020) 2024-10-02 14:50:17 +02:00
auth_noise.go metrics, tuning in tests, db cleanups, fix concurrency issue (#1895) 2024-04-21 18:28:17 +02:00
grpcv1.go resolve user identifier to stable ID 2024-11-19 09:50:53 +01:00
grpcv1_test.go rename package name to hscontrol 2023-05-10 20:47:51 +02:00
handlers.go Changed all the html into go using go-elem (#2161) 2024-10-04 11:39:24 +00:00
metrics.go Handle /derp/latency-check (#2227) 2024-11-06 15:59:38 +01:00
noise.go cleanup linter warnings (#2206) 2024-10-23 10:45:59 -05:00
oidc.go Redo OIDC configuration (#2020) 2024-10-02 14:50:17 +02:00
platform_config.go Changed all the html into go using go-elem (#2161) 2024-10-04 11:39:24 +00:00
poll.go #2140 Fixed reflection of hostname change (#2199) 2024-10-17 09:45:33 -06:00
suite_test.go Redo OIDC configuration (#2020) 2024-10-02 14:50:17 +02:00
tailsql.go Use result of fmt.Errorf call (#1668) 2024-02-15 11:02:54 +01:00