1
0
mirror of https://github.com/juanfont/headscale.git synced 2024-12-20 19:09:07 +01:00
juanfont.headscale/acls_types.go

80 lines
1.8 KiB
Go
Raw Normal View History

2021-07-03 11:55:32 +02:00
package headscale
import (
2021-11-05 08:24:00 +01:00
"encoding/json"
2021-07-03 11:55:32 +02:00
"strings"
2021-07-03 17:31:32 +02:00
"github.com/tailscale/hujson"
2021-07-03 11:55:32 +02:00
"inet.af/netaddr"
)
2021-11-13 09:39:04 +01:00
// ACLPolicy represents a Tailscale ACL Policy.
2021-07-03 11:55:32 +02:00
type ACLPolicy struct {
Groups Groups `json:"Groups"`
Hosts Hosts `json:"Hosts"`
TagOwners TagOwners `json:"TagOwners"`
ACLs []ACL `json:"ACLs"`
Tests []ACLTest `json:"Tests"`
}
2021-11-13 09:39:04 +01:00
// ACL is a basic rule for the ACL Policy.
2021-07-03 11:55:32 +02:00
type ACL struct {
Action string `json:"Action"`
Users []string `json:"Users"`
Ports []string `json:"Ports"`
}
2021-11-13 09:39:04 +01:00
// Groups references a series of alias in the ACL rules.
2021-07-03 11:55:32 +02:00
type Groups map[string][]string
2021-11-13 09:39:04 +01:00
// Hosts are alias for IP addresses or subnets.
2021-07-03 17:31:32 +02:00
type Hosts map[string]netaddr.IPPrefix
2021-07-03 11:55:32 +02:00
2021-11-13 09:39:04 +01:00
// TagOwners specify what users (namespaces?) are allow to use certain tags.
2021-07-03 17:31:32 +02:00
type TagOwners map[string][]string
2021-07-03 11:55:32 +02:00
2021-11-13 09:39:04 +01:00
// ACLTest is not implemented, but should be use to check if a certain rule is allowed.
2021-07-03 11:55:32 +02:00
type ACLTest struct {
User string `json:"User"`
Allow []string `json:"Allow"`
Deny []string `json:"Deny,omitempty"`
}
2021-11-13 09:39:04 +01:00
// UnmarshalJSON allows to parse the Hosts directly into netaddr objects.
func (hosts *Hosts) UnmarshalJSON(data []byte) error {
newHosts := Hosts{}
hostIPPrefixMap := make(map[string]string)
2021-11-05 08:24:00 +01:00
ast, err := hujson.Parse(data)
if err != nil {
return err
}
ast.Standardize()
data = ast.Pack()
err = json.Unmarshal(data, &hostIPPrefixMap)
2021-07-03 17:31:32 +02:00
if err != nil {
return err
2021-07-03 11:55:32 +02:00
}
for host, prefixStr := range hostIPPrefixMap {
if !strings.Contains(prefixStr, "/") {
prefixStr += "/32"
2021-07-03 11:55:32 +02:00
}
prefix, err := netaddr.ParseIPPrefix(prefixStr)
2021-07-03 11:55:32 +02:00
if err != nil {
2021-07-03 17:31:32 +02:00
return err
2021-07-03 11:55:32 +02:00
}
newHosts[host] = prefix
2021-07-03 11:55:32 +02:00
}
*hosts = newHosts
2021-11-14 16:46:09 +01:00
2021-07-03 17:31:32 +02:00
return nil
}
2021-11-13 09:39:04 +01:00
// IsZero is perhaps a bit naive here.
func (policy ACLPolicy) IsZero() bool {
if len(policy.Groups) == 0 && len(policy.Hosts) == 0 && len(policy.ACLs) == 0 {
2021-07-03 17:31:32 +02:00
return true
}
2021-11-14 16:46:09 +01:00
2021-07-03 17:31:32 +02:00
return false
2021-07-03 11:55:32 +02:00
}