mirror of
https://github.com/juanfont/headscale.git
synced 2025-08-14 13:51:01 +02:00
Fix /machine/map
endpoint vulnerability (#2642)
* Improve map auth logic * Bugfix * Add comment, improve error message * noise: make func, get by node this commit splits the additional validation into a separate function so it can be reused if we add more endpoints in the future. It swaps the check, so we still look up by NodeKey, but before accepting the connection, we validate the known machinekey from the db against the noise connection. The reason for this is that when a node logs in or out, the node key is replaced and it will no longer be possible to look it up, breaking reauthentication. Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com> Co-authored-by: Kristoffer Dalby <kristoffer@tailscale.com>
This commit is contained in:
parent
e7fe645be5
commit
7d3e7a28e2
@ -1,6 +1,12 @@
|
|||||||
# CHANGELOG
|
# CHANGELOG
|
||||||
|
|
||||||
## Next
|
## 0.26.1 (2025-06-06)
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
|
||||||
|
- Ensure nodes are matching both node key and machine key
|
||||||
|
when connecting.
|
||||||
|
[#2642](https://github.com/juanfont/headscale/pull/2642)
|
||||||
|
|
||||||
### Database integrity improvements
|
### Database integrity improvements
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user