mirror of
https://github.com/Buriburizaem0n/nezha_domains.git
synced 2026-09-19 09:40:12 +00:00
fix(rpc): allow global agent secret across server owners
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
This commit is contained in:
@@ -101,6 +101,11 @@ func authorizeAgentForUUID(userId uint64, clientUUID string) (clientID uint64, h
|
||||
// Treat as unknown (registration path) rather than impersonation.
|
||||
return 0, false, nil
|
||||
}
|
||||
if userId == 0 {
|
||||
// The legacy global agent secret maps to user 0. It predates per-user
|
||||
// agent secrets, so keep it compatible by allowing any existing UUID.
|
||||
return cid, true, nil
|
||||
}
|
||||
if server.UserID != userId {
|
||||
return 0, false, fmt.Errorf("client UUID does not belong to the agent secret owner")
|
||||
}
|
||||
|
||||
@@ -73,6 +73,18 @@ func TestAuthorizeAgentForUUIDRejectsForeignServerUUID(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestAuthorizeAgentForUUIDAllowsGlobalDefaultSecret(t *testing.T) {
|
||||
defer setupAuthAgentFixture(t)()
|
||||
|
||||
cid, hasID, err := authorizeAgentForUUID(0, "uuid-bob")
|
||||
if err != nil {
|
||||
t.Fatalf("global default secret must be allowed to use existing UUIDs, got %v", err)
|
||||
}
|
||||
if !hasID || cid != 2 {
|
||||
t.Fatalf("expected (cid=2, hasID=true), got (cid=%d, hasID=%v)", cid, hasID)
|
||||
}
|
||||
}
|
||||
|
||||
// An unknown UUID must NOT be treated as an impersonation attempt — it is
|
||||
// the normal first-time registration path and the caller (Check) creates a
|
||||
// new server bound to the secret owner.
|
||||
|
||||
Reference in New Issue
Block a user