mirror of
https://github.com/Buriburizaem0n/nezha_domains.git
synced 2026-09-19 17:50:12 +00:00
fix(rpc): allow global agent secret across server owners
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
This commit is contained in:
@@ -101,6 +101,11 @@ func authorizeAgentForUUID(userId uint64, clientUUID string) (clientID uint64, h
|
|||||||
// Treat as unknown (registration path) rather than impersonation.
|
// Treat as unknown (registration path) rather than impersonation.
|
||||||
return 0, false, nil
|
return 0, false, nil
|
||||||
}
|
}
|
||||||
|
if userId == 0 {
|
||||||
|
// The legacy global agent secret maps to user 0. It predates per-user
|
||||||
|
// agent secrets, so keep it compatible by allowing any existing UUID.
|
||||||
|
return cid, true, nil
|
||||||
|
}
|
||||||
if server.UserID != userId {
|
if server.UserID != userId {
|
||||||
return 0, false, fmt.Errorf("client UUID does not belong to the agent secret owner")
|
return 0, false, fmt.Errorf("client UUID does not belong to the agent secret owner")
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -73,6 +73,18 @@ func TestAuthorizeAgentForUUIDRejectsForeignServerUUID(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAuthorizeAgentForUUIDAllowsGlobalDefaultSecret(t *testing.T) {
|
||||||
|
defer setupAuthAgentFixture(t)()
|
||||||
|
|
||||||
|
cid, hasID, err := authorizeAgentForUUID(0, "uuid-bob")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("global default secret must be allowed to use existing UUIDs, got %v", err)
|
||||||
|
}
|
||||||
|
if !hasID || cid != 2 {
|
||||||
|
t.Fatalf("expected (cid=2, hasID=true), got (cid=%d, hasID=%v)", cid, hasID)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// An unknown UUID must NOT be treated as an impersonation attempt — it is
|
// An unknown UUID must NOT be treated as an impersonation attempt — it is
|
||||||
// the normal first-time registration path and the caller (Check) creates a
|
// the normal first-time registration path and the caller (Check) creates a
|
||||||
// new server bound to the secret owner.
|
// new server bound to the secret owner.
|
||||||
|
|||||||
Reference in New Issue
Block a user