hub: S1 wgsync (pinned-SSH push + declarative reconciler) + /admin/wg API + env wiring
internal/wgsync: x/crypto/ssh client with ssh.FixedHostKey pin (no insecure fallback), forced-command exec, ok/applied response contract; Reconciler pushes the FULL peer list on Trigger or 5-min tick (drift repair by construction). internal/api/wg.go: PUT/GET /admin/wg/endpoint + POST/DELETE/GET /admin/wg/peers, global-key-only, pubkey in body (base64 vs URL), sync ok|deferred|disabled. main.go: WG_ENDPOINT_SSH_* env wiring, disabled-with-INFO when unconfigured. Groups B/C/D tests incl. in-process SSH server; red-proofs b/c/d run + reverted. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
This commit is contained in:
@@ -49,6 +49,10 @@ type Handler struct {
|
||||
mailSender mailrelay.Sender
|
||||
mailLimiter *mailRateLimiter
|
||||
mailFromAllow map[string]bool
|
||||
|
||||
// S1 offsite connectivity: the wgsync reconciler seam (internal/api/wg.go). nil = peer-sync
|
||||
// disabled — mutations still persist, responses carry sync:"disabled".
|
||||
wgSyncer WGSyncer
|
||||
}
|
||||
|
||||
// SetLatestVersionProvider wires the registry version checker so the controller report ACK can
|
||||
@@ -187,6 +191,18 @@ func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
case r.Method == http.MethodPost && strings.HasPrefix(path, "/admin/hosts/") && strings.HasSuffix(path, "/jobs"):
|
||||
hostID := strings.TrimSuffix(strings.TrimPrefix(path, "/admin/hosts/"), "/jobs")
|
||||
h.handleAdminEnqueueJob(w, r, hostID)
|
||||
// S1 offsite connectivity — WG endpoint record + peer registry (global key only, api/wg.go).
|
||||
// DELETE carries the pubkey in the body: base64 '/'+'+' keep pubkeys out of URL paths.
|
||||
case r.Method == http.MethodPut && path == "/admin/wg/endpoint":
|
||||
h.handleAdminSetWGEndpoint(w, r)
|
||||
case r.Method == http.MethodGet && path == "/admin/wg/endpoint":
|
||||
h.handleAdminGetWGEndpoint(w, r)
|
||||
case r.Method == http.MethodPost && path == "/admin/wg/peers":
|
||||
h.handleAdminAddWGPeer(w, r)
|
||||
case r.Method == http.MethodDelete && path == "/admin/wg/peers":
|
||||
h.handleAdminDeleteWGPeer(w, r)
|
||||
case r.Method == http.MethodGet && path == "/admin/wg/peers":
|
||||
h.handleAdminListWGPeers(w, r)
|
||||
case r.Method == http.MethodPost && path == "/event":
|
||||
h.handleEvent(w, r)
|
||||
case r.Method == http.MethodPost && path == "/mail":
|
||||
|
||||
@@ -0,0 +1,264 @@
|
||||
package api
|
||||
|
||||
// S1 offsite connectivity (doc 06 §3.2/§5): the operator admin surface for the WG endpoint
|
||||
// record + peer registry. GLOBAL key ONLY on every route (the handleAdminSetDesiredState gate) —
|
||||
// a per-host key must never author the peer list; the box-facing registration path is S2.
|
||||
// DELETE takes the pubkey in the JSON body: WG pubkeys are std base64 ('/' and '+'), so a pubkey
|
||||
// NEVER appears in a URL path — and no, URL-escaping is not the fix (see the S1 spec §8).
|
||||
|
||||
import (
|
||||
"context"
|
||||
"database/sql"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/netip"
|
||||
"time"
|
||||
|
||||
"gitea.dooplex.hu/admin/felhom-hub/internal/store"
|
||||
)
|
||||
|
||||
// WGSyncer is the reconciler seam (satisfied by *wgsync.Reconciler; tests inject a fake). nil =
|
||||
// peer-sync disabled: mutations still hit the DB (the source of truth) and report sync:"disabled".
|
||||
type WGSyncer interface {
|
||||
SyncNow(ctx context.Context) error
|
||||
Trigger()
|
||||
}
|
||||
|
||||
// SetWGSyncer wires the wgsync reconciler (mirror of SetLatestVersionProvider; nil-safe).
|
||||
func (h *Handler) SetWGSyncer(s WGSyncer) {
|
||||
h.wgSyncer = s
|
||||
}
|
||||
|
||||
// validateWGPubkey enforces the exact WG public-key shape: 44 chars of std base64 decoding to
|
||||
// 32 bytes. Anything else is rejected before any allocation.
|
||||
func validateWGPubkey(pk string) error {
|
||||
if len(pk) != 44 {
|
||||
return fmt.Errorf("pubkey must be 44 base64 chars, got %d", len(pk))
|
||||
}
|
||||
raw, err := base64.StdEncoding.DecodeString(pk)
|
||||
if err != nil {
|
||||
return fmt.Errorf("pubkey is not valid base64: %v", err)
|
||||
}
|
||||
if len(raw) != 32 {
|
||||
return fmt.Errorf("pubkey must decode to 32 bytes, got %d", len(raw))
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// syncAfterMutation runs an inline sync after a peer mutation. The DB write already happened —
|
||||
// it is the source of truth — so a push failure is REPORTED, not rolled back: the reconciler's
|
||||
// next tick converges the endpoint (Scenario D).
|
||||
func (h *Handler) syncAfterMutation(ctx context.Context) string {
|
||||
if h.wgSyncer == nil {
|
||||
return "disabled"
|
||||
}
|
||||
syncCtx, cancel := context.WithTimeout(ctx, 10*time.Second)
|
||||
defer cancel()
|
||||
if err := h.wgSyncer.SyncNow(syncCtx); err != nil {
|
||||
h.logger.Printf("[ERROR] wgsync: inline push after mutation failed: %v (reconciler will retry)", err)
|
||||
h.wgSyncer.Trigger()
|
||||
return "deferred: " + err.Error()
|
||||
}
|
||||
return "ok"
|
||||
}
|
||||
|
||||
// handleAdminSetWGEndpoint — PUT /admin/wg/endpoint. Upserts the endpoint record.
|
||||
func (h *Handler) handleAdminSetWGEndpoint(w http.ResponseWriter, r *http.Request) {
|
||||
_, _, isGlobal, ok := h.checkAuthHost(r)
|
||||
if !ok || !isGlobal {
|
||||
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
body, err := io.ReadAll(io.LimitReader(r.Body, 1<<20))
|
||||
if err != nil {
|
||||
http.Error(w, "Bad request", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
var req struct {
|
||||
EndpointID string `json:"endpoint_id"`
|
||||
DNSName string `json:"dns_name"`
|
||||
WGPort int `json:"wg_port"`
|
||||
ServerPubkey string `json:"server_pubkey"`
|
||||
TunnelSubnet string `json:"tunnel_subnet"`
|
||||
PBSTunnelIP string `json:"pbs_tunnel_ip"`
|
||||
}
|
||||
if err := json.Unmarshal(body, &req); err != nil {
|
||||
http.Error(w, "Invalid payload: body must be JSON", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
if req.DNSName == "" {
|
||||
http.Error(w, "Invalid payload: dns_name required", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
if req.WGPort < 1 || req.WGPort > 65535 {
|
||||
http.Error(w, "Invalid payload: wg_port must be 1-65535", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
if err := validateWGPubkey(req.ServerPubkey); err != nil {
|
||||
http.Error(w, "Invalid payload: server_pubkey: "+err.Error(), http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
prefix, err := netip.ParsePrefix(req.TunnelSubnet)
|
||||
if err != nil {
|
||||
http.Error(w, "Invalid payload: tunnel_subnet must be CIDR", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
pbsAddr, err := netip.ParseAddr(req.PBSTunnelIP)
|
||||
if err != nil || !prefix.Contains(pbsAddr) {
|
||||
http.Error(w, "Invalid payload: pbs_tunnel_ip must be an address inside tunnel_subnet", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
if err := h.store.SetWGEndpoint(&store.WGEndpoint{
|
||||
EndpointID: req.EndpointID, DNSName: req.DNSName, WGPort: req.WGPort,
|
||||
ServerPubkey: req.ServerPubkey, TunnelSubnet: req.TunnelSubnet, PBSTunnelIP: req.PBSTunnelIP,
|
||||
}); err != nil {
|
||||
h.logger.Printf("[ERROR] set wg endpoint: %v", err)
|
||||
http.Error(w, "Internal error", http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
h.logger.Printf("[INFO] wg endpoint set: %s (%s:%d, subnet %s)", req.DNSName, req.DNSName, req.WGPort, req.TunnelSubnet)
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(http.StatusOK)
|
||||
w.Write([]byte(`{"status":"ok"}`))
|
||||
}
|
||||
|
||||
// handleAdminGetWGEndpoint — GET /admin/wg/endpoint.
|
||||
func (h *Handler) handleAdminGetWGEndpoint(w http.ResponseWriter, r *http.Request) {
|
||||
_, _, isGlobal, ok := h.checkAuthHost(r)
|
||||
if !ok || !isGlobal {
|
||||
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
e, err := h.store.GetWGEndpoint()
|
||||
if err == sql.ErrNoRows {
|
||||
http.Error(w, "wg endpoint not configured", http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
h.logger.Printf("[ERROR] get wg endpoint: %v", err)
|
||||
http.Error(w, "Internal error", http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{
|
||||
"endpoint_id": e.EndpointID, "dns_name": e.DNSName, "wg_port": e.WGPort,
|
||||
"server_pubkey": e.ServerPubkey, "tunnel_subnet": e.TunnelSubnet, "pbs_tunnel_ip": e.PBSTunnelIP,
|
||||
})
|
||||
}
|
||||
|
||||
// handleAdminAddWGPeer — POST /admin/wg/peers. Allocates a /32 (idempotent on pubkey) and
|
||||
// pushes the full list inline (sync semantics: ok | deferred | disabled).
|
||||
func (h *Handler) handleAdminAddWGPeer(w http.ResponseWriter, r *http.Request) {
|
||||
_, _, isGlobal, ok := h.checkAuthHost(r)
|
||||
if !ok || !isGlobal {
|
||||
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
body, err := io.ReadAll(io.LimitReader(r.Body, 1<<20))
|
||||
if err != nil {
|
||||
http.Error(w, "Bad request", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
var req struct {
|
||||
Pubkey string `json:"pubkey"`
|
||||
HostID string `json:"host_id"`
|
||||
Note string `json:"note"`
|
||||
}
|
||||
if err := json.Unmarshal(body, &req); err != nil {
|
||||
http.Error(w, "Invalid payload: body must be JSON", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
if err := validateWGPubkey(req.Pubkey); err != nil {
|
||||
http.Error(w, "Invalid payload: "+err.Error(), http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
ip, existed, err := h.store.AddWGPeer(req.Pubkey, req.HostID, req.Note)
|
||||
if err == store.ErrWGEndpointUnset {
|
||||
http.Error(w, "wg endpoint not configured", http.StatusConflict)
|
||||
return
|
||||
}
|
||||
if err == store.ErrWGSubnetExhausted {
|
||||
http.Error(w, "tunnel subnet exhausted", http.StatusConflict)
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
h.logger.Printf("[ERROR] add wg peer: %v", err)
|
||||
http.Error(w, "Internal error", http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
syncStatus := h.syncAfterMutation(r.Context())
|
||||
h.logger.Printf("[INFO] wg peer added: %s -> %s/32 (existed=%v, sync=%s)", req.Pubkey, ip, existed, syncStatus)
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(http.StatusOK)
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{
|
||||
"pubkey": req.Pubkey, "assigned_ip": ip + "/32", "existed": existed, "sync": syncStatus,
|
||||
})
|
||||
}
|
||||
|
||||
// handleAdminDeleteWGPeer — DELETE /admin/wg/peers, pubkey in the JSON body (never the URL).
|
||||
// Unknown pubkey → 404 with NO sync (nothing changed). Known → delete + inline push: the pushed
|
||||
// full list no longer contains the peer, so revocation lands with the push (Scenario B).
|
||||
func (h *Handler) handleAdminDeleteWGPeer(w http.ResponseWriter, r *http.Request) {
|
||||
_, _, isGlobal, ok := h.checkAuthHost(r)
|
||||
if !ok || !isGlobal {
|
||||
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
body, err := io.ReadAll(io.LimitReader(r.Body, 1<<20))
|
||||
if err != nil {
|
||||
http.Error(w, "Bad request", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
var req struct {
|
||||
Pubkey string `json:"pubkey"`
|
||||
}
|
||||
if err := json.Unmarshal(body, &req); err != nil {
|
||||
http.Error(w, "Invalid payload: body must be JSON", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
if err := validateWGPubkey(req.Pubkey); err != nil {
|
||||
http.Error(w, "Invalid payload: "+err.Error(), http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
err = h.store.RemoveWGPeer(req.Pubkey)
|
||||
if err == sql.ErrNoRows {
|
||||
http.Error(w, "Unknown pubkey", http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
h.logger.Printf("[ERROR] remove wg peer: %v", err)
|
||||
http.Error(w, "Internal error", http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
syncStatus := h.syncAfterMutation(r.Context())
|
||||
h.logger.Printf("[INFO] wg peer removed: %s (sync=%s)", req.Pubkey, syncStatus)
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(http.StatusOK)
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{"status": "ok", "sync": syncStatus})
|
||||
}
|
||||
|
||||
// handleAdminListWGPeers — GET /admin/wg/peers. The verification surface (S2 builds UI on top).
|
||||
func (h *Handler) handleAdminListWGPeers(w http.ResponseWriter, r *http.Request) {
|
||||
_, _, isGlobal, ok := h.checkAuthHost(r)
|
||||
if !ok || !isGlobal {
|
||||
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
peers, err := h.store.ListWGPeers()
|
||||
if err != nil {
|
||||
h.logger.Printf("[ERROR] list wg peers: %v", err)
|
||||
http.Error(w, "Internal error", http.StatusInternalServerError)
|
||||
return
|
||||
}
|
||||
out := make([]map[string]interface{}, 0, len(peers))
|
||||
for _, p := range peers {
|
||||
out = append(out, map[string]interface{}{
|
||||
"pubkey": p.Pubkey, "assigned_ip": p.AssignedIP + "/32", "host_id": p.HostID, "note": p.Note,
|
||||
})
|
||||
}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{"peers": out})
|
||||
}
|
||||
@@ -0,0 +1,212 @@
|
||||
package api
|
||||
|
||||
// Group B — WG admin API auth + validation (Scenario C). Non-hollow: asserts store effects and
|
||||
// fake-syncer call counts, not just statuses.
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"testing"
|
||||
|
||||
"gitea.dooplex.hu/admin/felhom-hub/internal/store"
|
||||
)
|
||||
|
||||
// fakeWGSyncer counts SyncNow/Trigger calls; err scripts the SyncNow result.
|
||||
type fakeWGSyncer struct {
|
||||
syncCalls int
|
||||
triggerCalls int
|
||||
err error
|
||||
}
|
||||
|
||||
func (f *fakeWGSyncer) SyncNow(ctx context.Context) error { f.syncCalls++; return f.err }
|
||||
func (f *fakeWGSyncer) Trigger() { f.triggerCalls++ }
|
||||
|
||||
// testPK returns a VALID WG-shaped pubkey (44 std-base64 chars, 32 bytes) unique per fill byte.
|
||||
func testPK(fill byte) string {
|
||||
return base64.StdEncoding.EncodeToString(bytes.Repeat([]byte{fill}, 32))
|
||||
}
|
||||
|
||||
func putTestEndpoint(t *testing.T, h *Handler) {
|
||||
t.Helper()
|
||||
body := `{"dns_name":"ep0.example","wg_port":443,"server_pubkey":"` + testPK(9) + `",` +
|
||||
`"tunnel_subnet":"10.77.0.0/24","pbs_tunnel_ip":"10.77.0.1"}`
|
||||
rr := do(h, http.MethodPut, "/admin/wg/endpoint", globalKey, body)
|
||||
if rr.Code != http.StatusOK {
|
||||
t.Fatalf("PUT endpoint = %d: %s", rr.Code, rr.Body.String())
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_PerHostKeyForbidden(t *testing.T) {
|
||||
h, st, _ := newTestHandler(t)
|
||||
st.UpsertHost(&store.Host{HostID: "h1", CustomerID: "c1", APIKey: "HKEY"})
|
||||
putTestEndpoint(t, h)
|
||||
fake := &fakeWGSyncer{}
|
||||
h.SetWGSyncer(fake)
|
||||
|
||||
for _, m := range []string{http.MethodPost, http.MethodDelete, http.MethodGet} {
|
||||
rr := do(h, m, "/admin/wg/peers", "HKEY", `{"pubkey":"`+testPK(1)+`"}`)
|
||||
if rr.Code != http.StatusForbidden {
|
||||
t.Errorf("%s with per-host key = %d, want 403", m, rr.Code)
|
||||
}
|
||||
}
|
||||
rr := do(h, http.MethodPut, "/admin/wg/endpoint", "HKEY", `{}`)
|
||||
if rr.Code != http.StatusForbidden {
|
||||
t.Errorf("PUT endpoint with per-host key = %d, want 403", rr.Code)
|
||||
}
|
||||
peers, _ := st.ListWGPeers()
|
||||
if len(peers) != 0 {
|
||||
t.Errorf("rows created despite 403: %d", len(peers))
|
||||
}
|
||||
if fake.syncCalls != 0 {
|
||||
t.Errorf("sync ran despite 403: %d calls", fake.syncCalls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_AddHappyPath(t *testing.T) {
|
||||
h, st, _ := newTestHandler(t)
|
||||
putTestEndpoint(t, h)
|
||||
fake := &fakeWGSyncer{}
|
||||
h.SetWGSyncer(fake)
|
||||
|
||||
rr := do(h, http.MethodPost, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(1)+`","note":"test"}`)
|
||||
if rr.Code != http.StatusOK {
|
||||
t.Fatalf("POST = %d: %s", rr.Code, rr.Body.String())
|
||||
}
|
||||
var resp struct {
|
||||
Pubkey string `json:"pubkey"`
|
||||
AssignedIP string `json:"assigned_ip"`
|
||||
Existed bool `json:"existed"`
|
||||
Sync string `json:"sync"`
|
||||
}
|
||||
json.Unmarshal(rr.Body.Bytes(), &resp)
|
||||
if resp.AssignedIP != "10.77.0.2/32" || resp.Existed || resp.Sync != "ok" {
|
||||
t.Errorf("resp = %+v, want .2/32 existed=false sync=ok", resp)
|
||||
}
|
||||
if fake.syncCalls != 1 {
|
||||
t.Errorf("sync calls = %d, want 1", fake.syncCalls)
|
||||
}
|
||||
peers, _ := st.ListWGPeers()
|
||||
if len(peers) != 1 || peers[0].AssignedIP != "10.77.0.2" || peers[0].Note != "test" {
|
||||
t.Errorf("stored peers = %+v", peers)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_SyncDeferredOnPushFailure(t *testing.T) {
|
||||
h, _, _ := newTestHandler(t)
|
||||
putTestEndpoint(t, h)
|
||||
fake := &fakeWGSyncer{err: context.DeadlineExceeded}
|
||||
h.SetWGSyncer(fake)
|
||||
|
||||
rr := do(h, http.MethodPost, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(1)+`"}`)
|
||||
if rr.Code != http.StatusOK {
|
||||
t.Fatalf("POST = %d (DB write is source of truth; push failure must not fail the request)", rr.Code)
|
||||
}
|
||||
var resp struct {
|
||||
Sync string `json:"sync"`
|
||||
}
|
||||
json.Unmarshal(rr.Body.Bytes(), &resp)
|
||||
if len(resp.Sync) < 8 || resp.Sync[:8] != "deferred" {
|
||||
t.Errorf("sync = %q, want deferred:...", resp.Sync)
|
||||
}
|
||||
if fake.triggerCalls != 1 {
|
||||
t.Errorf("Trigger calls = %d, want 1 (reconciler retry requested)", fake.triggerCalls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_SyncDisabledWhenUnwired(t *testing.T) {
|
||||
h, _, _ := newTestHandler(t)
|
||||
putTestEndpoint(t, h)
|
||||
// no SetWGSyncer — nil seam
|
||||
rr := do(h, http.MethodPost, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(1)+`"}`)
|
||||
if rr.Code != http.StatusOK {
|
||||
t.Fatalf("POST = %d", rr.Code)
|
||||
}
|
||||
var resp struct {
|
||||
Sync string `json:"sync"`
|
||||
}
|
||||
json.Unmarshal(rr.Body.Bytes(), &resp)
|
||||
if resp.Sync != "disabled" {
|
||||
t.Errorf("sync = %q, want disabled", resp.Sync)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_BadPubkeyRejected(t *testing.T) {
|
||||
h, st, _ := newTestHandler(t)
|
||||
putTestEndpoint(t, h)
|
||||
bad := []string{
|
||||
"not-base64",
|
||||
base64.StdEncoding.EncodeToString(bytes.Repeat([]byte{1}, 16)), // 24 chars
|
||||
"!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!", // 44 chars, not base64
|
||||
base64.StdEncoding.EncodeToString(bytes.Repeat([]byte{1}, 33)), // 44 chars but 33 bytes
|
||||
}
|
||||
for _, pk := range bad {
|
||||
rr := do(h, http.MethodPost, "/admin/wg/peers", globalKey, `{"pubkey":"`+pk+`"}`)
|
||||
if rr.Code != http.StatusBadRequest {
|
||||
t.Errorf("pubkey %q = %d, want 400", pk, rr.Code)
|
||||
}
|
||||
}
|
||||
peers, _ := st.ListWGPeers()
|
||||
if len(peers) != 0 {
|
||||
t.Errorf("allocation happened for bad pubkey: %+v", peers)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_NoEndpointIs409(t *testing.T) {
|
||||
h, _, _ := newTestHandler(t)
|
||||
rr := do(h, http.MethodPost, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(1)+`"}`)
|
||||
if rr.Code != http.StatusConflict {
|
||||
t.Errorf("POST without endpoint = %d, want 409", rr.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGEndpoint_PBSOutsideSubnetRejected(t *testing.T) {
|
||||
h, _, _ := newTestHandler(t)
|
||||
body := `{"dns_name":"ep0.example","wg_port":443,"server_pubkey":"` + testPK(9) + `",` +
|
||||
`"tunnel_subnet":"10.77.0.0/24","pbs_tunnel_ip":"10.88.0.1"}`
|
||||
rr := do(h, http.MethodPut, "/admin/wg/endpoint", globalKey, body)
|
||||
if rr.Code != http.StatusBadRequest {
|
||||
t.Errorf("PUT with pbs outside subnet = %d, want 400", rr.Code)
|
||||
}
|
||||
rr = do(h, http.MethodGet, "/admin/wg/endpoint", globalKey, "")
|
||||
if rr.Code != http.StatusNotFound {
|
||||
t.Errorf("GET after rejected PUT = %d, want 404 (nothing stored)", rr.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_DeleteUnknown404NoSync(t *testing.T) {
|
||||
h, _, _ := newTestHandler(t)
|
||||
putTestEndpoint(t, h)
|
||||
fake := &fakeWGSyncer{}
|
||||
h.SetWGSyncer(fake)
|
||||
rr := do(h, http.MethodDelete, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(7)+`"}`)
|
||||
if rr.Code != http.StatusNotFound {
|
||||
t.Errorf("DELETE unknown = %d, want 404", rr.Code)
|
||||
}
|
||||
if fake.syncCalls != 0 {
|
||||
t.Errorf("sync ran on 404 delete: %d", fake.syncCalls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWGPeers_DeleteKnownRemovesAndSyncs(t *testing.T) {
|
||||
h, st, _ := newTestHandler(t)
|
||||
putTestEndpoint(t, h)
|
||||
fake := &fakeWGSyncer{}
|
||||
h.SetWGSyncer(fake)
|
||||
do(h, http.MethodPost, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(1)+`"}`)
|
||||
do(h, http.MethodPost, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(2)+`"}`)
|
||||
|
||||
rr := do(h, http.MethodDelete, "/admin/wg/peers", globalKey, `{"pubkey":"`+testPK(1)+`"}`)
|
||||
if rr.Code != http.StatusOK {
|
||||
t.Fatalf("DELETE = %d: %s", rr.Code, rr.Body.String())
|
||||
}
|
||||
peers, _ := st.ListWGPeers()
|
||||
if len(peers) != 1 || peers[0].Pubkey != testPK(2) {
|
||||
t.Errorf("peers after delete = %+v, want only p2", peers)
|
||||
}
|
||||
if fake.syncCalls != 3 { // 2 adds + 1 delete
|
||||
t.Errorf("sync calls = %d, want 3", fake.syncCalls)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user