You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/ipn
Will Norris 6b956b49e0 client/web: add some security checks for full client
Require that requests to servers in manage mode are made to the
Tailscale IP (either ipv4 or ipv6) or quad-100. Also set various
security headers on those responses.  These might be too restrictive,
but we can relax them as needed.

Allow requests to /ok (even in manage mode) with no checks. This will be
used for the connectivity check from a login client to see if the
management client is reachable.

Updates tailscale/corp#14335

Signed-off-by: Will Norris <will@tailscale.com>
2 years ago
..
conffile
ipnauth ipn/ipnauth: improve the Windows token administrator check 2 years ago
ipnlocal client/web: add some security checks for full client 2 years ago
ipnserver ipn/ipnauth: improve the Windows token administrator check 2 years ago
ipnstate
localapi ipn/localapi: make serveTKASign require write permission (#10094) 2 years ago
policy
store
backend.go
conf.go
doc.go
fake_test.go
ipn_clone.go ipn: introduce app connector advertisement preference and flags 2 years ago
ipn_test.go
ipn_view.go ipn: introduce app connector advertisement preference and flags 2 years ago
prefs.go ipn: introduce app connector advertisement preference and flags 2 years ago
prefs_test.go ipn: introduce app connector advertisement preference and flags 2 years ago
serve.go
serve_test.go
store.go
store_test.go