You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/ipn
Will Norris 6b956b49e0 client/web: add some security checks for full client
Require that requests to servers in manage mode are made to the
Tailscale IP (either ipv4 or ipv6) or quad-100. Also set various
security headers on those responses.  These might be too restrictive,
but we can relax them as needed.

Allow requests to /ok (even in manage mode) with no checks. This will be
used for the connectivity check from a login client to see if the
management client is reachable.

Updates tailscale/corp#14335

Signed-off-by: Will Norris <will@tailscale.com>
7 months ago
..
conffile ipn/{conffile,ipnlocal}: start booting tailscaled from a config file w/ auth key 8 months ago
ipnauth ipn/ipnauth: improve the Windows token administrator check 7 months ago
ipnlocal client/web: add some security checks for full client 7 months ago
ipnserver ipn/ipnauth: improve the Windows token administrator check 7 months ago
ipnstate client/web: restrict full management client behind browser sessions 8 months ago
localapi ipn/localapi: make serveTKASign require write permission (#10094) 7 months ago
policy ipn: prefer allow/denylist terminology 1 year ago
store cmd/k8s-operator,ipn/store/kubestore: patch secrets instead of updating 9 months ago
backend.go cmd/tailscale,ipn/ipnlocal: print debug component names 8 months ago
conf.go ipn: add user pref for running web client 7 months ago
doc.go all: update copyright and license headers 1 year ago
fake_test.go all: update copyright and license headers 1 year ago
ipn_clone.go ipn: introduce app connector advertisement preference and flags 7 months ago
ipn_test.go net/packet: split off checksum munging into different pkg 8 months ago
ipn_view.go ipn: introduce app connector advertisement preference and flags 7 months ago
prefs.go ipn: introduce app connector advertisement preference and flags 7 months ago
prefs_test.go ipn: introduce app connector advertisement preference and flags 7 months ago
serve.go ipn/localapi: require local Windows admin to set serve path (#9969) 7 months ago
serve_test.go ipn/localapi: require local Windows admin to set serve path (#9969) 7 months ago
store.go ipn: avoid useless no-op WriteState calls 10 months ago
store_test.go ipn: avoid useless no-op WriteState calls 10 months ago