You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/ipn
Will Norris 236531c5fc ipn/ipnserver: always allow Windows SYSTEM user to connect
When establishing connections to the ipnserver, we validate that the
local user is allowed to connect.  If Tailscale is currently being
managed by a different user (primarily for multi-user Windows installs),
we don't allow the connection.

With the new device web UI, the inbound connection is coming from
tailscaled itself, which is often running as "NT AUTHORITY\SYSTEM".
In this case, we still want to allow the connection, even though it
doesn't match the user running the Tailscale GUI. The SYSTEM user has
full access to everything on the system anyway, so this doesn't escalate
privileges.

Eventually, we want the device web UI to run outside of the tailscaled
process, at which point this exception would probably not be needed.

Updates tailscale/corp#16393

Signed-off-by: Will Norris <will@tailscale.com>
2 years ago
..
conffile ipn/{conffile,ipnlocal}: start booting tailscaled from a config file w/ auth key 2 years ago
ipnauth ipn/ipnserver: always allow Windows SYSTEM user to connect 2 years ago
ipnlocal ipn/ipnserver: always allow Windows SYSTEM user to connect 2 years ago
ipnserver ipn/ipnserver: always allow Windows SYSTEM user to connect 2 years ago
ipnstate ipn/ipnstate: add AllowedIPs to PeerStatus 2 years ago
localapi cmd/tailscale, ipn/ipnlocal: add 'debug dial-types' command 2 years ago
policy ipn,tailconfig: clean up unreleased and removed app connector service 2 years ago
store cmd/k8s-operator,ipn/store/kubestore: patch secrets instead of updating 2 years ago
backend.go taildrop: remove breaking abstraction layers for apple (#10728) 2 years ago
conf.go ipn,cmd/tailscale/cli: support hierarchical MaskedPrefs (#10507) 2 years ago
doc.go all: update copyright and license headers 3 years ago
fake_test.go all: update copyright and license headers 3 years ago
ipn_clone.go linuxfw,wgengine/route,ipn: add c2n and nodeattrs to control linux netfilter 2 years ago
ipn_test.go net/packet: split off checksum munging into different pkg 2 years ago
ipn_view.go linuxfw,wgengine/route,ipn: add c2n and nodeattrs to control linux netfilter 2 years ago
prefs.go ipn: apply ControlURL policy before login 2 years ago
prefs_test.go ipn: apply tailnet-wide default for auto-updates (#10508) 2 years ago
serve.go ipn/localapi: require local Windows admin to set serve path (#9969) 2 years ago
serve_test.go ipn/localapi: require local Windows admin to set serve path (#9969) 2 years ago
store.go taildrop: lazily perform full deletion scan after first taildrop use (#10137) 2 years ago
store_test.go ipn: avoid useless no-op WriteState calls 2 years ago