enroll devices against the headscale server the owner picked
/api/vpn/enroll minted pre-auth keys itself, from HEADSCALE_URL, HEADSCALE_API_KEY and HEADSCALE_USER in the host env. Three globals describe one server; Officer keeps a registry of many in headscale_servers with one active, so the env could contradict the server the owner had selected — and HEADSCALE_USER filed every joining device under the same name on all of them. The two credential vars had already been removed from the environment and nothing noticed: the route checks `if (!base || !apiKey)` first, so it had been answering 503 to every enrollment attempt, silently. HEADSCALE_USER was read but never reached. Enrollment moves into the sidecar that owns the registry and acts on the active server. The owning user is resolved rather than hardcoded: an explicit userId wins, one user on the server needs no choice, several is a 409 listing them instead of a silent guess. The platform route keeps its path and response shape — both are a contract with enrollVpn() in the mobile core — and is now a bare forward holding no Headscale URL, key or user name. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -11,7 +11,8 @@ import { MIN_VERSION_LABEL } from './version';
|
||||
// generated on that server, and switches between them; one is active at a time. So configuration lives in
|
||||
// Postgres (headscale_servers, keys encrypted at rest), NOT in env vars — this sidecar deliberately reads
|
||||
// neither HEADSCALE_URL nor HEADSCALE_API_KEY, so a registered server can never be shadowed by host env.
|
||||
// (Those two vars belong solely to the unrelated /api/vpn/enroll route, which is none of our business.)
|
||||
// Device enrollment used to be the exception, minting keys in the platform from those two vars plus
|
||||
// HEADSCALE_USER; it moved here (enroll.ts) and now acts on the active server like everything else.
|
||||
//
|
||||
// ─────────────────────────────────────────────────────────────────────────────────────────────────
|
||||
// HTTP CONTRACT — the platform strips its /api/headscale mount prefix before forwarding.
|
||||
@@ -43,6 +44,9 @@ import { MIN_VERSION_LABEL } from './version';
|
||||
// → the ONLY response carrying the real secret
|
||||
// POST /_officer/keys/:id/expire expire without deleting
|
||||
// DELETE /_officer/keys/:id delete outright
|
||||
// POST /_officer/enroll {userId?} → {controlUrl, authKey} — a single-use 10-minute key
|
||||
// for a joining device. userId is only required when the server
|
||||
// has more than one user; reached via /api/vpn/enroll.
|
||||
// anything else 404
|
||||
//
|
||||
// There is deliberately NO transparent /api/v1/* passthrough. Headscale's REST shape changed repeatedly
|
||||
|
||||
Reference in New Issue
Block a user