Add one-time setup links as an alternative to the QR code
A config can now be handed over as a one-time link, valid for 1 h, 24 h or 7 days and protected by a PIN by default. Keys are made only when the link is opened; the link works once and is revoked after 5 wrong PINs. Issuing a new config offers the same choice, and the current config keeps working until the link is used. Remove the option to paste a client's public key, in the web UI, the API and the iOS app.
This commit is contained in:
@@ -118,8 +118,15 @@ type Peer struct {
|
||||
Keepalive *int `json:"keepalive,omitempty"` // nil = server default
|
||||
Created time.Time `json:"created"`
|
||||
ConfigIssued *time.Time `json:"configIssued,omitempty"`
|
||||
// Setup is a pending one-time setup link. A peer created with a link has
|
||||
// no public key until the link is opened.
|
||||
Setup *SetupLink `json:"setup,omitempty"`
|
||||
}
|
||||
|
||||
// hasKey reports whether the peer has a public key, i.e. it can be in the
|
||||
// kernel. A peer waiting for its setup link has none yet.
|
||||
func (p *Peer) hasKey() bool { return p.PublicKey != "" }
|
||||
|
||||
type LogConfig struct {
|
||||
Level string `json:"level"` // debug | info | warn | error
|
||||
MaxSizeMB int `json:"maxSizeMB"`
|
||||
@@ -346,7 +353,7 @@ func (c *Config) validate() error {
|
||||
return fmt.Errorf("address %s is used twice", ip)
|
||||
}
|
||||
ips[ip] = true
|
||||
if keys[p.PublicKey] {
|
||||
if p.hasKey() && keys[p.PublicKey] {
|
||||
return fmt.Errorf("peer %q: public key is used by another peer", p.Name)
|
||||
}
|
||||
keys[p.PublicKey] = true
|
||||
|
||||
Reference in New Issue
Block a user