Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

This file was deleted.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

This file was deleted.

16 changes: 16 additions & 0 deletions src-tauri/migrations/20251117093105_force_all_traffic.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
-- add client_traffic_policy column to `instance` table
-- since SQLite does not support native enums we'll store them as integers
-- 0 - None
-- 1 - Disable all traffic
-- 2 - Force all traffic
ALTER TABLE instance ADD COLUMN client_traffic_policy INTEGER NOT NULL DEFAULT 0;

-- populate new column based on value in `disable_all_traffic` column
UPDATE instance
SET client_traffic_policy = CASE
WHEN disable_all_traffic = true THEN 1
ELSE 0
END;

-- drop the `disable_all_traffic` column since it's no longer needed
ALTER TABLE instance DROP COLUMN disable_all_traffic;
2 changes: 1 addition & 1 deletion src-tauri/proto
Submodule proto updated 1 files
+9 −1 core/proxy.proto
30 changes: 22 additions & 8 deletions src-tauri/src/commands.rs
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ use crate::{
database::{
models::{
connection::{ActiveConnection, Connection, ConnectionInfo},
instance::{Instance, InstanceInfo},
instance::{ClientTrafficPolicy, Instance, InstanceInfo},
location::{Location, LocationMfaMode},
location_stats::LocationStats,
tunnel::{Tunnel, TunnelConnection, TunnelConnectionInfo, TunnelStats},
Expand Down Expand Up @@ -393,7 +393,7 @@ pub async fn all_instances() -> Result<Vec<InstanceInfo<Id>>, Error> {
proxy_url: instance.proxy_url,
active: connected,
pubkey: keys.pubkey,
disable_all_traffic: instance.disable_all_traffic,
client_traffic_policy: instance.client_traffic_policy,
enterprise_enabled: instance.enterprise_enabled,
openid_display_name: instance.openid_display_name,
});
Expand Down Expand Up @@ -576,15 +576,14 @@ pub(crate) async fn do_update_instance(
instance.proxy_url = instance_info.proxy_url;
instance.username = instance_info.username;
// Make sure to update the locations too if we are disabling all traffic
if instance.disable_all_traffic != instance_info.disable_all_traffic
&& instance_info.disable_all_traffic
let policy = instance_info.client_traffic_policy.into();
if instance.client_traffic_policy != policy && policy == ClientTrafficPolicy::DisableAllTraffic
{
debug!("Disabling all traffic for all locations of instance {instance}");
Location::disable_all_traffic_for_all(transaction.as_mut(), instance.id).await?;
debug!("Disabled all traffic for all locations of instance {instance}");
}
instance.disable_all_traffic = instance_info.disable_all_traffic;
instance.enterprise_enabled = instance_info.enterprise_enabled;
instance.client_traffic_policy = instance_info.client_traffic_policy.into();
instance.openid_display_name = instance_info.openid_display_name;
instance.uuid = instance_info.id;
// Token may be empty if it was not issued
Expand Down Expand Up @@ -923,11 +922,13 @@ pub async fn update_location_routing(
match connection_type {
ConnectionType::Location => {
if let Some(mut location) = Location::find_by_id(&*DB_POOL, location_id).await? {
// Check if the instance has route_all_traffic disabled
let instance = Instance::find_by_id(&*DB_POOL, location.instance_id)
.await?
.ok_or(Error::NotFound)?;
if instance.disable_all_traffic && route_all_traffic {
// Check if the instance has route_all_traffic disabled
if (instance.client_traffic_policy == ClientTrafficPolicy::DisableAllTraffic)
&& route_all_traffic
{
error!(
"Couldn't update location routing: instance with id {} has \
route_all_traffic disabled.",
Expand All @@ -937,6 +938,19 @@ pub async fn update_location_routing(
"Instance has route_all_traffic disabled".into(),
));
}
// Check if the instance has route_all_traffic enforced
if (instance.client_traffic_policy == ClientTrafficPolicy::ForceAllTraffic)
&& !route_all_traffic
{
error!(
"Couldn't update location routing: instance with id {} has \
route_all_traffic enforced.",
instance.id
);
return Err(Error::InternalError(
"Instance has route_all_traffic enforced".into(),
));
}

location.route_all_traffic = route_all_traffic;
location.save(&*DB_POOL).await?;
Expand Down
Loading