headscale/hscontrol
max 84d2dfa41d state: clear stale expiry so tagged nodes can re-authenticate after logout
A tagged node that runs `tailscale logout` could never log back in with an
auth key. `tailscale logout` sends a past expiry, and handleLogout stamps it
on the node with no IsTagged guard, so a tagged node (which has key-expiry
disabled and never expires) ends up Expired. On the next
`tailscale up --auth-key`, HandleNodeFromPreAuthKey saw the node as expired and
took the expired-node validation path, re-validating and rejecting the
already-spent one-shot key with "authkey already used" (an infinite
re-register loop for reusable keys).

Exclude tagged nodes from the expired-node validation gate and clear a stale
past expiry on re-registration, restoring the "tagged nodes never expire"
invariant. A deliberately set future expiry (headscale nodes expire) is in the
future, so IsExpired is false and it is left untouched.

Fixes #3371
2026-07-07 18:56:26 +02:00
..
api hscontrol, integration: test OAuth scope enforcement and the oauth-clients CLI 2026-06-26 09:18:06 +02:00
assets assets: fix logo alignment and error icon centering 2026-04-13 17:23:47 +01:00
capver capver: order TailscaleLatestMajorMinor versions with cmpver 2026-06-26 22:06:26 +02:00
db hscontrol: add the OAuth client and access-token model 2026-06-26 09:18:06 +02:00
derp all: fix full-tree golangci-lint findings 2026-06-20 21:08:01 +02:00
dns dns, change, noise, auth, capver: misc consolidation 2026-06-17 16:12:19 +02:00
mapper mapper: skip peers with invalid names instead of failing the map 2026-07-01 15:19:08 +02:00
policy chore: fix function comment to match actual function name 2026-07-03 07:27:08 +02:00
scope api/v2: add OAuth client-credentials auth and scope enforcement 2026-06-26 09:18:06 +02:00
servertest hscontrol, integration: test OAuth scope enforcement and the oauth-clients CLI 2026-06-26 09:18:06 +02:00
state state: clear stale expiry so tagged nodes can re-authenticate after logout 2026-07-07 18:56:26 +02:00
templates templates: consolidate shared page and component helpers 2026-06-17 16:12:19 +02:00
testdata/apiv1_golden test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
types state: reject renames whose FQDN exceeds the hostname limit 2026-07-01 15:19:08 +02:00
util all: fix full-tree golangci-lint findings 2026-06-20 21:08:01 +02:00
apiv1_apikeys_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_auth_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_authmw_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_client_test.go gen/client/v1: add the generated HTTP client 2026-06-19 15:21:00 +02:00
apiv1_harness_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_health_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_nodes_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_policy_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_preauthkeys_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv1_socket_test.go gen/client/v1: add the generated HTTP client 2026-06-19 15:21:00 +02:00
apiv1_users_test.go test: add golden parity tests for the v1 API 2026-06-19 15:21:00 +02:00
apiv2_acl_test.go hscontrol: add v2 API contract tests 2026-06-21 04:17:03 +02:00
apiv2_devices_test.go hscontrol: add v2 API contract tests 2026-06-21 04:17:03 +02:00
apiv2_keys_test.go api/v2: add OAuth client-credentials auth and scope enforcement 2026-06-26 09:18:06 +02:00
apiv2_oauth_matrix_test.go hscontrol, integration: test OAuth scope enforcement and the oauth-clients CLI 2026-06-26 09:18:06 +02:00
apiv2_oauth_test.go hscontrol, integration: test OAuth scope enforcement and the oauth-clients CLI 2026-06-26 09:18:06 +02:00
apiv2_settings_test.go hscontrol: collapse key and settings asserts into cmp.Diff 2026-06-24 18:41:06 +02:00
apiv2_users_test.go hscontrol: contract-test the v2 users endpoint 2026-06-24 18:41:06 +02:00
app.go hscontrol: register /ts2021 for WebSocket GET 2026-07-01 15:20:01 +02:00
app_test.go app: add security headers middleware 2026-04-17 16:31:49 +01:00
auth.go dns, change, noise, auth, capver: misc consolidation 2026-06-17 16:12:19 +02:00
auth_tags_test.go hscontrol: remove the proto, gRPC and grpc-gateway stack 2026-06-19 15:21:00 +02:00
auth_test.go state: return all nodes for a machine key, reject ambiguous ownership 2026-06-15 20:29:15 +02:00
debug.go all: adopt slices helpers 2026-06-17 16:12:19 +02:00
handlers.go handlers: set verify Content-Type before writing the body 2026-06-17 16:12:19 +02:00
handlers_test.go handlers: set verify Content-Type before writing the body 2026-06-17 16:12:19 +02:00
metrics.go metrics, policy/v2: drop unused scaffolding + nil-error returns 2026-05-19 09:55:22 +02:00
noise.go dns, change, noise, auth, capver: misc consolidation 2026-06-17 16:12:19 +02:00
noise_test.go hscontrol: register /ts2021 for WebSocket GET 2026-07-01 15:20:01 +02:00
oidc.go oidc: harden callback CSRF cookies, state reuse, and issuer config 2026-06-26 09:18:06 +02:00
oidc_confirm_test.go all: annotate gosec false positives with rationale 2026-05-19 09:55:22 +02:00
oidc_cookiename_test.go oidc: avoid slice panic in getCookieName for short values 2026-06-08 10:04:49 +02:00
oidc_template_test.go oidc: render HTML error pages for browser-facing failures 2026-04-13 17:23:47 +01:00
oidc_test.go oidc: harden callback CSRF cookies, state reuse, and issuer config 2026-06-26 09:18:06 +02:00
platform_config.go hscontrol: consolidate debug-endpoint and template helpers 2026-06-17 16:12:19 +02:00
platform_config_test.go hscontrol: read Apple platform via chi.URLParam, not mux.Vars 2026-06-05 15:00:59 +02:00
poll.go poll: return an HTTP error on long-poll setup failure 2026-07-01 15:19:08 +02:00
poll_test.go poll: return an HTTP error on long-poll setup failure 2026-07-01 15:19:08 +02:00
realip.go all: adopt slices helpers 2026-06-17 16:12:19 +02:00
realip_test.go hscontrol: gate proxy header trust on trusted_proxies 2026-05-18 17:17:55 +02:00
tailsql.go policy, mapper, capver, hscontrol: remove dead code 2026-06-17 16:12:19 +02:00
templates_consistency_test.go Update links to Tailscale documentation 2026-04-18 09:33:41 +02:00