state: apply default node key expiry on registration
Use the node.expiry config to apply a default expiry to non-tagged nodes when the client does not request a specific expiry. This covers all registration paths: new node creation, re-authentication, and pre-auth key re-registration. Tagged nodes remain exempt and never expire. Fixes #1711
This commit is contained in:
parent
4d0b273b90
commit
6337a3dbc4
3 changed files with 40 additions and 8 deletions
|
|
@ -1354,7 +1354,7 @@ func TestOIDCExpiryAfterRestart(t *testing.T) {
|
|||
"HEADSCALE_OIDC_CLIENT_ID": scenario.mockOIDC.ClientID(),
|
||||
"CREDENTIALS_DIRECTORY_TEST": "/tmp",
|
||||
"HEADSCALE_OIDC_CLIENT_SECRET_PATH": "${CREDENTIALS_DIRECTORY_TEST}/hs_client_oidc_secret",
|
||||
"HEADSCALE_OIDC_EXPIRY": "72h",
|
||||
"HEADSCALE_NODE_EXPIRY": "72h",
|
||||
}
|
||||
|
||||
err = scenario.CreateHeadscaleEnvWithLoginURL(
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue