integration: add tests for ACL group with deleted/unknown users
Add DeleteUser method to ControlServer interface and implement it in HeadscaleInContainer to enable testing user deletion scenarios. Add two integration tests for issue #2967: - TestACLGroupWithUnknownUser: tests that valid users can communicate when a group references a non-existent user - TestACLGroupAfterUserDeletion: tests connectivity after deleting a user that was referenced in an ACL group These tests currently pass but don't fully reproduce the reported issue where deleted users break connectivity for the entire group. Updates #2967
This commit is contained in:
parent
951fd5a8e7
commit
98c0817b95
3 changed files with 308 additions and 0 deletions
|
|
@ -1333,6 +1333,31 @@ func (t *HeadscaleInContainer) MapUsers() (map[string]*v1.User, error) {
|
|||
return userMap, nil
|
||||
}
|
||||
|
||||
// DeleteUser deletes a user from the Headscale instance.
|
||||
func (t *HeadscaleInContainer) DeleteUser(userID uint64) error {
|
||||
command := []string{
|
||||
"headscale",
|
||||
"users",
|
||||
"delete",
|
||||
"--identifier",
|
||||
strconv.FormatUint(userID, 10),
|
||||
"--force",
|
||||
"--output",
|
||||
"json",
|
||||
}
|
||||
|
||||
_, _, err := dockertestutil.ExecuteCommand(
|
||||
t.container,
|
||||
command,
|
||||
[]string{},
|
||||
)
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to execute delete user command: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (h *HeadscaleInContainer) SetPolicy(pol *policyv2.Policy) error {
|
||||
err := h.writePolicy(pol)
|
||||
if err != nil {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue