headscale/hscontrol
Kristoffer Dalby 11f0d4cfdd policy/v2: include nodes with empty filters in BuildPeerMap
Previously, nodes with empty filter rules (e.g., tagged servers that are
only destinations, never sources) were skipped entirely in BuildPeerMap.
This could cause visibility issues when using autogroup:self with
multiple user groups.

Remove the len(filter) == 0 skip condition so all nodes are included in
nodeMatchers. Empty filters result in empty matchers where CanAccess()
returns false, but the node still needs to be in the map so symmetric
visibility works correctly: if node A can access node B, both should see
each other regardless of B's filter rules.

Add comprehensive tests for:
- Multi-group scenarios where autogroup:self is used by privileged users
- Nodes with empty filters remaining visible to authorized peers
- Combined access rules (autogroup:self + tags in same rule)

Updates #2990
2026-02-03 16:53:15 +01:00
..
assets editorconfig: add basic editor config 2025-12-16 10:12:36 +01:00
capver capver: generate 2025-12-18 10:02:23 +01:00
db db: use PolicyManager for RequestTags migration 2026-01-21 15:10:29 +01:00
derp derp: migrate to derpserver package API 2026-01-21 19:17:10 +00:00
dns integration: replace time.Sleep with assert.EventuallyWithT (#2680) 2025-07-10 23:38:55 +02:00
mapper db: use PolicyManager for RequestTags migration 2026-01-21 15:10:29 +01:00
policy policy/v2: include nodes with empty filters in BuildPeerMap 2026-02-03 16:53:15 +01:00
routes debug: add json and improve 2025-09-09 09:40:00 +02:00
state state: omit AuthKeyID/AuthKey in node Updates to prevent FK errors 2026-01-26 12:12:11 +00:00
templates Link to headscale.net for docs 2026-01-16 14:54:04 +01:00
types gen: regenerate protobuf and type views 2026-01-21 19:17:10 +00:00
util util/dns: fix variable redeclaration in ValidateDNSName 2026-01-17 10:13:24 +01:00
app.go app: only wire up debug server if set 2025-12-17 12:32:04 +01:00
auth.go cli: ensure tagged-devices is included in profile list (#2991) 2026-01-09 16:31:23 +01:00
auth_tags_test.go state: disable key expiry for tagged nodes 2026-01-16 17:05:59 +01:00
auth_test.go state: omit AuthKeyID/AuthKey in node Updates to prevent FK errors 2026-01-26 12:12:11 +00:00
debug.go lint and leftover 2025-09-09 09:40:00 +02:00
grpcv1.go grpc: support expire/delete API keys by ID 2026-01-20 17:13:38 +01:00
grpcv1_test.go grpc: support expire/delete API keys by ID 2026-01-20 17:13:38 +01:00
handlers.go all: remove deadcode (#2952) 2025-12-10 15:55:15 +01:00
metrics.go all: remove deadcode (#2952) 2025-12-10 15:55:15 +01:00
noise.go all: remove deadcode (#2952) 2025-12-10 15:55:15 +01:00
oidc.go oidc: make email verification configurable 2025-12-18 11:42:32 +00:00
oidc_template_test.go make tags first class node owner (#2885) 2025-12-02 12:01:25 +01:00
oidc_test.go oidc: make email verification configurable 2025-12-18 11:42:32 +00:00
platform_config.go Return better web errors to the user (#2398) 2025-02-01 15:25:18 +01:00
poll.go all: remove deadcode (#2952) 2025-12-10 15:55:15 +01:00
tailsql.go integration: replace time.Sleep with assert.EventuallyWithT (#2680) 2025-07-10 23:38:55 +02:00
templates_consistency_test.go Link to headscale.net for docs 2026-01-16 14:54:04 +01:00