You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
permits the support team to access a PostgreSQL database, but prohibits access to the servers, while the developers have access to the database and servers.
if a new user marty is enrolled, marty has access to everything, bypassing the ACLs.
Version of headscale used: v0.20.0
Version of tailscale client: 1.38.2
OS (e.g. Linux, Mac, Cygwin, WSL, etc.) and version: macOS Ventura
The text was updated successfully, but these errors were encountered:
Noted, I will try to write a test case to "prove" it and then fix it for the #1069 work and hopefully get it resolve when I am sitting down with that work.
Bug description
If a new user is enrolled into Headscale and it doesn't belong to any group, the user has access to the whole network.
To Reproduce
Describing an ACL as following:
permits the support team to access a PostgreSQL database, but prohibits access to the servers, while the developers have access to the database and servers.
if a new user
marty
is enrolled,marty
has access to everything, bypassing the ACLs.v0.20.0
1.38.2
The text was updated successfully, but these errors were encountered: