tailscale/ipn/ipnlocal
Brad Fitzpatrick c2efe46f72 ipn/ipnlocal: restrict exit node DoH server based on ACL'ed packet filter
Don't be a DoH DNS server to peers unless the Tailnet admin has permitted
that peer autogroup:internet access.

Updates #1713

Change-Id: Iec69360d8e4d24d5187c26904b6a75c1dabc8979
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
2021-11-29 09:56:59 -08:00
..
dnsconfig_test.go ipn/ipnlocal: for IPv6-only nodes, publish IPv6 MagicDNS records of peers 2021-10-04 08:54:23 -07:00
local.go ipn/ipnlocal: restrict exit node DoH server based on ACL'ed packet filter 2021-11-29 09:56:59 -08:00
local_test.go ipn/ipnlocal: use netaddr.IPSetBuilder when constructing list of interface IPPrefixes. 2021-10-14 18:53:54 -04:00
loglines_test.go ipn/ipnstate: use key.NodePublic instead of tailcfg.NodeKey. 2021-11-01 20:32:10 -07:00
peerapi.go ipn/ipnlocal: restrict exit node DoH server based on ACL'ed packet filter 2021-11-29 09:56:59 -08:00
peerapi_macios_ext.go all: simplify ts_macext build tags 2021-08-17 11:13:03 -07:00
peerapi_test.go ipn/ipnlocal: restrict exit node DoH server based on ACL'ed packet filter 2021-11-29 09:56:59 -08:00
state_test.go ipn/ipnlocal: handle key extensions after key has already expired 2021-11-08 18:15:09 -08:00