diff --git a/ipn/localapi/debug.go b/ipn/localapi/debug.go index 6b304b752..b2aa87fff 100644 --- a/ipn/localapi/debug.go +++ b/ipn/localapi/debug.go @@ -522,7 +522,7 @@ func (h *Handler) serveDebugLog(w http.ResponseWriter, r *http.Request) { http.Error(w, feature.ErrUnavailable.Error(), http.StatusNotImplemented) return } - if !h.PermitRead { + if !h.PermitWrite { http.Error(w, "debug-log access denied", http.StatusForbidden) return } diff --git a/ipn/localapi/debug_test.go b/ipn/localapi/debug_test.go index 0f4374c42..58bda7f37 100644 --- a/ipn/localapi/debug_test.go +++ b/ipn/localapi/debug_test.go @@ -9,6 +9,7 @@ import ( "net/http" "net/http/httptest" "net/url" + "strings" "testing" "tailscale.com/ipn" @@ -73,3 +74,44 @@ func TestServeDevSetStateStore(t *testing.T) { }) } } + +func TestServeDebugLogGate(t *testing.T) { + t.Parallel() + + tests := []struct { + desc string + permitRead bool + permitWrite bool + wantStatus int + }{ + { + desc: "read-only-denied", + permitRead: true, + wantStatus: http.StatusForbidden, + }, + { + desc: "write-allowed", + permitRead: true, + permitWrite: true, + wantStatus: http.StatusNoContent, + }, + } + + for _, tt := range tests { + t.Run(tt.desc, func(t *testing.T) { + h := handlerForTest(t, &Handler{ + PermitRead: tt.permitRead, + PermitWrite: tt.permitWrite, + b: newTestLocalBackend(t), + }) + req := httptest.NewRequest("POST", "http://local-tailscaled.sock/localapi/v0/debug-log", + strings.NewReader(`{"prefix":"test","lines":["line"]}`)) + resp := httptest.NewRecorder() + h.serveDebugLog(resp, req) + + if resp.Code != tt.wantStatus { + t.Errorf("resp.Code = %d, want %d; body: %s", resp.Code, tt.wantStatus, resp.Body.String()) + } + }) + } +} diff --git a/ipn/localapi/localapi_test.go b/ipn/localapi/localapi_test.go index 14e9d5ad2..a0426715c 100644 --- a/ipn/localapi/localapi_test.go +++ b/ipn/localapi/localapi_test.go @@ -35,6 +35,7 @@ import ( "tailscale.com/tailcfg/peercap" "tailscale.com/tsd" "tailscale.com/tstest" + "tailscale.com/tstime" "tailscale.com/types/key" "tailscale.com/types/logger" "tailscale.com/types/logid" @@ -53,6 +54,9 @@ func handlerForTest(t testing.TB, h *Handler) *Handler { if h.logf == nil { h.logf = logger.TestLogger(t) } + if h.clock == nil { + h.clock = tstime.StdClock{} + } return h }