Skip to content

feat: issue per-user preauth keys for shared Headscale - #1

Merged
0x7fffff92 merged 4 commits into
mainfrom
feature/unified-headscale
Sep 23, 2026
Merged

0x7fffff92 merged 4 commits into
mainfrom
feature/unified-headscale

Conversation

@0x7fffff92

Copy link
Copy Markdown
Member

Summary

  • Verify X-Authorization through the Olares token verification service.
  • Use the verified Olares username instead of the fixed default Headscale user.
  • Create the corresponding Headscale user when it does not exist.
  • Handle concurrent user creation by re-reading the user after creation.
  • Issue reusable preauth keys with a 24-hour lifetime.
  • Build the complete Go package so the identity verification code is included.

Motivation

The shared Headscale deployment serves multiple Olares users. Preauth keys must therefore be issued for the authenticated user's corresponding Headscale account rather than a global default account.

Requests with a missing or invalid Olares session token are rejected with 401 Unauthorized.

@0x7fffff92
0x7fffff92 merged commit e68eaaf into main Sep 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant