Expand description
The identity endpoints under /api/v1/auth/, JSON in and out, as a
router isb serve mounts on its TCP listener next to /mcp and
/healthz.
- Browser sessions ride in the
isb_sessioncookie: HttpOnly, SameSite=Lax, Path=/, and Secure unless the request came over plain loopback HTTP (noX-Forwarded-Proto: https, a loopbackHost), sohttp://localhostdevelopment works and anything through a tunnel or a TLS proxy gets a Secure cookie. - API tokens ride in
Authorization: Bearer isb_tok_.... A request carryingAuthorizationis judged by it alone; cookies are ignored. - CSRF: every request other than GET/HEAD must carry
X-Isb-Csrf: 1, unless it carriesAuthorization: Bearer. A browser sends a custom header cross-origin only after a CORS preflight, which isb never grants, so a forged form or fetch from another site is refused before it does anything. Login and setup are covered too (login CSRF signs a victim into the attacker’s account). - First-run setup is claimed by an edge identity (
super::edge: the tailnet peer, or the verified Access user), whom the front door already let in. With no edge identity, it needs the one-time setup token the daemon writes to<state>/setup-token(0600) and logs as a/setup#TOKENlink, so whoever reaches the port first cannot claim the platform.isb user createon the host is the other way in. - Edge sign-in (
POST edge) starts a session for the user an edge identity belongs to, so behind a tailnet or Access nobody types a password. - External sign-in and passkeys are in the
externalsubmodule.
Modules§
- spec
- The identity endpoints as data: every route
super::AuthApianswers, with who may call it, its body and its answer, and the MCP tool that does the same (or why there is none). The OpenAPI document is built from this table, and a test holds it to the router’s ownmatcharms, so the two cannot drift apart.
Structs§
Enums§
- Notice
- Something worth telling a user out of band.
Constants§
- COOKIE
- The session cookie.
- CSRF_
HEADER - The anti-CSRF header the web UI sends on every state-changing request.
- LOGIN_
PAGE - Where a failed browser sign-in lands, with
?error=CODE. - OAUTH_
COOKIE - The cookie binding an OAuth flow to the browser that started it.
- PREFIX
- Every endpoint lives under this prefix.
Functions§
- client_
ip - The client’s address:
Cf-Connecting-IPwhen the peer is loopback (the tunnel; Cloudflare sets that header and clients cannot), else the peer. - cookie
- The value of cookie
name, if sent. - plain_
loopback_ http - True when the request came straight to loopback over plain HTTP: a
loopback peer, a loopback
Host, and no proxy saying it was HTTPS. - safe_
next - A same-origin path to go to after sign-in: starts with one
/, no backslash, no whitespace or control characters. Never an absolute URL or a protocol-relative//host. - session_
cookie Set-Cookiefor the session (an empty token with max-age 0 clears it).
Type Aliases§
- AgentFn
- The tailnet or Access agent identity behind a request, if an org maps it (the daemon’s gate).
- Notifier
- Delivers a
Notice(email, chat).Erris logged, never shown to the requester, who gets the same answer either way. - Router
- Answers the requests it owns,
Nonefor the rest. - Superadmin
Fn - The superadmin behind a request, if any: a superadmin token, or a listed tailnet or Access identity (the daemon’s gate).