Skip to main content

Module http

Module http 

Source
Expand description

The identity endpoints under /api/v1/auth/, JSON in and out, as a router isb serve mounts on its TCP listener next to /mcp and /healthz.

  • Browser sessions ride in the isb_session cookie: HttpOnly, SameSite=Lax, Path=/, and Secure unless the request came over plain loopback HTTP (no X-Forwarded-Proto: https, a loopback Host), so http://localhost development works and anything through a tunnel or a TLS proxy gets a Secure cookie.
  • API tokens ride in Authorization: Bearer isb_tok_.... A request carrying Authorization is judged by it alone; cookies are ignored.
  • CSRF: every request other than GET/HEAD must carry X-Isb-Csrf: 1, unless it carries Authorization: Bearer. A browser sends a custom header cross-origin only after a CORS preflight, which isb never grants, so a forged form or fetch from another site is refused before it does anything. Login and setup are covered too (login CSRF signs a victim into the attacker’s account).
  • First-run setup is claimed by an edge identity (super::edge: the tailnet peer, or the verified Access user), whom the front door already let in. With no edge identity, it needs the one-time setup token the daemon writes to <state>/setup-token (0600) and logs as a /setup#TOKEN link, so whoever reaches the port first cannot claim the platform. isb user create on the host is the other way in.
  • Edge sign-in (POST edge) starts a session for the user an edge identity belongs to, so behind a tailnet or Access nobody types a password.
  • External sign-in and passkeys are in the external submodule.

Modules§

spec
The identity endpoints as data: every route super::AuthApi answers, with who may call it, its body and its answer, and the MCP tool that does the same (or why there is none). The OpenAPI document is built from this table, and a test holds it to the router’s own match arms, so the two cannot drift apart.

Structs§

ApiConfig
AuthApi
The endpoints, over one store.

Enums§

Notice
Something worth telling a user out of band.

Constants§

COOKIE
The session cookie.
CSRF_HEADER
The anti-CSRF header the web UI sends on every state-changing request.
LOGIN_PAGE
Where a failed browser sign-in lands, with ?error=CODE.
OAUTH_COOKIE
The cookie binding an OAuth flow to the browser that started it.
PREFIX
Every endpoint lives under this prefix.

Functions§

client_ip
The client’s address: Cf-Connecting-IP when the peer is loopback (the tunnel; Cloudflare sets that header and clients cannot), else the peer.
cookie
The value of cookie name, if sent.
plain_loopback_http
True when the request came straight to loopback over plain HTTP: a loopback peer, a loopback Host, and no proxy saying it was HTTPS.
safe_next
A same-origin path to go to after sign-in: starts with one /, no backslash, no whitespace or control characters. Never an absolute URL or a protocol-relative //host.
session_cookie
Set-Cookie for the session (an empty token with max-age 0 clears it).

Type Aliases§

AgentFn
The tailnet or Access agent identity behind a request, if an org maps it (the daemon’s gate).
Notifier
Delivers a Notice (email, chat). Err is logged, never shown to the requester, who gets the same answer either way.
Router
Answers the requests it owns, None for the rest.
SuperadminFn
The superadmin behind a request, if any: a superadmin token, or a listed tailnet or Access identity (the daemon’s gate).