fix(nano): say that [server] listen is ignored instead of defaulting it
LoadNano filled in [server] listen = "0.0.0.0:8080" when it was unset, and a test pinned that value, but felis nano never reads it: it binds the -listen flag, which the installer sets from FELIS_NANO_LISTEN. An operator moving nano off loopback by writing [server] listen in its config got connection refused from the proxy and no hint that the key did nothing. LoadNano no longer sets the default, and nano prints a line naming the ignored value and the address it actually binds whenever the key is set. It is a warning rather than a load error so a full felis.toml copied onto a nano host keeps starting. The assertion that pinned the unused default is removed along with it. The new test runs cmdNano against a config that sets [server] listen and one that does not, with an unbindable -listen so it returns after loading. The first must warn and the second must not; with the old default restored, the second prints a warning about 0.0.0.0:8080.
This commit is contained in:
4 files changed
+34
-7
No files matched your search
@@ -257,9 +257,6 @@ func LoadNano(path string) (*Config, error) {
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if cfg.Server.Listen == "" {
|
||||
cfg.Server.Listen = defaultListen
|
||||
}
|
||||
if err := cfg.validateAuthSources(); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
@@ -379,7 +379,7 @@ func TestLoadRejectsUnqueryableAuthSourceURL(t *testing.T) {
|
||||
// TestLoadNanoAcceptsMinimalConfig is the linchpin of the Felis-nano fold: a nano host has no
|
||||
// Postgres and no FQDN, so LoadNano must accept a felis.toml carrying ONLY [[auth_source]] —
|
||||
// the control-plane requirements (database.url, root_domain) that full Load enforces are
|
||||
// deliberately skipped. It still applies the listen default and hands back the sources.
|
||||
// deliberately skipped. It hands back the sources.
|
||||
func TestLoadNanoAcceptsMinimalConfig(t *testing.T) {
|
||||
cfg, err := config.LoadNano(writeTOML(t, `
|
||||
[[auth_source]]
|
||||
@@ -393,9 +393,6 @@ url = "https://littleskin.example.net/api/yggdrasil/sessionserver/session/minecr
|
||||
if len(cfg.AuthSources) != 1 || cfg.AuthSources[0].Tag != "littleskin" {
|
||||
t.Fatalf("auth sources = %+v, want one littleskin source", cfg.AuthSources)
|
||||
}
|
||||
if cfg.Server.Listen != "0.0.0.0:8080" {
|
||||
t.Errorf("default listen = %q, want 0.0.0.0:8080", cfg.Server.Listen)
|
||||
}
|
||||
}
|
||||
|
||||
// TestLoadNanoStillEnforcesAuthSourceRules pins that skipping the control-plane requirements
|
||||
|
||||
Reference in new issue
Block a user