diff --git a/CHANGELOG.md b/CHANGELOG.md index be9e8456..a7bf028b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,14 @@ ## 0.17.0 (2022-XX-XX) +- Add ability to connect to PostgreSQL over TLS/SSL [#745](https://github.com/juanfont/headscale/pull/745) + +## 0.16.3 (2022-08-17) + +### Changes + +- Fix issue with OIDC authentication [#747](https://github.com/juanfont/headscale/pull/747) + ## 0.16.2 (2022-08-14) ### Changes @@ -125,7 +133,7 @@ This is a part of aligning `headscale`'s behaviour with Tailscale's upstream beh - OpenID Connect users will be mapped per namespaces - Each user will get its own namespace, created if it does not exist - `oidc.domain_map` option has been removed - - `strip_email_domain` option has been added (see [config-example.yaml](./config_example.yaml)) + - `strip_email_domain` option has been added (see [config-example.yaml](./config-example.yaml)) ### Changes diff --git a/app.go b/app.go index 9f113c2b..7ed9d2ed 100644 --- a/app.go +++ b/app.go @@ -129,12 +129,16 @@ func NewHeadscale(cfg *Config) (*Headscale, error) { switch cfg.DBtype { case Postgres: dbString = fmt.Sprintf( - "host=%s dbname=%s user=%s sslmode=disable", + "host=%s dbname=%s user=%s", cfg.DBhost, cfg.DBname, cfg.DBuser, ) + if !cfg.DBssl { + dbString += " sslmode=disable" + } + if cfg.DBport != 0 { dbString += fmt.Sprintf(" port=%d", cfg.DBport) } diff --git a/config-example.yaml b/config-example.yaml index ed447f9a..b369029c 100644 --- a/config-example.yaml +++ b/config-example.yaml @@ -121,6 +121,7 @@ db_path: /var/lib/headscale/db.sqlite # db_name: headscale # db_user: foo # db_pass: bar +# db_ssl: false ### TLS configuration # diff --git a/config.go b/config.go index 69358401..3c241b29 100644 --- a/config.go +++ b/config.go @@ -47,6 +47,7 @@ type Config struct { DBname string DBuser string DBpass string + DBssl bool TLS TLSConfig @@ -506,6 +507,7 @@ func GetHeadscaleConfig() (*Config, error) { DBname: viper.GetString("db_name"), DBuser: viper.GetString("db_user"), DBpass: viper.GetString("db_pass"), + DBssl: viper.GetBool("db_ssl"), TLS: GetTLSConfig(), diff --git a/oidc.go b/oidc.go index 63762716..60d531e5 100644 --- a/oidc.go +++ b/oidc.go @@ -318,7 +318,7 @@ func extractIDTokenClaims( idToken *oidc.IDToken, ) (*IDTokenClaims, error) { var claims IDTokenClaims - if err := idToken.Claims(claims); err != nil { + if err := idToken.Claims(&claims); err != nil { log.Error(). Err(err). Caller().