mirror of
https://github.com/EasyTier/EasyTier.git
synced 2026-10-11 13:56:14 -08:00
feat(cli): show direct peers using temporary credentials (#2663)
Add credential peers with table and JSON output while preserving credential list. Match authenticated remote credential keys to stored fingerprints and virtual route addresses. Keep instance results isolated and exclude unproven relay users. Enable SHA-256 for CLI-only builds and add regression and multi-instance tests. Accept omitted protobuf default lists in the existing multi-instance test. Refs #2529
This commit is contained in:
1 parent
bd06395573
commit
d96eaa668b
4 files changed
+470
-7
No files matched your search
@@ -0,0 +1,55 @@
|
||||
# Inspect credential users from the CLI
|
||||
|
||||
On a node that stores the issued credentials, list their currently authenticated
|
||||
direct peers:
|
||||
|
||||
```sh
|
||||
easytier-cli credential peers
|
||||
|
||||
# Select one network instance and return machine-readable output.
|
||||
easytier-cli --instance-name my-network --output json credential peers
|
||||
```
|
||||
|
||||
The table associates each credential ID with peer IDs, virtual IPv4/IPv6
|
||||
addresses, and hostnames. A reusable credential can have multiple peers;
|
||||
multiple tunnels to the same peer appear only once. Existing `credential list`
|
||||
output is unchanged.
|
||||
|
||||
JSON output has this shape for one instance:
|
||||
|
||||
```json
|
||||
{
|
||||
"credentials": [
|
||||
{
|
||||
"credential_id": "user-123",
|
||||
"peers": [
|
||||
{
|
||||
"peer_id": 42,
|
||||
"ipv4": "10.144.144.2",
|
||||
"ipv6": null,
|
||||
"hostname": "laptop"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
Without an explicit instance selector, the command follows the other CLI query
|
||||
commands: it queries running instances, wrapping multiple results with their
|
||||
instance IDs and names.
|
||||
|
||||
## Scope
|
||||
|
||||
The association uses the remote public key of an authenticated live credential
|
||||
connection, matched against the credential's SHA-256 public-key fingerprint.
|
||||
It never uses a route advertisement alone as proof of credential identity.
|
||||
Credential secrets and connection keys are not printed.
|
||||
|
||||
This is a per-node snapshot, not a network-wide login history. An empty `peers`
|
||||
array (shown as `no direct peers` in the table) does not mean a credential is
|
||||
unused elsewhere: its users may only be connected to another node or reachable
|
||||
through a relay. Older cores without credential fingerprints cannot be matched.
|
||||
Missing route addresses are returned as `null` (shown as `-`); a peer may connect
|
||||
before its route or DHCP address is available. Addresses and connection state
|
||||
can change between the RPC snapshots.
|
||||
Reference in new issue
Block a user