Skip to content

fix(kms): deny on an empty device allowlist in auth-simple - #1344

Merged
kvinwang merged 1 commit into
nextfrom
fix/auth-simple-empty-device-allowlist
Sep 24, 2026
Merged

kvinwang merged 1 commit into
nextfrom
fix/auth-simple-empty-device-allowlist

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Split out of #1247.

With allowAnyDevice: false and devices: [], auth-simple skipped the device check and allowed every device. DstackApp.isAppAllowed and auth-mock both deny in that case. auth-simple now denies too, on both the app and KMS paths.

Behaviour change: both fields default to those values, so a config that sets neither now denies every device instead of allowing all. To keep the old behaviour, set allowAnyDevice: true or list the device ids. Every documented config already sets allowAnyDevice: true.

@kvinwang
kvinwang force-pushed the fix/auth-simple-empty-device-allowlist branch from d94a0d6 to bf655ec Compare September 24, 2026 03:52
@kvinwang
kvinwang merged commit fb3ed11 into next Sep 24, 2026
11 checks passed
@kvinwang
kvinwang deleted the fix/auth-simple-empty-device-allowlist branch September 24, 2026 04:13
kvinwang added a commit that referenced this pull request Sep 25, 2026
#1344 made an empty devices list deny instead of allow. tc-kms-auth-001 now
empties both the app and KMS lists on the live listener and expects the device
denial, then expects allowAnyDevice to allow the same boot.

Signed-off-by: Kevin Wang <wy721@qq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant