Epic: #122 · Depends on: FM-943
Context
The maintainer reaches the controller through tailscale serve, which can attach identity headers (e.g. Tailscale-User-Login) to proxied requests. The maintainer approved exploring this as the first step away from anonymous-lan-admin.
Goal
An ADR, then an opt-in mode: when requests arrive from a configured loopback serve proxy with identity headers, the principal is the tailnet user. It feeds the existing authz boundary and audit; otherwise behavior is unchanged.
Architecture reference
ADR-0003/0004; FM-105/FM-S02 (deferred auth); docs/architecture/security.md; PLAN M8.
Dependencies
FM-943
Research required
Tailscale serve identity header documentation; header spoofing risks when not behind serve.
Acceptance criteria
- Headers trusted only from the configured loopback peer; spoofed headers from other peers are ignored and audited as evidence
- Audit records the tailnet principal; UI shows who you are
Non-goals
- Full M8 authentication, OIDC, per-user permissions
Tests
Header-trust unit tests, spoofing tests, audit tests.
Epic: #122 · Depends on: FM-943
Context
The maintainer reaches the controller through
tailscale serve, which can attach identity headers (e.g.Tailscale-User-Login) to proxied requests. The maintainer approved exploring this as the first step away fromanonymous-lan-admin.Goal
An ADR, then an opt-in mode: when requests arrive from a configured loopback serve proxy with identity headers, the principal is the tailnet user. It feeds the existing authz boundary and audit; otherwise behavior is unchanged.
Architecture reference
ADR-0003/0004; FM-105/FM-S02 (deferred auth);
docs/architecture/security.md; PLAN M8.Dependencies
FM-943
Research required
Tailscale serve identity header documentation; header spoofing risks when not behind serve.
Acceptance criteria
Non-goals
Tests
Header-trust unit tests, spoofing tests, audit tests.