Skip to content

feat(policy): enforce server client policies in the Windows client - #29

Merged
CallMeTechie merged 4 commits into
masterfrom
feat/client-policies
Oct 2, 2026
Merged

CallMeTechie merged 4 commits into
masterfrom
feat/client-policies

Conversation

@CallMeTechie

@CallMeTechie CallMeTechie commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Windows (Community) part of Client-Richtlinien vom Server. Server: CallMeTechie/gatecontrol#256, core: CallMeTechie/gatecontrol-client-core#16.

core.ref is pinned to the core PR head 97c7aad1d139f678fb671cd3395432111e2a0c12 (core PR #16 head, merged with core master incl. support bundles #15). Once the core PR is merged, bump it to the merge commit.

Enforcement

Policy Community client
kill switch required kill switch forced on (and enabled right away if the tunnel is up). Toggles in Settings and Overview plus the tray entry are disabled
auto-connect required tunnel.autoConnect forced on and locked. Connects when the policy arrives
auto-connect always_on additionally no manual disconnect (hero button, sidebar toggle and tray disabled, IPC refuses it). The tunnel is brought back every minute when it is down
autostart required / forbidden app.startWithWindows forced, login item set or removed, toggle locked
split-tunnel modes only the allowed modes are selectable (Windows: off/include; if nothing is left, full tunnel). A forced change reconnects. A locked preset or lockSettings freezes mode and routes
lockSettings every setting except language and theme is locked
lockServer server card and config import hidden. server:setup and config import are refused in main

Locked controls show the hint "Vom Administrator festgelegt" / "Set by your administrator". Settings also shows a "managed" banner. Locks are checked in the main process (core IPC guards), not only in the UI.

Fail-safe: the last known policy is applied at start-up (offline). An unreachable server keeps it. A policy that was never fetched (or an old server without the endpoint) means no restriction.

Client-side enforcement is a management convenience, not a security boundary against a local administrator (README).

Tests

  • npm test: 57/57
  • Playwright e2e run locally (Linux, xvfb, electron 44): 11/11, including the new test/e2e/policy.spec.js:
    • with a policy: locked settings are disabled with the hint
    • with an old server that has no policy endpoint: everything stays unlocked

🤖 Generated with Claude Code

https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD


Generated by Claude Code


Generated by Claude Code

Claude added 4 commits October 2, 2026 20:26
- Uses the core ClientPolicyService (core.ref pinned to the core PR head):
  the last known policy is applied at start-up (offline-safe), then the
  server is asked; changes arrive via polling and the policyVersion of
  heartbeat/permissions answers.
- Main process: forces the store values (kill switch on, auto-connect on,
  autostart on/off incl. the autostart registration, allowed split mode),
  enables the kill switch when the tunnel is up, reconnects after a forced
  split-mode change, connects when auto-connect is required, and keeps the
  tunnel up under "always on" (no manual disconnect, retry every minute).
  Tray: disconnect / kill switch entries disabled when locked.
- Renderer: locked settings are disabled with the hint "Vom Administrator
  festgelegt" (kill switch, autostart, auto-connect, split modes/routes,
  remaining settings under lockSettings), server/re-setup area hidden
  under lockServer, managed banner in the settings. Split-tunnel changes
  use tunnel:reconnect.
- E2E: mock server serves the policy; new policy spec (locked settings,
  old server without the endpoint stays unlocked). README section.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
…master

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
Brings in the support bundle feature; core.ref stays pinned to the core
client-policies head (which already contains core master with the
support bundle code).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
@CallMeTechie
CallMeTechie merged commit 3b657da into master Oct 2, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants