Repository navigation
feat(policy): enforce server client policies in the Windows client - #29
Merged
Merged
Conversation
added 4 commits
October 2, 2026 20:26
- Uses the core ClientPolicyService (core.ref pinned to the core PR head): the last known policy is applied at start-up (offline-safe), then the server is asked; changes arrive via polling and the policyVersion of heartbeat/permissions answers. - Main process: forces the store values (kill switch on, auto-connect on, autostart on/off incl. the autostart registration, allowed split mode), enables the kill switch when the tunnel is up, reconnects after a forced split-mode change, connects when auto-connect is required, and keeps the tunnel up under "always on" (no manual disconnect, retry every minute). Tray: disconnect / kill switch entries disabled when locked. - Renderer: locked settings are disabled with the hint "Vom Administrator festgelegt" (kill switch, autostart, auto-connect, split modes/routes, remaining settings under lockSettings), server/re-setup area hidden under lockServer, managed banner in the settings. Split-tunnel changes use tunnel:reconnect. - E2E: mock server serves the policy; new policy spec (locked settings, old server without the endpoint stays unlocked). README section. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
…master Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
Brings in the support bundle feature; core.ref stays pinned to the core client-policies head (which already contains core master with the support bundle code). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Windows (Community) part of Client-Richtlinien vom Server. Server: CallMeTechie/gatecontrol#256, core: CallMeTechie/gatecontrol-client-core#16.
core.refis pinned to the core PR head97c7aad1d139f678fb671cd3395432111e2a0c12 (core PR #16 head, merged with core master incl. support bundles #15). Once the core PR is merged, bump it to the merge commit.Enforcement
requiredrequiredtunnel.autoConnectforced on and locked. Connects when the policy arrivesalways_onrequired/forbiddenapp.startWithWindowsforced, login item set or removed, toggle lockedoff/include; if nothing is left, full tunnel). A forced change reconnects. A locked preset or lockSettings freezes mode and routesserver:setupand config import are refused in mainLocked controls show the hint "Vom Administrator festgelegt" / "Set by your administrator". Settings also shows a "managed" banner. Locks are checked in the main process (core IPC guards), not only in the UI.
Fail-safe: the last known policy is applied at start-up (offline). An unreachable server keeps it. A policy that was never fetched (or an old server without the endpoint) means no restriction.
Client-side enforcement is a management convenience, not a security boundary against a local administrator (README).
Tests
npm test: 57/57test/e2e/policy.spec.js:🤖 Generated with Claude Code
https://claude.ai/code/session_016xX1efcZF1f6G9rhmaJNLD
Generated by Claude Code
Generated by Claude Code