mirror of
https://github.com/openziti/ziti.git
synced 2026-09-10 16:55:41 +00:00
d7076430c9
- reports edge router policy denials with an access-denied error naming the missing policy, replacing the session error reused on the sessionless ER/T and create-circuit-v3 paths - adds EdgeRouterManager.GetEdgeRouterAccess, which reports which of the two required policy links (identity-to-edge-router, service-to-edge-router) is absent, and removes the boolean IsAccessToEdgeRouterAllowed it replaces - logs the controller's rejection on the router at warn level, since it is recoverable and retried by the periodic scan; the router previously discarded the error code and message - delays a new terminator's first create attempt by a fixed 2s so config applied in quick succession settles before the router asks, avoiding a 2-3 minute wait for the retry scan; the delay is a deliberate stopgap until edge router policy visibility lands in the router data model - propagates the controller's error code and retry hint to SDK clients on the dial paths, which dropped the code and left every refusal classified as unknown - adds the retry hint header to controller error replies, grouped with the other error-reply headers rather than the create-circuit-v3 request headers - notes that the sync strategy headers alias the edge namespace's 1013-1015 ids and stay disjoint only by message content type - tests the per-policy denial reporting, the error code carried with and without a retry hint, the controller-to-SDK error code mapping at both dial relay sites, and the terminator settle gate - waits for terminator establishment in the tunneler dataflow tests instead of a fixed sleep, so they no longer race the settle delay - restores the tproxy multiple-lanIf and multiple-resolver changelog entries with keep markers, which regeneration drops because their commits reference pull requests rather than issues