mirror of
https://gitea.com/gitea/tea.git
synced 2026-10-05 21:38:13 +02:00
fix(login): avoid SSH passphrase prompt with ssh-agent logins (#1102)
Fixes #866 ## Problem `tea` still prompts for an SSH key passphrase for logins created with `--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea auto-discovers a matching private key in `~/.ssh` even when the login is configured to use the running ssh-agent. That on-disk key is stored in `ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK to load the file from disk instead of signing through the agent. ## Changes - Stop auto-discovering a private key when the login uses the ssh-agent. - Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent logins pass an empty key path and the SDK talks to `ssh-agent`. - Prefer SSH remotes for agent logins, matching key-file logins. - Add unit tests for the new key-path and auto-discovery behavior. ## Testing - `go test ./modules/config ./modules/task ./modules/git` - `go build ./...` --------- Co-authored-by: bircni <bircni@icloud.com> Reviewed-on: https://gitea.com/gitea/tea/pulls/1102 Reviewed-by: bircni <bircni@icloud.com> Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
This commit is contained in:
committed by
bircni
co-authored by
bircni
parent
6daaa7c05e
commit
bcd62a1fb2
+12
-3
@@ -489,7 +489,7 @@ func (l *Login) ClientWithoutRefresh(options ...gitea.ClientOption) *gitea.Clien
|
||||
fmt.Fprintf(os.Stderr, "Failed to read SSH passphrase: %s\n", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
options = append(options, gitea.UseSSHCert(l.SSHCertPrincipal, l.SSHKey, l.SSHPassphrase))
|
||||
options = append(options, gitea.UseSSHCert(l.SSHCertPrincipal, l.SSHKeyPath(), l.SSHPassphrase))
|
||||
}
|
||||
|
||||
if l.SSHKeyFingerprint != "" {
|
||||
@@ -497,7 +497,7 @@ func (l *Login) ClientWithoutRefresh(options ...gitea.ClientOption) *gitea.Clien
|
||||
fmt.Fprintf(os.Stderr, "Failed to read SSH passphrase: %s\n", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
options = append(options, gitea.UseSSHPubkey(l.SSHKeyFingerprint, l.SSHKey, l.SSHPassphrase))
|
||||
options = append(options, gitea.UseSSHPubkey(l.SSHKeyFingerprint, l.SSHKeyPath(), l.SSHPassphrase))
|
||||
}
|
||||
|
||||
client, err := gitea.NewClient(l.URL, options...)
|
||||
@@ -513,7 +513,7 @@ func (l *Login) ClientWithoutRefresh(options ...gitea.ClientOption) *gitea.Clien
|
||||
}
|
||||
|
||||
func (l *Login) askForSSHPassphrase() error {
|
||||
if ok, err := utils.IsKeyEncrypted(l.SSHKey); ok && err == nil && l.SSHPassphrase == "" {
|
||||
if ok, err := utils.IsKeyEncrypted(l.SSHKeyPath()); ok && err == nil && l.SSHPassphrase == "" {
|
||||
return huh.NewInput().
|
||||
Title("ssh-key is encrypted please enter the passphrase: ").
|
||||
Validate(huh.ValidateNotEmpty()).
|
||||
@@ -525,6 +525,15 @@ func (l *Login) askForSSHPassphrase() error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// SSHKeyPath returns the on-disk SSH key to use, or an empty string when the
|
||||
// login is configured to authenticate through a running ssh-agent.
|
||||
func (l *Login) SSHKeyPath() string {
|
||||
if l.SSHAgent {
|
||||
return ""
|
||||
}
|
||||
return l.SSHKey
|
||||
}
|
||||
|
||||
// GetSSHHost returns SSH host name
|
||||
func (l *Login) GetSSHHost() string {
|
||||
if l.SSHHost != "" {
|
||||
|
||||
Reference in New Issue
Block a user