mirror of
https://gitea.com/gitea/tea.git
synced 2026-10-05 21:38:13 +02:00
fix(login): avoid SSH passphrase prompt with ssh-agent logins (#1102)
Fixes #866 ## Problem `tea` still prompts for an SSH key passphrase for logins created with `--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea auto-discovers a matching private key in `~/.ssh` even when the login is configured to use the running ssh-agent. That on-disk key is stored in `ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK to load the file from disk instead of signing through the agent. ## Changes - Stop auto-discovering a private key when the login uses the ssh-agent. - Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent logins pass an empty key path and the SDK talks to `ssh-agent`. - Prefer SSH remotes for agent logins, matching key-file logins. - Add unit tests for the new key-path and auto-discovery behavior. ## Testing - `go test ./modules/config ./modules/task ./modules/git` - `go build ./...` --------- Co-authored-by: bircni <bircni@icloud.com> Reviewed-on: https://gitea.com/gitea/tea/pulls/1102 Reviewed-by: bircni <bircni@icloud.com> Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
This commit is contained in:
committed by
bircni
co-authored by
bircni
parent
6daaa7c05e
commit
bcd62a1fb2
@@ -90,6 +90,39 @@ func TestLoginClientWithSSHPubkeyDoesNotDeadlockOnFirstRequest(t *testing.T) {
|
||||
assert.EqualValues(t, 1, signedIssueRequests.Load())
|
||||
}
|
||||
|
||||
func TestLoginSSHKeyPath(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
login Login
|
||||
want string
|
||||
}{
|
||||
{
|
||||
name: "disk key",
|
||||
login: Login{SSHKey: "/tmp/id_ed25519"},
|
||||
want: "/tmp/id_ed25519",
|
||||
},
|
||||
{
|
||||
name: "ssh agent ignores disk key",
|
||||
login: Login{SSHKey: "/tmp/id_ed25519", SSHAgent: true},
|
||||
want: "",
|
||||
},
|
||||
{
|
||||
name: "ssh agent without disk key",
|
||||
login: Login{SSHAgent: true},
|
||||
want: "",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
assert.Equal(t, tt.want, tt.login.SSHKeyPath())
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func writeTestSSHKey(t *testing.T) (string, string) {
|
||||
t.Helper()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user