Skip to content

Reuse a masked password only for the host it was saved for - #48

Merged
rangoDJ merged 2 commits into
mainfrom
fix/profile-secret-host-check
Oct 7, 2026
Merged

rangoDJ merged 2 commits into
mainfrom
fix/profile-secret-host-check

Conversation

@rangoDJ

@rangoDJ rangoDJ commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Fixes #47

What changed

  • check_masked_secrets_target(): when a profile comes back with its password or SSH key masked, the stored secret is reused only if the protocol, host (case-insensitive) and port (protocol default when unset) match the stored profile. Otherwise POST /api/profiles and POST /api/session/connect return 400: "The host, port or protocol changed: enter the password (or SSH key) again".
  • README: a note that a saved password is only reused for its host, port and protocol.
  • Behaviour change for users: editing a saved profile's host, port or protocol now requires re-entering its password or key.

Testing

  • pytest: 247 passed, 8 skipped. New API tests: the same host reuses the secret; a different host, IP, port or protocol is refused for connect and the store is left unchanged on save; a new host with a new password saves; host case and an explicit default port count as the same target. Six of them fail without the fix.
  • Merged with main (Refuse to overwrite a profiles.json that can't be read #40 changed the same functions); both fixes are covered by the suite.
  • Not tested in a running container.

🤖 Generated with Claude Code

rangoDJ and others added 2 commits October 7, 2026 16:36
A profile sent back with its password or SSH key still masked had the
stored secret restored by profile id alone, with no check that the host,
port or protocol were unchanged. Pointing a saved profile at another
machine and connecting sent the stored credentials there, although the
API never shows them. Masked secrets are now refused for a different
target; the password has to be entered again.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rangoDJ
rangoDJ merged commit b8c57f4 into main Oct 7, 2026
4 checks passed
@rangoDJ
rangoDJ deleted the fix/profile-secret-host-check branch October 7, 2026 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Saved profile passwords can be sent to a different host

1 participant