Unlock passphrase-protected SSH keys - #111
Merged
Merged
Conversation
…ted-keys # Conflicts: # CHANGELOG.md # crates/omnyssh-core/src/ssh/session.rs # crates/omnyssh-gui/ui/src/lib/ipc/router.test.ts # crates/omnyssh-gui/ui/src/lib/ipc/subscribe.ts # crates/omnyssh/src/app/action.rs # crates/omnyssh/src/app/actions.rs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A host whose identity file has a passphrase could not connect at all: both apps
failed with a bare "SSH authentication failed".
Builds on #103 by @sisodiahs — his commit
fc94e3dis kept exactly as submitted.Merge with "Create a merge commit" (not squash or rebase) so it lands on
mainunder his name and #103 is marked merged.
What was wrong
Keys were always read without a passphrase, so an encrypted
identity_file(ordefault key) failed with a generic authentication error and the terminal tab just
closed.
What changes
From #103: in-memory passphrase cache per canonical key path (
ssh::identity), atyped "passphrase required" outcome,
KeyPassphraseRequiredevent, the prompt inboth apps,
unlock_identitycommand.On top of it:
passphrase was removed loads as is
never classified as a refusal; genuine refusals keep main's behaviour
cancelled prompt comes back only when you open a session that needs the key
a tunnel holds its ports and waits for the unlock instead of redialling
unlock_identityonly accepts keys the core found encryptedsits above the update popup, paste types into it, Ctrl+C cancels it, the KDF runs
off the render loop, fixed-height popup
yields to a focused terminal, which would have received the passphrase); focus
goes back when it closes; a terminal finishing its open never steals it; Escape
closes only the top dialog
prompt covers Windows too — and it can't be verified here; worth its own PR); FIDO
id_*_skdefault keys (russh can't signwith them)
Verification
0/0, vitest 238/238, Playwright 38/39 (the one failure is pre-existing, below)
then redials on unlock), TUI render at 80x24, vitest queue/router, Playwright
passphrase spec (6)
encrypted default key, ProxyJump with both keys encrypted, wrong-then-right
passphrase, cancel + no re-prompt after the backoff retry, terminal screen, paste,
Ctrl+C; desktop app under Xvfb: prompt at launch, wrong passphrase, unlock,
dashboard online, terminal and SFTP, cancel then terminal re-prompts
Waived review findings
would be a failed login; still better than main, which stopped it (Stop/Start
resets)
on-disk changes honest; pollers hold their sessions
OpenSSH format by default; russh can't decrypt every PKCS#8 variant)
identity_fileto pickprompts once (rare; the unlock then ends in a normal refusal)
again
to credit @sisodiahs (as in fix(ssh): connect ProxyJump hosts through their bastion #75/Ship a native .rpm package for Fedora/RHEL #77)
Pre-existing (not touched)
e2e/terminal.spec.tsexpects "Close web-1 · terminal"; the label is host-onlysince d898d96
Supersedes #103.