fix(login): avoid SSH passphrase prompt with ssh-agent logins (#1102)

Fixes #866

## Problem

`tea` still prompts for an SSH key passphrase for logins created with
`--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea
auto-discovers a matching private key in `~/.ssh` even when the login is
configured to use the running ssh-agent. That on-disk key is stored in
`ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK
to load the file from disk instead of signing through the agent.

## Changes

- Stop auto-discovering a private key when the login uses the ssh-agent.
- Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent
  logins pass an empty key path and the SDK talks to `ssh-agent`.
- Prefer SSH remotes for agent logins, matching key-file logins.
- Add unit tests for the new key-path and auto-discovery behavior.

## Testing

- `go test ./modules/config ./modules/task ./modules/git`
- `go build ./...`

---------

Co-authored-by: bircni <bircni@icloud.com>
Reviewed-on: https://gitea.com/gitea/tea/pulls/1102
Reviewed-by: bircni <bircni@icloud.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
This commit is contained in:
Lunny Xiao
2026-10-01 19:58:41 +00:00
committed by bircni
parent 6daaa7c05e
commit bcd62a1fb2
8 changed files with 90 additions and 13 deletions
+12 -3
View File
@@ -489,7 +489,7 @@ func (l *Login) ClientWithoutRefresh(options ...gitea.ClientOption) *gitea.Clien
fmt.Fprintf(os.Stderr, "Failed to read SSH passphrase: %s\n", err)
os.Exit(1)
}
options = append(options, gitea.UseSSHCert(l.SSHCertPrincipal, l.SSHKey, l.SSHPassphrase))
options = append(options, gitea.UseSSHCert(l.SSHCertPrincipal, l.SSHKeyPath(), l.SSHPassphrase))
}
if l.SSHKeyFingerprint != "" {
@@ -497,7 +497,7 @@ func (l *Login) ClientWithoutRefresh(options ...gitea.ClientOption) *gitea.Clien
fmt.Fprintf(os.Stderr, "Failed to read SSH passphrase: %s\n", err)
os.Exit(1)
}
options = append(options, gitea.UseSSHPubkey(l.SSHKeyFingerprint, l.SSHKey, l.SSHPassphrase))
options = append(options, gitea.UseSSHPubkey(l.SSHKeyFingerprint, l.SSHKeyPath(), l.SSHPassphrase))
}
client, err := gitea.NewClient(l.URL, options...)
@@ -513,7 +513,7 @@ func (l *Login) ClientWithoutRefresh(options ...gitea.ClientOption) *gitea.Clien
}
func (l *Login) askForSSHPassphrase() error {
if ok, err := utils.IsKeyEncrypted(l.SSHKey); ok && err == nil && l.SSHPassphrase == "" {
if ok, err := utils.IsKeyEncrypted(l.SSHKeyPath()); ok && err == nil && l.SSHPassphrase == "" {
return huh.NewInput().
Title("ssh-key is encrypted please enter the passphrase: ").
Validate(huh.ValidateNotEmpty()).
@@ -525,6 +525,15 @@ func (l *Login) askForSSHPassphrase() error {
return nil
}
// SSHKeyPath returns the on-disk SSH key to use, or an empty string when the
// login is configured to authenticate through a running ssh-agent.
func (l *Login) SSHKeyPath() string {
if l.SSHAgent {
return ""
}
return l.SSHKey
}
// GetSSHHost returns SSH host name
func (l *Login) GetSSHHost() string {
if l.SSHHost != "" {
+33
View File
@@ -90,6 +90,39 @@ func TestLoginClientWithSSHPubkeyDoesNotDeadlockOnFirstRequest(t *testing.T) {
assert.EqualValues(t, 1, signedIssueRequests.Load())
}
func TestLoginSSHKeyPath(t *testing.T) {
t.Parallel()
tests := []struct {
name string
login Login
want string
}{
{
name: "disk key",
login: Login{SSHKey: "/tmp/id_ed25519"},
want: "/tmp/id_ed25519",
},
{
name: "ssh agent ignores disk key",
login: Login{SSHKey: "/tmp/id_ed25519", SSHAgent: true},
want: "",
},
{
name: "ssh agent without disk key",
login: Login{SSHAgent: true},
want: "",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
t.Parallel()
assert.Equal(t, tt.want, tt.login.SSHKeyPath())
})
}
}
func writeTestSSHKey(t *testing.T) (string, string) {
t.Helper()
+5 -1
View File
@@ -153,7 +153,7 @@ func CreateLogin(ctx stdctx.Context, name, token, user, passwd, otp, scopes, ssh
// so we just use the host
login.SSHHost = serverURL.Host
if len(sshKey) == 0 {
if shouldFindSSHKey(sshKey, sshAgent) {
login.SSHKey, err = findSSHKey(ctx, client)
if err != nil {
fmt.Printf("Warning: problem while finding a SSH key: %s\n", err)
@@ -176,6 +176,10 @@ func CreateLogin(ctx stdctx.Context, name, token, user, passwd, otp, scopes, ssh
return nil
}
func shouldFindSSHKey(sshKey string, sshAgent bool) bool {
return sshKey == "" && !sshAgent
}
func shouldCheckTokenUniqueness(token string, sshAgent bool, sshKey, sshCertPrincipal, sshKeyFingerprint string) bool {
if sshAgent || sshKey != "" || sshCertPrincipal != "" || sshKeyFingerprint != "" {
return false
+32
View File
@@ -55,3 +55,35 @@ func TestShouldCheckTokenUniqueness(t *testing.T) {
})
}
}
func TestShouldFindSSHKey(t *testing.T) {
tests := []struct {
name string
sshKey string
sshAgent bool
want bool
}{
{
name: "explicit key",
sshKey: "~/.ssh/id_ed25519",
want: false,
},
{
name: "ssh agent",
sshAgent: true,
want: false,
},
{
name: "no key configured",
want: true,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
if got := shouldFindSSHKey(tt.sshKey, tt.sshAgent); got != tt.want {
t.Fatalf("expected %v, got %v", tt.want, got)
}
})
}
}
+4 -5
View File
@@ -61,10 +61,9 @@ func remoteURLForPR(login *config.Login, pr *gitea.PullRequest) string {
if isRemoteDeleted(pr) {
repo = pr.Base.Repository
}
if len(login.SSHKey) != 0 {
// login.SSHKey is nonempty, if user specified a key manually or we automatically
// found a matching private key on this machine during login creation.
// this means, we are very likely to have a working ssh setup.
if login.SSHKeyPath() != "" || login.SSHAgent {
// Use SSH when a key file is configured, or when the login authenticates
// through a running ssh-agent. In both cases we have a working SSH setup.
return repo.SSHURL
}
return repo.CloneURL
@@ -84,7 +83,7 @@ func doPRFetch(
if err != nil {
return "", err
}
auth, err := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKey, callback)
auth, err := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKeyPath(), callback)
if err != nil {
return "", err
}
+1 -1
View File
@@ -95,7 +95,7 @@ call me again with the --ignore-sha flag`, remoteBranch)
if urlErr != nil {
return urlErr
}
auth, authErr := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKey, callback)
auth, authErr := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKeyPath(), callback)
if authErr != nil {
return authErr
}
+1 -1
View File
@@ -210,7 +210,7 @@ func CreateAgitFlowPull(requestCtx stdctx.Context, ctx *context.TeaContext, remo
return err
}
auth, err := local_git.GetAuthForURL(url, ctx.Login.GetAccessToken(), ctx.Login.SSHKey, callback)
auth, err := local_git.GetAuthForURL(url, ctx.Login.GetAccessToken(), ctx.Login.SSHKeyPath(), callback)
if err != nil {
return err
}
+2 -2
View File
@@ -33,7 +33,7 @@ func RepoClone(
return nil, err
}
auth, err := local_git.GetAuthForURL(originURL, login.GetAccessToken(), login.SSHKey, callback)
auth, err := local_git.GetAuthForURL(originURL, login.GetAccessToken(), login.SSHKeyPath(), callback)
if err != nil {
return nil, err
}
@@ -68,7 +68,7 @@ func RepoClone(
func cloneURL(repo *gitea.Repository, login *config.Login) (*url.URL, error) {
urlStr := repo.CloneURL
if login.SSHKey != "" {
if login.SSHKeyPath() != "" || login.SSHAgent {
urlStr = repo.SSHURL
}
return local_git.ParseURL(urlStr)