mirror of
https://gitea.com/gitea/tea.git
synced 2026-10-05 17:33:50 +00:00
fix(login): avoid SSH passphrase prompt with ssh-agent logins (#1102)
Fixes #866 ## Problem `tea` still prompts for an SSH key passphrase for logins created with `--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea auto-discovers a matching private key in `~/.ssh` even when the login is configured to use the running ssh-agent. That on-disk key is stored in `ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK to load the file from disk instead of signing through the agent. ## Changes - Stop auto-discovering a private key when the login uses the ssh-agent. - Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent logins pass an empty key path and the SDK talks to `ssh-agent`. - Prefer SSH remotes for agent logins, matching key-file logins. - Add unit tests for the new key-path and auto-discovery behavior. ## Testing - `go test ./modules/config ./modules/task ./modules/git` - `go build ./...` --------- Co-authored-by: bircni <bircni@icloud.com> Reviewed-on: https://gitea.com/gitea/tea/pulls/1102 Reviewed-by: bircni <bircni@icloud.com> Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
This commit is contained in:
@@ -153,7 +153,7 @@ func CreateLogin(ctx stdctx.Context, name, token, user, passwd, otp, scopes, ssh
|
||||
// so we just use the host
|
||||
login.SSHHost = serverURL.Host
|
||||
|
||||
if len(sshKey) == 0 {
|
||||
if shouldFindSSHKey(sshKey, sshAgent) {
|
||||
login.SSHKey, err = findSSHKey(ctx, client)
|
||||
if err != nil {
|
||||
fmt.Printf("Warning: problem while finding a SSH key: %s\n", err)
|
||||
@@ -176,6 +176,10 @@ func CreateLogin(ctx stdctx.Context, name, token, user, passwd, otp, scopes, ssh
|
||||
return nil
|
||||
}
|
||||
|
||||
func shouldFindSSHKey(sshKey string, sshAgent bool) bool {
|
||||
return sshKey == "" && !sshAgent
|
||||
}
|
||||
|
||||
func shouldCheckTokenUniqueness(token string, sshAgent bool, sshKey, sshCertPrincipal, sshKeyFingerprint string) bool {
|
||||
if sshAgent || sshKey != "" || sshCertPrincipal != "" || sshKeyFingerprint != "" {
|
||||
return false
|
||||
|
||||
@@ -55,3 +55,35 @@ func TestShouldCheckTokenUniqueness(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestShouldFindSSHKey(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
sshKey string
|
||||
sshAgent bool
|
||||
want bool
|
||||
}{
|
||||
{
|
||||
name: "explicit key",
|
||||
sshKey: "~/.ssh/id_ed25519",
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "ssh agent",
|
||||
sshAgent: true,
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "no key configured",
|
||||
want: true,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
if got := shouldFindSSHKey(tt.sshKey, tt.sshAgent); got != tt.want {
|
||||
t.Fatalf("expected %v, got %v", tt.want, got)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
@@ -61,10 +61,9 @@ func remoteURLForPR(login *config.Login, pr *gitea.PullRequest) string {
|
||||
if isRemoteDeleted(pr) {
|
||||
repo = pr.Base.Repository
|
||||
}
|
||||
if len(login.SSHKey) != 0 {
|
||||
// login.SSHKey is nonempty, if user specified a key manually or we automatically
|
||||
// found a matching private key on this machine during login creation.
|
||||
// this means, we are very likely to have a working ssh setup.
|
||||
if login.SSHKeyPath() != "" || login.SSHAgent {
|
||||
// Use SSH when a key file is configured, or when the login authenticates
|
||||
// through a running ssh-agent. In both cases we have a working SSH setup.
|
||||
return repo.SSHURL
|
||||
}
|
||||
return repo.CloneURL
|
||||
@@ -84,7 +83,7 @@ func doPRFetch(
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
auth, err := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKey, callback)
|
||||
auth, err := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKeyPath(), callback)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
@@ -95,7 +95,7 @@ call me again with the --ignore-sha flag`, remoteBranch)
|
||||
if urlErr != nil {
|
||||
return urlErr
|
||||
}
|
||||
auth, authErr := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKey, callback)
|
||||
auth, authErr := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKeyPath(), callback)
|
||||
if authErr != nil {
|
||||
return authErr
|
||||
}
|
||||
|
||||
@@ -210,7 +210,7 @@ func CreateAgitFlowPull(requestCtx stdctx.Context, ctx *context.TeaContext, remo
|
||||
return err
|
||||
}
|
||||
|
||||
auth, err := local_git.GetAuthForURL(url, ctx.Login.GetAccessToken(), ctx.Login.SSHKey, callback)
|
||||
auth, err := local_git.GetAuthForURL(url, ctx.Login.GetAccessToken(), ctx.Login.SSHKeyPath(), callback)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
@@ -33,7 +33,7 @@ func RepoClone(
|
||||
return nil, err
|
||||
}
|
||||
|
||||
auth, err := local_git.GetAuthForURL(originURL, login.GetAccessToken(), login.SSHKey, callback)
|
||||
auth, err := local_git.GetAuthForURL(originURL, login.GetAccessToken(), login.SSHKeyPath(), callback)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -68,7 +68,7 @@ func RepoClone(
|
||||
|
||||
func cloneURL(repo *gitea.Repository, login *config.Login) (*url.URL, error) {
|
||||
urlStr := repo.CloneURL
|
||||
if login.SSHKey != "" {
|
||||
if login.SSHKeyPath() != "" || login.SSHAgent {
|
||||
urlStr = repo.SSHURL
|
||||
}
|
||||
return local_git.ParseURL(urlStr)
|
||||
|
||||
Reference in New Issue
Block a user