fix(login): avoid SSH passphrase prompt with ssh-agent logins (#1102)

Fixes #866

## Problem

`tea` still prompts for an SSH key passphrase for logins created with
`--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea
auto-discovers a matching private key in `~/.ssh` even when the login is
configured to use the running ssh-agent. That on-disk key is stored in
`ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK
to load the file from disk instead of signing through the agent.

## Changes

- Stop auto-discovering a private key when the login uses the ssh-agent.
- Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent
  logins pass an empty key path and the SDK talks to `ssh-agent`.
- Prefer SSH remotes for agent logins, matching key-file logins.
- Add unit tests for the new key-path and auto-discovery behavior.

## Testing

- `go test ./modules/config ./modules/task ./modules/git`
- `go build ./...`

---------

Co-authored-by: bircni <bircni@icloud.com>
Reviewed-on: https://gitea.com/gitea/tea/pulls/1102
Reviewed-by: bircni <bircni@icloud.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
This commit is contained in:
Lunny Xiao
2026-10-01 19:58:41 +00:00
committed by bircni
parent 6daaa7c05e
commit bcd62a1fb2
8 changed files with 90 additions and 13 deletions
+4 -5
View File
@@ -61,10 +61,9 @@ func remoteURLForPR(login *config.Login, pr *gitea.PullRequest) string {
if isRemoteDeleted(pr) {
repo = pr.Base.Repository
}
if len(login.SSHKey) != 0 {
// login.SSHKey is nonempty, if user specified a key manually or we automatically
// found a matching private key on this machine during login creation.
// this means, we are very likely to have a working ssh setup.
if login.SSHKeyPath() != "" || login.SSHAgent {
// Use SSH when a key file is configured, or when the login authenticates
// through a running ssh-agent. In both cases we have a working SSH setup.
return repo.SSHURL
}
return repo.CloneURL
@@ -84,7 +83,7 @@ func doPRFetch(
if err != nil {
return "", err
}
auth, err := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKey, callback)
auth, err := local_git.GetAuthForURL(url, login.GetAccessToken(), login.SSHKeyPath(), callback)
if err != nil {
return "", err
}