mirror of
https://gitea.com/gitea/tea.git
synced 2026-10-04 09:14:32 +00:00
bcd62a1fb2
Fixes #866 ## Problem `tea` still prompts for an SSH key passphrase for logins created with `--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea auto-discovers a matching private key in `~/.ssh` even when the login is configured to use the running ssh-agent. That on-disk key is stored in `ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK to load the file from disk instead of signing through the agent. ## Changes - Stop auto-discovering a private key when the login uses the ssh-agent. - Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent logins pass an empty key path and the SDK talks to `ssh-agent`. - Prefer SSH remotes for agent logins, matching key-file logins. - Add unit tests for the new key-path and auto-discovery behavior. ## Testing - `go test ./modules/config ./modules/task ./modules/git` - `go build ./...` --------- Co-authored-by: bircni <bircni@icloud.com> Reviewed-on: https://gitea.com/gitea/tea/pulls/1102 Reviewed-by: bircni <bircni@icloud.com> Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
90 lines
2.0 KiB
Go
90 lines
2.0 KiB
Go
// Copyright 2026 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package task
|
|
|
|
import "testing"
|
|
|
|
func TestShouldCheckTokenUniqueness(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
token string
|
|
sshAgent bool
|
|
sshKey string
|
|
sshCertPrincipal string
|
|
sshKeyFingerprint string
|
|
wantCheckUniqueness bool
|
|
}{
|
|
{
|
|
name: "token only",
|
|
token: "token",
|
|
wantCheckUniqueness: true,
|
|
},
|
|
{
|
|
name: "token with ssh agent",
|
|
token: "token",
|
|
sshAgent: true,
|
|
wantCheckUniqueness: false,
|
|
},
|
|
{
|
|
name: "token with ssh key path",
|
|
token: "token",
|
|
sshKey: "~/.ssh/id_ed25519",
|
|
wantCheckUniqueness: false,
|
|
},
|
|
{
|
|
name: "token with ssh cert principal",
|
|
token: "token",
|
|
sshCertPrincipal: "principal",
|
|
wantCheckUniqueness: false,
|
|
},
|
|
{
|
|
name: "token with ssh key fingerprint",
|
|
token: "token",
|
|
sshKeyFingerprint: "SHA256:example",
|
|
wantCheckUniqueness: false,
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
got := shouldCheckTokenUniqueness(tt.token, tt.sshAgent, tt.sshKey, tt.sshCertPrincipal, tt.sshKeyFingerprint)
|
|
if got != tt.wantCheckUniqueness {
|
|
t.Fatalf("expected %v, got %v", tt.wantCheckUniqueness, got)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestShouldFindSSHKey(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
sshKey string
|
|
sshAgent bool
|
|
want bool
|
|
}{
|
|
{
|
|
name: "explicit key",
|
|
sshKey: "~/.ssh/id_ed25519",
|
|
want: false,
|
|
},
|
|
{
|
|
name: "ssh agent",
|
|
sshAgent: true,
|
|
want: false,
|
|
},
|
|
{
|
|
name: "no key configured",
|
|
want: true,
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
if got := shouldFindSSHKey(tt.sshKey, tt.sshAgent); got != tt.want {
|
|
t.Fatalf("expected %v, got %v", tt.want, got)
|
|
}
|
|
})
|
|
}
|
|
}
|