Files
Tea-Cli/modules/task/login_create_test.go
T
Lunny Xiao bcd62a1fb2 fix(login): avoid SSH passphrase prompt with ssh-agent logins (#1102)
Fixes #866

## Problem

`tea` still prompts for an SSH key passphrase for logins created with
`--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea
auto-discovers a matching private key in `~/.ssh` even when the login is
configured to use the running ssh-agent. That on-disk key is stored in
`ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK
to load the file from disk instead of signing through the agent.

## Changes

- Stop auto-discovering a private key when the login uses the ssh-agent.
- Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent
  logins pass an empty key path and the SDK talks to `ssh-agent`.
- Prefer SSH remotes for agent logins, matching key-file logins.
- Add unit tests for the new key-path and auto-discovery behavior.

## Testing

- `go test ./modules/config ./modules/task ./modules/git`
- `go build ./...`

---------

Co-authored-by: bircni <bircni@icloud.com>
Reviewed-on: https://gitea.com/gitea/tea/pulls/1102
Reviewed-by: bircni <bircni@icloud.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2026-10-01 19:58:41 +00:00

90 lines
2.0 KiB
Go

// Copyright 2026 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package task
import "testing"
func TestShouldCheckTokenUniqueness(t *testing.T) {
tests := []struct {
name string
token string
sshAgent bool
sshKey string
sshCertPrincipal string
sshKeyFingerprint string
wantCheckUniqueness bool
}{
{
name: "token only",
token: "token",
wantCheckUniqueness: true,
},
{
name: "token with ssh agent",
token: "token",
sshAgent: true,
wantCheckUniqueness: false,
},
{
name: "token with ssh key path",
token: "token",
sshKey: "~/.ssh/id_ed25519",
wantCheckUniqueness: false,
},
{
name: "token with ssh cert principal",
token: "token",
sshCertPrincipal: "principal",
wantCheckUniqueness: false,
},
{
name: "token with ssh key fingerprint",
token: "token",
sshKeyFingerprint: "SHA256:example",
wantCheckUniqueness: false,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
got := shouldCheckTokenUniqueness(tt.token, tt.sshAgent, tt.sshKey, tt.sshCertPrincipal, tt.sshKeyFingerprint)
if got != tt.wantCheckUniqueness {
t.Fatalf("expected %v, got %v", tt.wantCheckUniqueness, got)
}
})
}
}
func TestShouldFindSSHKey(t *testing.T) {
tests := []struct {
name string
sshKey string
sshAgent bool
want bool
}{
{
name: "explicit key",
sshKey: "~/.ssh/id_ed25519",
want: false,
},
{
name: "ssh agent",
sshAgent: true,
want: false,
},
{
name: "no key configured",
want: true,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
if got := shouldFindSSHKey(tt.sshKey, tt.sshAgent); got != tt.want {
t.Fatalf("expected %v, got %v", tt.want, got)
}
})
}
}