Files
Tea-Cli/modules/task/repo_clone.go
T
Lunny Xiao bcd62a1fb2 fix(login): avoid SSH passphrase prompt with ssh-agent logins (#1102)
Fixes #866

## Problem

`tea` still prompts for an SSH key passphrase for logins created with
`--ssh-agent-key` or `--ssh-agent-principal`. During `tea login add`, tea
auto-discovers a matching private key in `~/.ssh` even when the login is
configured to use the running ssh-agent. That on-disk key is stored in
`ssh_key`, so later `Login.Client()` asks for its passphrase and tells the SDK
to load the file from disk instead of signing through the agent.

## Changes

- Stop auto-discovering a private key when the login uses the ssh-agent.
- Add `Login.SSHKeyPath()` and use it for HTTPSign and git auth, so agent
  logins pass an empty key path and the SDK talks to `ssh-agent`.
- Prefer SSH remotes for agent logins, matching key-file logins.
- Add unit tests for the new key-path and auto-discovery behavior.

## Testing

- `go test ./modules/config ./modules/task ./modules/git`
- `go build ./...`

---------

Co-authored-by: bircni <bircni@icloud.com>
Reviewed-on: https://gitea.com/gitea/tea/pulls/1102
Reviewed-by: bircni <bircni@icloud.com>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
2026-10-01 19:58:41 +00:00

76 lines
1.8 KiB
Go

// Copyright 2021 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package task
import (
stdctx "context"
"net/url"
gitea "gitea.dev/sdk"
"gitea.dev/tea/modules/config"
local_git "gitea.dev/tea/modules/git"
)
// RepoClone creates a local git clone in the given path, and sets up upstream remote
// for fork repos, for good usability with tea.
func RepoClone(
ctx stdctx.Context,
path string,
login *config.Login,
repoOwner, repoName string,
callback func(string) (string, error),
depth int,
) (*local_git.TeaRepo, error) {
repoMeta, _, err := login.Client().Repositories.GetRepo(ctx, repoOwner, repoName)
if err != nil {
return nil, err
}
originURL, err := cloneURL(repoMeta, login)
if err != nil {
return nil, err
}
auth, err := local_git.GetAuthForURL(originURL, login.GetAccessToken(), login.SSHKeyPath(), callback)
if err != nil {
return nil, err
}
// default path behavior as native git
if path == "" {
path = repoName
}
repo, err := local_git.Clone(path, originURL.String(), auth, depth, login.Insecure)
if err != nil {
return nil, err
}
// set up upstream remote for forks
if repoMeta.Fork && repoMeta.Parent != nil {
upstreamURL, err := cloneURL(repoMeta.Parent, login)
if err != nil {
return nil, err
}
upstreamBranch := repoMeta.Parent.DefaultBranch
if err = repo.AddRemote("upstream", upstreamURL.String()); err != nil {
return nil, err
}
if err = repo.SetBranchUpstream(upstreamBranch, "upstream", upstreamBranch); err != nil {
return nil, err
}
}
return repo, nil
}
func cloneURL(repo *gitea.Repository, login *config.Login) (*url.URL, error) {
urlStr := repo.CloneURL
if login.SSHKeyPath() != "" || login.SSHAgent {
urlStr = repo.SSHURL
}
return local_git.ParseURL(urlStr)
}