Always try password before keyboard-interactive for the first factor. After
any partial success, prefer keyboard-interactive when the server still allows
it so multi-factor/EDR second factors work without a per-host switch. Remove
the requiresMfa UI and "remember MFA" checkbox; keep secondary-prompt
protections and hostId-aware password save.
Default stays password-first for ordinary hosts. Hosts with requiresMfa
prefer keyboard-interactive so EDR secondary factors are not skipped.
Secondary prompts can suggest enabling MFA mode for that host.
Pass allowSavePassword=false for post-partialSuccess / EDR / multi-round
keyboard-interactive challenges so the modal cannot overwrite the host
login password with a secondary secret (Codex P2 on #2151).
Expand secondary-password regex to allow words between "secondary" and
"password", and scan keyboard-interactive name/instructions so Chinese
"二次认证密码" banners still block auto-fill when only the English field
label is in the prompt text.
Track partialSuccess on simple/agent ordered auth handlers, omit saved
password from second-factor modal payloads, and align modal prefill
deny-list with the backend MFA vocabulary.
Do not auto-fill keyboard-interactive challenges that look like
secondary/EDR passwords, and skip saved-password auto-fill after a
first-factor partialSuccess so step-up prompts always surface the modal.
* fix: support CSV password import and save password in keyboard-interactive auth (#627)
- Add Password column support to CSV import/export/template
- Add isAPasswordPrompt detection (prompt contains "password" + echo=false)
- Auto-fill saved password in keyboard-interactive modal
- Add "Save password" checkbox for password prompts in keyboard-interactive modal
- Wire save callback through sessionId → host to persist password
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: address review feedback for keyboard-interactive and CSV changes
- Merge password field in dedupeHosts to avoid losing passwords from duplicate CSV rows
- Extract isAPasswordPrompt to module-level pure function
- Only render save-password checkbox at the first password prompt index
- Clean up orphaned i18n keys (useSaved, useSavedPassword, fill, fillSaved)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: preserve whitespace in CSV imported passwords
Passwords may intentionally contain leading/trailing whitespace.
Removing .trim() ensures lossless CSV round-trip and correct auth.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: exclude OTP prompts from password detection and guard jump host save
- Add negative patterns (one-time, otp, verification, token, code) to
isAPasswordPrompt to avoid auto-filling SSH password into OTP fields
- Only save password when request hostname matches session hostname,
preventing jump host passwords from overwriting the destination host
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: skip formula injection guard for password column in CSV export
Password values starting with =, +, -, @ were getting a ' prefix from
the CSV formula injection protection, breaking round-trip fidelity.
Now password column is escaped for CSV syntax only, preserving the
credential verbatim.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: only skip formula guard for data rows, not header row
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Enhances keyboard-interactive (2FA/MFA) authentication by implementing a queue-based system, allowing multiple concurrent requests to be processed sequentially.
Previously, password prompts during keyboard-interactive authentication were auto-filled if a saved password was available. This change removes the auto-fill behavior to prevent issues with custom or ambiguous prompt texts, instead providing a user-initiated "Use saved password" option in the UI.
Increases the connection timeout to 120 seconds to provide ample time for users to complete 2FA challenges. A new UI indicator shows when additional 2FA requests are pending.
Also, refines SSH authentication logic to strictly respect explicit password authentication, preventing unintended attempts to use private keys when password authentication is selected.