Commit Graph

15 Commits

Author SHA1 Message Date
bincxz 06bbc646a7 fix(port-forward): route auth responses to request owner 2026-07-21 04:29:26 +00:00
ydm 9e4816af70 fix(sftp): 复用终端 SSH 会话打开 SFTP 2026-07-21 11:41:46 +08:00
bincxz 9a0956595c fix(ssh): drop host MFA switch; password-first with automatic KI fallback
Always try password before keyboard-interactive for the first factor. After
any partial success, prefer keyboard-interactive when the server still allows
it so multi-factor/EDR second factors work without a per-host switch. Remove
the requiresMfa UI and "remember MFA" checkbox; keep secondary-prompt
protections and hostId-aware password save.
2026-07-15 23:51:46 +08:00
ydm 987032ffa5 fix(ssh): 补齐 MFA exec 元数据和密码提示标签 2026-07-15 23:51:46 +08:00
ydm 0d6513c14e fix(ssh): 精确保存 MFA 主机并调整证书认证顺序 2026-07-15 23:51:46 +08:00
bincxz f2dc48e8b6 fix(ssh): host-level MFA instead of global keyboard-interactive first
Default stays password-first for ordinary hosts. Hosts with requiresMfa
prefer keyboard-interactive so EDR secondary factors are not skipped.
Secondary prompts can suggest enabling MFA mode for that host.
2026-07-15 23:51:46 +08:00
ydm 47909d4ae6 fix(ssh): 修复 EDR 二次认证弹窗 2026-07-15 23:51:45 +08:00
bincxz d354ccbb2c fix(ssh): hide save-password for second-factor KI prompts
Pass allowSavePassword=false for post-partialSuccess / EDR / multi-round
keyboard-interactive challenges so the modal cannot overwrite the host
login password with a secondary secret (Codex P2 on #2151).
2026-07-13 11:17:33 +08:00
bincxz 568a8f0ab7 fix(ssh): match Secondary Authentication Password EDR prompts
Expand secondary-password regex to allow words between "secondary" and
"password", and scan keyboard-interactive name/instructions so Chinese
"二次认证密码" banners still block auto-fill when only the English field
label is in the prompt text.
2026-07-13 11:08:44 +08:00
bincxz a926a36e35 fix(ssh): address codex review on MFA secondary password prefill
Track partialSuccess on simple/agent ordered auth handlers, omit saved
password from second-factor modal payloads, and align modal prefill
deny-list with the backend MFA vocabulary.
2026-07-13 10:57:55 +08:00
bincxz a1079bd7d4 fix(ssh): show MFA modal for EDR secondary passwords (#2150)
Do not auto-fill keyboard-interactive challenges that look like
secondary/EDR passwords, and skip saved-password auto-fill after a
first-factor partialSuccess so step-up prompts always surface the modal.
2026-07-13 10:53:13 +08:00
Zheng Liu d9334a8e73 fix: harden session restore isolation 2026-06-18 11:26:26 +08:00
陈大猫 24df4b6548 fix: support CSV password import and save password in keyboard-interactive auth (#629)
* fix: support CSV password import and save password in keyboard-interactive auth (#627)

- Add Password column support to CSV import/export/template
- Add isAPasswordPrompt detection (prompt contains "password" + echo=false)
- Auto-fill saved password in keyboard-interactive modal
- Add "Save password" checkbox for password prompts in keyboard-interactive modal
- Wire save callback through sessionId → host to persist password

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address review feedback for keyboard-interactive and CSV changes

- Merge password field in dedupeHosts to avoid losing passwords from duplicate CSV rows
- Extract isAPasswordPrompt to module-level pure function
- Only render save-password checkbox at the first password prompt index
- Clean up orphaned i18n keys (useSaved, useSavedPassword, fill, fillSaved)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: preserve whitespace in CSV imported passwords

Passwords may intentionally contain leading/trailing whitespace.
Removing .trim() ensures lossless CSV round-trip and correct auth.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: exclude OTP prompts from password detection and guard jump host save

- Add negative patterns (one-time, otp, verification, token, code) to
  isAPasswordPrompt to avoid auto-filling SSH password into OTP fields
- Only save password when request hostname matches session hostname,
  preventing jump host passwords from overwriting the destination host

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: skip formula injection guard for password column in CSV export

Password values starting with =, +, -, @ were getting a ' prefix from
the CSV formula injection protection, breaking round-trip fidelity.
Now password column is escaped for CSV syntax only, preserving the
credential verbatim.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: only skip formula guard for data rows, not header row

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-05 14:39:39 +08:00
bincxz 5918f91132 Improves 2FA and SSH authentication handling
Enhances keyboard-interactive (2FA/MFA) authentication by implementing a queue-based system, allowing multiple concurrent requests to be processed sequentially.

Previously, password prompts during keyboard-interactive authentication were auto-filled if a saved password was available. This change removes the auto-fill behavior to prevent issues with custom or ambiguous prompt texts, instead providing a user-initiated "Use saved password" option in the UI.

Increases the connection timeout to 120 seconds to provide ample time for users to complete 2FA challenges. A new UI indicator shows when additional 2FA requests are pending.

Also, refines SSH authentication logic to strictly respect explicit password authentication, preventing unintended attempts to use private keys when password authentication is selected.
2026-01-20 17:59:42 +08:00
copilot-swe-agent[bot] 869d30d4dd Add keyboard-interactive (2FA/MFA) authentication support for SSH, SFTP, and Port Forwarding
Co-authored-by: binaricat <16399091+binaricat@users.noreply.github.com>
2026-01-19 18:13:21 +00:00