* feat(ssh): accept PuTTY-style CLI args from bastion hosts
Reuse the existing ssh:// and telnet:// deep-link path so PAM products that launch putty.exe -ssh user@host -P port -pw password can point at Netcatty instead.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ssh): consume operands of ignored PuTTY flags
Unknown value-taking options such as -m and -D were skipped while their next token was treated as a host or port, which could connect the supplied password to the wrong endpoint.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ssh): reject unsupported PuTTY protocols and unknown flags
-raw/-rlogin/-serial must not fall through to SSH with the supplied password, and valueless switches such as -batch must not consume the following host. Unknown dash flags are now rejected instead of guessed.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ssh): reject missing or empty PuTTY option operands
An empty or trailing -pw was turned into ssh://user:@host, which the deep-link path treats as no password and can then authenticate with a saved vault credential.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ssh): reject unsupported -pwfile, -i, and -hostkey launches
Those options request credentials or a host-key pin this pipeline cannot honor, so connecting with -pw or a vault match would silently change the authentication the caller asked for.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ssh): keep .app/.exe hosts and reject -loghost
Suffix filtering now only covers the Electron script argument, so destinations like prod.app are not dropped. -loghost is rejected because this pipeline cannot honor the logical host-key identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ssh): keep packaged argv[1] hosts like prod.js
Suffix filtering now applies only after an Electron binary, so a packaged launch can still use a first-position hostname that looks like a script.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>