ssh install refuses stray arguments before -- and a symlinked authorized_keys (closes #61)
check / check (push) Failing after 3s
check / check (push) Failing after 3s
ssh install now takes the host alone before --: any other word there, or a second argument without --, is refused before the mnemonic is read or sftp runs, so keyfunc ssh install alice@host frank@host no longer installs the key for frank@host. The first listing of ~/.ssh is now ls -n, which shows the file type, so a symlinked authorized_keys is refused before any upload instead of being replaced by a regular file; the README says so. Judgement calls: install -- host is refused; a symlinked authorized_keys is refused even when its target already holds the key. Model: opus-5-5 Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
This commit was merged in pull request #62.
This commit is contained in:
@@ -177,10 +177,13 @@ same way: one that cannot be read fails the first listing, and one that can be
|
||||
read but not entered fails the second, after which the tool says that `~/.ssh`
|
||||
cannot be entered. The wording of a missing file elsewhere does not count
|
||||
either, since `ssh` writes `No such file or directory` about an `-i` it cannot
|
||||
find on a session that then authenticates through the agent. If an identical
|
||||
line is already in the file, the tool prints `already present` and connects no
|
||||
further. Otherwise the line is added (after a newline, if the file did not end
|
||||
with one) and a second connection:
|
||||
find on a session that then authenticates through the agent. An
|
||||
`authorized_keys` that the first listing shows to be a symlink is refused and
|
||||
left as it is, since the rename below would replace the link itself and the file
|
||||
it points at would never get the key. If an identical line is already in the
|
||||
file, the tool prints `already present` and connects no further. Otherwise the
|
||||
line is added (after a newline, if the file did not end with one) and a second
|
||||
connection:
|
||||
|
||||
- makes `~/.ssh` and sets it to mode `0700`, but only when the first connection
|
||||
found none; a `~/.ssh` that was already there keeps the mode it had;
|
||||
|
||||
Reference in New Issue
Block a user