Skip to content

Require temporary credentials for authorized accounts without stored secrets - #1737

Merged
ZhaoJiSen merged 2 commits into
devfrom
pr@dev@fix_missing_account_secret
Sep 24, 2026
Merged

ZhaoJiSen merged 2 commits into
devfrom
pr@dev@fix_missing_account_secret

Conversation

@fit2bot

@fit2bot fit2bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Require temporary credentials for authorized accounts without stored secrets Prompt for one-time passwords or SSH private keys when an authorized account has no stored secret. Route quick-connect and reconnect entry points through setup before requesting a token, while keeping entered secrets out of saved preferences. Constraint: Existing admin session setup cannot preserve admin authority; require an explicit error for that URL path. Constraint: The repository hook formats unrelated worktree changes and runs local-listen Web Proxy tests, so this scoped commit uses manual verification. Confidence: high Scope-risk: moderate Tested: 995 Web tests, lint, Web and Electron typechecks, staged format and diff checks. Not-tested: Web Proxy tests were not rerun after the user excluded them. Related: jumpserver/jumpserver#17614 Co-authored-by: OmX omx@oh-my-codex.dev

…secrets

Prompt for one-time passwords or SSH private keys when an authorized account has no stored secret. Route quick-connect and reconnect entry points through setup before requesting a token, while keeping entered secrets out of saved preferences.

Constraint: Existing admin session setup cannot preserve admin authority; require an explicit error for that URL path.
Constraint: The repository hook formats unrelated worktree changes and runs local-listen Web Proxy tests, so this scoped commit uses manual verification.
Confidence: high
Scope-risk: moderate
Tested: 995 Web tests, lint, Web and Electron typechecks, staged format and diff checks.
Not-tested: Web Proxy tests were not rerun after the user excluded them.
Related: jumpserver/jumpserver#17614
Co-authored-by: OmX <omx@oh-my-codex.dev>
@fit2bot
fit2bot requested a review from a team September 24, 2026 02:34
The first PR commit mixed SFTP file-manager credential changes with the authorized account flow. Restore SFTP-specific files and behavior to dev while retaining password and SSH-key input for hosted accounts without stored secrets. The original SFTP implementation remains available on the local wip/sftp-temporary-credentials branch for a separate submission.

Constraint: Issue jumpserver/jumpserver#17614 covers authorized empty-password account connections, not SFTP file-manager behavior
Rejected: Keep SFTP changes in this PR | they belong in a separate follow-up
Confidence: high
Scope-risk: moderate
Tested: 85 focused Vitest tests; pnpm test:web (995 passed, 14 skipped); pnpm typecheck:web; pnpm typecheck:electron; pnpm lint:check; git diff --cached --check
Not-tested: Web Proxy tests, per user request
Related: jumpserver/jumpserver#17614
Co-authored-by: OmX <omx@oh-my-codex.dev>
@ZhaoJiSen
ZhaoJiSen merged commit 0e5f568 into dev Sep 24, 2026
11 of 14 checks passed
@ZhaoJiSen
ZhaoJiSen deleted the pr@dev@fix_missing_account_secret branch September 24, 2026 03:05
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Reliability Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants