Repository navigation
Require temporary credentials for authorized accounts without stored secrets - #1737
Merged
Merged
Conversation
…secrets Prompt for one-time passwords or SSH private keys when an authorized account has no stored secret. Route quick-connect and reconnect entry points through setup before requesting a token, while keeping entered secrets out of saved preferences. Constraint: Existing admin session setup cannot preserve admin authority; require an explicit error for that URL path. Constraint: The repository hook formats unrelated worktree changes and runs local-listen Web Proxy tests, so this scoped commit uses manual verification. Confidence: high Scope-risk: moderate Tested: 995 Web tests, lint, Web and Electron typechecks, staged format and diff checks. Not-tested: Web Proxy tests were not rerun after the user excluded them. Related: jumpserver/jumpserver#17614 Co-authored-by: OmX <omx@oh-my-codex.dev>
ZhaoJiSen
approved these changes
Sep 24, 2026
The first PR commit mixed SFTP file-manager credential changes with the authorized account flow. Restore SFTP-specific files and behavior to dev while retaining password and SSH-key input for hosted accounts without stored secrets. The original SFTP implementation remains available on the local wip/sftp-temporary-credentials branch for a separate submission. Constraint: Issue jumpserver/jumpserver#17614 covers authorized empty-password account connections, not SFTP file-manager behavior Rejected: Keep SFTP changes in this PR | they belong in a separate follow-up Confidence: high Scope-risk: moderate Tested: 85 focused Vitest tests; pnpm test:web (995 passed, 14 skipped); pnpm typecheck:web; pnpm typecheck:electron; pnpm lint:check; git diff --cached --check Not-tested: Web Proxy tests, per user request Related: jumpserver/jumpserver#17614 Co-authored-by: OmX <omx@oh-my-codex.dev>
ZhaoJiSen
approved these changes
Sep 24, 2026
|
9 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Require temporary credentials for authorized accounts without stored secrets Prompt for one-time passwords or SSH private keys when an authorized account has no stored secret. Route quick-connect and reconnect entry points through setup before requesting a token, while keeping entered secrets out of saved preferences. Constraint: Existing admin session setup cannot preserve admin authority; require an explicit error for that URL path. Constraint: The repository hook formats unrelated worktree changes and runs local-listen Web Proxy tests, so this scoped commit uses manual verification. Confidence: high Scope-risk: moderate Tested: 995 Web tests, lint, Web and Electron typechecks, staged format and diff checks. Not-tested: Web Proxy tests were not rerun after the user excluded them. Related: jumpserver/jumpserver#17614 Co-authored-by: OmX omx@oh-my-codex.dev