Skip to content

fix(ssh-config): ask each account before importing ~/.ssh/config (#557) - #565

Merged
kipavy merged 1 commit into
devfrom
fix/ssh-config-consent-557
Oct 7, 2026
Merged

kipavy merged 1 commit into
devfrom
fix/ssh-config-consent-557

Conversation

@kipavy

@kipavy kipavy commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Fixes #557.

The SSH Config Sync plugin imported this machine's ~/.ssh/config hosts, keys and identities into the Personal vault of whichever account was signed in. That included a second, unrelated account (e.g. a customer's self-hosted account) used on the same workstation.

What changes

  • Before its first sync on an account, the plugin shows a notification banner: "Import N hosts from this computer's ~/.ssh/config into this account's Personal vault? Their SSH keys are imported too." with Import / Don't import.
  • The answer is stored as import_consent in plugin storage. Plugin storage is restored per account on sign-in and account switch, so each account answers for itself. Dismissing the banner without answering asks again next launch. No prompt when ~/.ssh/config is missing or has no usable hosts.
  • Declined or unanswered accounts get no initial sync and no file watcher. A poll-interval change no longer restarts a stopped watcher. "Sync now" and the MCP sync tool refuse too.
  • New settings toggle Import from this computer changes the answer: on starts sync and watcher, off stops the watcher.
  • Existing accounts: an account with no stored answer but a non-empty alias_map counts as having said yes, so current users see no change after updating.
  • The three settings toggle rows now share one toggleRow helper.
  • Strings in all 6 locales with plural forms. Manifest 1.2.1 → 1.3.0.

Not changed

  • Declining or turning the toggle off does not remove hosts and keys already imported. Users who were already hit have to delete those by hand.
  • The answer is per account, not per device: saying Import on one machine means another machine signed in to the same account also imports its own ~/.ssh/config.
  • Users running a marketplace-installed copy keep the old behaviour until they click Update, which needs the catalogue entry bumped after release.

Verification

  • register.test.ts: 9 new tests. Forcing the gate open makes 8 of them fail.
  • vitest run src/plugins/ssh-config: 34 passed. tests/pluginCatalogPublish.test.ts passes.
  • tsc --noEmit clean, check-plugin-versions OK.
  • Not verified in the running app (banner, toggle, account switch).

The plugin imported local hosts, keys and identities into whichever
account was signed in, including a second, unrelated account on the same
machine. It now asks once per account before the first sync and stores
the answer in plugin storage, which is restored per account on sign-in.

Declined or unanswered accounts get no initial sync, no watcher, and the
Sync now button and MCP sync tool refuse. A settings toggle changes the
answer. Accounts that already have ssh-config hosts keep syncing without
a prompt.
@kipavy
kipavy merged commit 9731f6d into dev Oct 7, 2026
4 checks passed
@kipavy
kipavy deleted the fix/ssh-config-consent-557 branch October 7, 2026 10:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant