Skip to content

Support Warpgate SSH selectors and interactive authentication - #238

Merged
bifrost0x merged 11 commits into
mainfrom
dev/warpgate-integration
Sep 23, 2026
Merged

bifrost0x merged 11 commits into
mainfrom
dev/warpgate-integration

Conversation

@bifrost0x

@bifrost0x bifrost0x commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Warpgate connections need selector usernames, explicit multi-factor authentication, and target readiness before WebSSH starts a shell, tmux, or startup commands. This adds user:target support to existing SSH profiles and Quick SFTP with socket-owned prompts, bounded output, cancellation, and quota admission.

The integration is disabled by default. An administrator enables it globally under Settings → Administration → Integrations, using the existing protected settings endpoint and password/factor step-up. The setting persists in the existing application settings store. The server rejects gateway requests while disabled, including requests from stale or modified browser clients. Disabling also blocks unfinished gateway authentication; stored profiles and established sessions are retained. Open workspaces must be reloaded to refresh their UI capability.

Ordinary SSH retains its existing authentication, cancellation, request tracking, banner wait, and timeouts. Ordinary Quick SFTP remains synchronous. Only enabled gateway requests use the additional interaction lifecycle; cross-path request-ID collisions are rejected. Existing profile auth types, Tailscale authorization, jump-host routing, and host-key checks remain in place. Common SFTP failures now expose safe, actionable reasons such as permission denied or a read-only filesystem without returning raw exception details.

No Compose service, dependency, or database migration is added. Gateway dialogs reuse the existing modal structure, form controls and theme colors, with readable approval links, visible focus states and mobile layout. They remain above connection forms and below authentication banners.

See the integration guide for activation and limits. Terminal targets need PTY and exec support; Quick SFTP needs a temporary PTY plus a separate SFTP channel. Tickets and gateway administration are outside this change.

Validation for 15d9802:

  • Python 3.14 on Windows: 3,396 passed, 53 skipped. Six failures were reproduced on the unchanged 3568107 baseline: command-storage limit behavior, three POSIX entrypoint tests, the PTY shell probe and Linux route lookup. This is not a fully green local suite.
  • 653 JavaScript unit tests, JavaScript lint and all 10 vendored asset checks passed.
  • 12 gateway browser tests passed, including default-off behavior and actual admin enable/disable with step-up verification; 29 existing Quick Connect, profile launcher and post-connect browser tests passed.
  • Desktop and mobile screenshots were inspected. Gateway challenge screenshots use synthetic messages.
  • Hosted CI for this revision is pending.

Earlier real-protocol evidence remains revision-specific: 47eb6f3 was verified through browser TOTP authentication and cancellation against disposable Warpgate 0.29.0 and OpenSSH. At f4328b4, all 13 reference Warpgate tests passed, plus terminal commands, byte-identical SFTP transfers, tmux reconnect and WebUserApproval. These protocol fixtures were not rerun for the latest settings/UI change. External identity-provider and live Tailscale acceptance remain deployment-specific checks.

Refs #237.

@bifrost0x
bifrost0x marked this pull request as ready for review September 23, 2026 07:35
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T07:41:26.967637Z b97a9b4 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b97a9b4d9b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread static/js/app.js Outdated
Comment thread static/js/session-manager.js
@bifrost0x bifrost0x self-assigned this Sep 23, 2026
@bifrost0x bifrost0x added the enhancement New feature or request label Sep 23, 2026
@bifrost0x bifrost0x linked an issue Sep 23, 2026 that may be closed by this pull request
@bifrost0x
bifrost0x merged commit 7829e4c into main Sep 23, 2026
25 of 26 checks passed
@bifrost0x
bifrost0x deleted the dev/warpgate-integration branch September 23, 2026 15:49
@github-project-automation github-project-automation Bot moved this from Backlog to Done in WebSSH Roadmap Sep 23, 2026
@bifrost0x bifrost0x mentioned this pull request Oct 3, 2026
7 tasks done
@bifrost0x bifrost0x added this to the v2.5.0 milestone Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

Add support for Warpgate Userauth

1 participant