feat: add safe Gitea sync and signed updates
ForgeFlow quality gate / secret-scan (push) Failing after 32s
ForgeFlow quality gate / quality (push) Failing after 0s

This commit is contained in:
NuklearRabbit committed 2026-08-27 00:38:58 +02:00
1 parent cb9bdcd713
commit d47c7b5e41
46 files changed
+1658 -246

No files matched your search

+53 -7
View File
@@ -53,9 +53,10 @@ function parseCapabilityOutput(output) {
}
class SshService {
constructor({ store, diagnostics, idleConnectionMs = 60_000 }) {
constructor({ store, diagnostics, idleConnectionMs = 60_000, clientFactory = loadSshClient }) {
this.store = store;
this.diagnostics = diagnostics;
this.clientFactory = clientFactory;
// Every command used to pay for a TCP handshake, a key exchange and an
// authentication round trip. Sessions are kept per server for a short while
// so a sequence of commands shares one connection.
@@ -104,7 +105,7 @@ class SshService {
return { valid: true, method: 'privateKey', encrypted: Boolean(passphrase), privateKeyPath };
}
async connectionOptions(server, { trustOnFirstUse = false } = {}) {
async connectionOptions(server, { trustOnFirstUse = false, expectedFingerprint = null } = {}) {
const credentials = this.store.getServerCredentials(server.id);
let observedFingerprint = null;
const options = {
@@ -116,7 +117,8 @@ class SshService {
keepaliveCountMax: 3,
hostVerifier: (key) => {
observedFingerprint = fingerprintKey(key);
return trustOnFirstUse || Boolean(server.hostFingerprint && observedFingerprint === server.hostFingerprint);
const trustedFingerprint = String(server.hostFingerprint || expectedFingerprint || '').trim();
return trustOnFirstUse || Boolean(trustedFingerprint && observedFingerprint === trustedFingerprint);
},
};
if (server.authType === 'password') options.password = credentials.password;
@@ -137,7 +139,7 @@ class SshService {
if (!server) throw new Error('The configured SSH server no longer exists.');
// A trust-on-first-use connection is established without checking the
// fingerprint, so it must never serve a later verified call.
if (options.trustOnFirstUse) return this.withDedicatedClient(server, action, options);
if (options.trustOnFirstUse || options.expectedFingerprint) return this.withDedicatedClient(server, action, options);
return this.withPooledClient(server, action, options);
}
@@ -243,7 +245,7 @@ class SshService {
async withDedicatedClient(server, action, options = {}, { keepOpen = false } = {}) {
const serverId = server.id;
const Client = loadSshClient();
const Client = this.clientFactory();
const connection = await this.connectionOptions(server, options);
const client = new Client();
const started = Date.now();
@@ -414,7 +416,51 @@ class SshService {
}));
}
async test(serverId, { trustOnFirstUse = true } = {}) {
async probeHostFingerprint(serverId) {
const server = this.store.getServer(serverId);
if (!server) throw new Error('The configured SSH server no longer exists.');
const Client = this.clientFactory();
const client = new Client();
let observedFingerprint = null;
return new Promise((resolve, reject) => {
let settled = false;
const finish = (callback, value) => {
if (settled) return;
settled = true;
clearTimeout(timer);
try { client.end(); } catch { /* handshake already closed */ }
callback(value);
};
const completeProbe = (error = null) => {
if (observedFingerprint) {
finish(resolve, {
fingerprint: observedFingerprint,
server: { id: server.id, name: server.name, host: server.host, port: server.port || 22 },
});
return;
}
const wrapped = new Error(`Could not read the SSH host fingerprint: ${error?.message || 'the server closed the handshake'}`);
wrapped.code = error?.code || 'SSH_HOST_KEY_PROBE_FAILED';
finish(reject, wrapped);
};
const timer = setTimeout(() => completeProbe(new Error('The SSH host-key probe timed out.')), 25_000);
client.on('error', completeProbe);
client.on('close', () => completeProbe());
client.on('end', () => completeProbe());
client.connect({
host: server.host,
port: server.port || 22,
username: server.username,
readyTimeout: 20_000,
hostVerifier: (key) => {
observedFingerprint = fingerprintKey(key);
return false;
},
});
});
}
async test(serverId, { trustOnFirstUse = false, expectedFingerprint = null } = {}) {
return this.withClient(serverId, async (client, server, fingerprint) => {
const script = `
platform=$(uname -srm 2>/dev/null || true)
@@ -449,7 +495,7 @@ printf 'baseWritable=%s\\n' "$base_writable"
capabilities,
output: [capabilities.platform, capabilities.composeVersion].filter(Boolean).join('\n'),
};
}, { trustOnFirstUse });
}, { trustOnFirstUse, expectedFingerprint });
}
async exec(serverId, command, options = {}) {