Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled
62 lines
1.9 KiB
TypeScript
62 lines
1.9 KiB
TypeScript
import type { Host } from "./models";
|
|
import { sanitizeCredentialValue } from "./credentials";
|
|
|
|
/** Thrown when a drop lands in `/root` but the host has no usable sudo password. */
|
|
export class TerminalDropNeedsSudoError extends Error {
|
|
constructor() {
|
|
super("Terminal drop needs saved sudo elevation");
|
|
this.name = "TerminalDropNeedsSudoError";
|
|
}
|
|
}
|
|
|
|
export function normalizePosixAbsolutePath(
|
|
cwd: string | null | undefined,
|
|
): string | null {
|
|
if (typeof cwd !== "string") return null;
|
|
const trimmed = cwd.trim();
|
|
if (!trimmed.startsWith("/")) return null;
|
|
const collapsed = trimmed.replace(/\/+/g, "/");
|
|
if (collapsed === "/") return "/";
|
|
return collapsed.replace(/\/+$/, "");
|
|
}
|
|
|
|
export function posixPathNeedsLoginUserElevation(
|
|
cwd: string | null | undefined,
|
|
username: string | null | undefined,
|
|
): boolean {
|
|
const user = username?.trim() ?? "";
|
|
if (!user || user === "root") return false;
|
|
const path = normalizePosixAbsolutePath(cwd);
|
|
if (!path) return false;
|
|
return path === "/root" || path.startsWith("/root/");
|
|
}
|
|
|
|
export function hasUsableSftpSudoPassword(
|
|
password: string | undefined,
|
|
): boolean {
|
|
const value = sanitizeCredentialValue(password);
|
|
return typeof value === "string" && value.length > 0;
|
|
}
|
|
|
|
export function canElevateSftpForTerminalDrop(
|
|
host: Pick<Host, "sftpSudo" | "sftpFileProtocol">,
|
|
resolvedPassword?: string,
|
|
): boolean {
|
|
if (host.sftpFileProtocol === "scp") return false;
|
|
if (host.sftpSudo) return true;
|
|
return hasUsableSftpSudoPassword(resolvedPassword);
|
|
}
|
|
|
|
export function resolveTerminalDropSftpHost<T extends Host>(
|
|
host: T,
|
|
cwd: string,
|
|
resolved?: { password?: string; username?: string },
|
|
): T {
|
|
if (!posixPathNeedsLoginUserElevation(cwd, resolved?.username ?? host.username)) return host;
|
|
if (host.sftpSudo) return host;
|
|
if (!canElevateSftpForTerminalDrop(host, resolved?.password)) {
|
|
throw new TerminalDropNeedsSudoError();
|
|
}
|
|
return { ...host, sftpSudo: true };
|
|
}
|