Skip to content

Add opt-in saved SSH passwords with per-use device unlock #46

Description

@R055LE

Problem

Password authentication currently needs manual entry on every connection. Reuse must remain an explicit user choice with a clear device-access policy.

Contract

Add an optional saved password to a reusable SSH identity. Protect each saved password with Android Keystore authenticated encryption under a separate auth-bound key. Require device credential or supported strong biometric approval for every new connection that uses it. Support create, replace, and confirmation-gated deletion. On Android 10 and older, or when device authentication cannot be used, keep session-only password entry. Imported-key passphrases and privilege-prompt replies remain session-only.

Acceptance

  • No plaintext password enters Room, Android saved state, logs, diagnostics, backup, or clipboard.
  • Cancellation, key invalidation, missing device lock, and device transfer lead to manual re-entry or credential replacement, never silent bypass.
  • Deletion removes the ciphertext record and its protection key; profile and host-trust records remain.
  • Unlock authorizes one connection attempt, not a background cache or future session.

Validation

Add Keystore and UI tests on Android 11+ for successful use, cancellation, replacement, invalidation, and deletion; check the older-device fallback.

Depends on #45. Part of #44.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions