Problem
Password authentication currently needs manual entry on every connection. Reuse must remain an explicit user choice with a clear device-access policy.
Contract
Add an optional saved password to a reusable SSH identity. Protect each saved password with Android Keystore authenticated encryption under a separate auth-bound key. Require device credential or supported strong biometric approval for every new connection that uses it. Support create, replace, and confirmation-gated deletion. On Android 10 and older, or when device authentication cannot be used, keep session-only password entry. Imported-key passphrases and privilege-prompt replies remain session-only.
Acceptance
- No plaintext password enters Room, Android saved state, logs, diagnostics, backup, or clipboard.
- Cancellation, key invalidation, missing device lock, and device transfer lead to manual re-entry or credential replacement, never silent bypass.
- Deletion removes the ciphertext record and its protection key; profile and host-trust records remain.
- Unlock authorizes one connection attempt, not a background cache or future session.
Validation
Add Keystore and UI tests on Android 11+ for successful use, cancellation, replacement, invalidation, and deletion; check the older-device fallback.
Depends on #45. Part of #44.
Problem
Password authentication currently needs manual entry on every connection. Reuse must remain an explicit user choice with a clear device-access policy.
Contract
Add an optional saved password to a reusable SSH identity. Protect each saved password with Android Keystore authenticated encryption under a separate auth-bound key. Require device credential or supported strong biometric approval for every new connection that uses it. Support create, replace, and confirmation-gated deletion. On Android 10 and older, or when device authentication cannot be used, keep session-only password entry. Imported-key passphrases and privilege-prompt replies remain session-only.
Acceptance
Validation
Add Keystore and UI tests on Android 11+ for successful use, cancellation, replacement, invalidation, and deletion; check the older-device fallback.
Depends on #45. Part of #44.