Skip to content

Commit

Permalink
Merge pull request #1238 from smallstep/mariano/console
Browse files Browse the repository at this point in the history
Add console flag to ssh commands
  • Loading branch information
maraino authored Jul 16, 2024
2 parents 4fc8e4e + 2a6e644 commit 1fa7d00
Show file tree
Hide file tree
Showing 10 changed files with 21 additions and 23 deletions.
5 changes: 0 additions & 5 deletions command/ca/ca.go
Original file line number Diff line number Diff line change
Expand Up @@ -137,11 +137,6 @@ location being served by an existing fileserver in order to respond to ACME
challenge validation requests.`,
}

consoleFlag = cli.BoolFlag{
Name: "console",
Usage: "Complete the flow while remaining inside the terminal",
}

fingerprintFlag = cli.StringFlag{
Name: "fingerprint",
Usage: "The <fingerprint> of the targeted root certificate.",
Expand Down
2 changes: 1 addition & 1 deletion command/ca/certificate.go
Original file line number Diff line number Diff line change
Expand Up @@ -191,7 +191,7 @@ multiple SANs. The '--san' flag and the '--token' flag are mutually exclusive.`,
flags.Force,
flags.Offline,
flags.PasswordFile,
consoleFlag,
flags.Console,
flags.KMSUri,
flags.X5cCert,
flags.X5cKey,
Expand Down
2 changes: 1 addition & 1 deletion command/ca/sign.go
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,7 @@ $ step ca sign foo.csr foo.crt \
flags.Force,
flags.Offline,
flags.PasswordFile,
consoleFlag,
flags.Console,
flags.KMSUri,
flags.X5cCert,
flags.X5cKey,
Expand Down
12 changes: 1 addition & 11 deletions command/oauth/cmd.go
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
package oauth

import (
"bufio"
"bytes"
"crypto/sha256"
"crypto/x509"
Expand Down Expand Up @@ -901,11 +900,9 @@ func (o *oauth) DoDeviceAuthorization() (*token, error) {
idr.Interval = defaultDeviceAuthzInterval
}

fmt.Fprintf(os.Stderr, "Visit %s and enter the code: (press 'ENTER' to open default browser)\n", idr.VerificationURI)
fmt.Fprintf(os.Stderr, "Visit %s and enter the code:\n", idr.VerificationURI)
fmt.Fprintln(os.Stderr, idr.UserCode)

go openBrowserIfAsked(o, idr.VerificationURI)

// Poll the Token endpoint until the user completes the flow.
data = url.Values{}
data.Set("client_id", o.clientID)
Expand Down Expand Up @@ -939,13 +936,6 @@ func (o *oauth) DoDeviceAuthorization() (*token, error) {
}
}

func openBrowserIfAsked(o *oauth, u string) {
reader := bufio.NewReader(os.Stdin)
reader.ReadString('\n')

exec.OpenInBrowser(u, o.browser)
}

var errHTTPToken = errors.New("bad request; token not returned")

func (o *oauth) deviceAuthzTokenPoll(data url.Values) (*token, error) {
Expand Down
3 changes: 2 additions & 1 deletion command/ssh/certificate.go
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ func certificateCommand() cli.Command {
[**--password-file**=<file>] [**--provisioner-password-file**=<file>]
[**--add-user**] [**--not-before**=<time|duration>] [**--comment**=<comment>]
[**--not-after**=<time|duration>] [**--token**=<token>] [**--issuer**=<name>]
[**--no-password**] [**--insecure**] [**--force**] [**--x5c-cert**=<file>]
[**--console**] [**--no-password**] [**--insecure**] [**--force**] [**--x5c-cert**=<file>]
[**--x5c-key**=<file>] [**--k8ssa-token-path**=<file>] [**--no-agent**]
[**--kty**=<key-type>] [**--curve**=<curve>] [**--size**=<size>]
[**--ca-url**=<uri>] [**--root**=<file>] [**--context**=<name>]`,
Expand Down Expand Up @@ -176,6 +176,7 @@ $ step ssh certificate --kty OKP --curve Ed25519 mariano@work id_ed25519
flags.Token,
flags.TemplateSet,
flags.TemplateSetFile,
flags.Console,
sshAddUserFlag,
sshHostFlag,
sshHostIDFlag,
Expand Down
6 changes: 5 additions & 1 deletion command/ssh/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ func configCommand() cli.Command {
UsageText: `**step ssh config**
[**--team**=<name>] [**--team-authority**=<sub-domain>] [**--host**]
[**--set**=<key=value>] [**--set-file**=<file>] [**--dry-run**] [**--roots**]
[**--federation**] [**--force**] [**--offline**] [**--ca-config**=<file>]
[**--federation**] [**--console**] [**--force**] [**--offline**] [**--ca-config**=<file>]
[**--ca-url**=<uri>] [**--root**=<file>] [**--context**=<name>]
[**--authority**=<name>] [**--profile**=<name>]`,
Description: `**step ssh config** configures SSH to be used with certificates. It also supports
Expand Down Expand Up @@ -89,6 +89,7 @@ user or host certificates`,
times to set multiple variables.`,
},
flags.TemplateSetFile,
flags.Console,
flags.DryRun,
flags.Force,
flags.CaConfig,
Expand Down Expand Up @@ -204,6 +205,9 @@ func configAction(ctx *cli.Context) (recoverErr error) {
if step.Contexts().Enabled() {
data["Context"] = step.Contexts().GetCurrent().Name
}
if ctx.Bool("console") {
data["Console"] = "true"
}
if len(sets) > 0 {
for _, s := range sets {
i := strings.Index(s, "=")
Expand Down
3 changes: 2 additions & 1 deletion command/ssh/hosts.go
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ func hostsCommand() cli.Command {
Action: command.ActionFunc(hostsAction),
Usage: "returns a list of all valid hosts",
UsageText: `**step ssh hosts** [**--set**=<key=value>] [**--set-file**=<file>]
[**--offline**] [**--ca-config**=<file>] [**--ca-url**=<uri>] [**--root**=<file>]
[**--console**] [**--offline**] [**--ca-config**=<file>] [**--ca-url**=<uri>] [**--root**=<file>]
[**--context**=<name>]`,
Description: `**step ssh hosts** returns a list of valid hosts for SSH.
Expand All @@ -35,6 +35,7 @@ $ step ssh hosts
Flags: []cli.Flag{
flags.TemplateSet,
flags.TemplateSetFile,
flags.Console,
flags.Offline,
flags.CaConfig,
flags.CaURL,
Expand Down
3 changes: 2 additions & 1 deletion command/ssh/login.go
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ func loginCommand() cli.Command {
[**--token**=<token>] [**--provisioner**=<name>] [**--provisioner-password-file**=<file>]
[**--principal**=<string>] [**--not-before**=<time|duration>] [**--not-after**=<time|duration>]
[**--kty**=<key-type>] [**--curve**=<curve>] [**--size**=<size>] [**--comment**=<comment>]
[**--set**=<key=value>] [**--set-file**=<file>] [**--force**] [**--insecure**]
[**--set**=<key=value>] [**--set-file**=<file>] [**--console**] [**--force**] [**--insecure**]
[**--offline**] [**--ca-config**=<file>]
[**--ca-url**=<uri>] [**--root**=<file>] [**--context**=<name>]`,
Description: `**step ssh login** generates a new SSH key pair and send a request to [step
Expand Down Expand Up @@ -93,6 +93,7 @@ $ step ssh certificate --kty OKP --curve Ed25519 mariano@work id_ed25519
flags.NotAfter,
flags.TemplateSet,
flags.TemplateSetFile,
flags.Console,
flags.Force,
flags.Offline,
flags.CaConfig,
Expand Down
3 changes: 2 additions & 1 deletion command/ssh/proxycommand.go
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ func proxycommandCommand() cli.Command {
Usage: "proxy ssh connections according to the host registry",
UsageText: `**step ssh proxycommand** <user> <host> <port>
[**--provisioner**=<name>] [**--set**=<key=value>] [**--set-file**=<file>]
[**--offline**] [**--ca-config**=<file>]
[**--console**] [**--offline**] [**--ca-config**=<file>]
[**--ca-url**=<uri>] [**--root**=<file>] [**--context**=<name>]`,
Description: `**step ssh proxycommand** looks into the host registry
and proxies the ssh connection according to its configuration. This command
Expand All @@ -56,6 +56,7 @@ This command will add the user to the ssh-agent if necessary.
flags.ProvisionerPasswordFileWithAlias,
flags.TemplateSet,
flags.TemplateSetFile,
flags.Console,
flags.Offline,
flags.CaConfig,
flags.CaURL,
Expand Down
5 changes: 5 additions & 0 deletions flags/flags.go
Original file line number Diff line number Diff line change
Expand Up @@ -467,6 +467,11 @@ flag exists so it can be configured in $STEPPATH/config/defaults.json.`,
Name: "comment",
Usage: "The comment used when adding the certificate to an agent. Defaults to the subject if not provided.",
}

Console = cli.BoolFlag{
Name: "console",
Usage: `Complete the flow while remaining inside the terminal.`,
}
)

// FingerprintFormatFlag returns a flag for configuring the fingerprint format.
Expand Down

0 comments on commit 1fa7d00

Please sign in to comment.