Bring the naitve ssh pam to the browser gateway

This commit is contained in:
Owen
2026-05-22 11:30:21 -07:00
parent e6267cc1fc
commit 1ff26b7acd
7 changed files with 130 additions and 22 deletions
+7 -2
View File
@@ -62,11 +62,16 @@ func (g *Gateway) HandleSSH(w http.ResponseWriter, r *http.Request) {
}
target = net.JoinHostPort(host, port)
} else {
// Native SSH mode: validate against the global gateway token.
// Native SSH mode: validate the gateway token then read the target username.
if subtle.ConstantTimeCompare([]byte(token), []byte(g.authToken)) != 1 {
http.Error(w, "unauthorized", http.StatusUnauthorized)
return
}
username = r.URL.Query().Get("username")
if username == "" {
http.Error(w, "missing username", http.StatusBadRequest)
return
}
}
ws, err := websocket.Accept(w, r, &websocket.AcceptOptions{
@@ -81,7 +86,7 @@ func (g *Gateway) HandleSSH(w http.ResponseWriter, r *http.Request) {
defer ws.CloseNow() //nolint:errcheck
if nativeSSH {
if err := serveNativeSSHSession(ctx, ws); err != nil {
if err := serveNativeSSHSession(ctx, ws, username); err != nil {
log.Printf("SSH native session error: %v", err)
}
} else {