elevate: show key comment instead of fingerprint in notifications
This commit is contained in:
parent
d79861ff7c
commit
fb8f4acff1
|
|
@ -121,6 +121,17 @@ func (a *approvalAgent) SignWithFlags(key ssh.PublicKey, data []byte, flags agen
|
|||
func (a *approvalAgent) signWithApproval(key ssh.PublicKey, data []byte, flags agent.SignatureFlags) (*ssh.Signature, error) {
|
||||
fp := ssh.FingerprintSHA256(key)
|
||||
|
||||
// Try to get key comment for readable display
|
||||
comment := ""
|
||||
if keys, err := a.upstream.List(); err == nil {
|
||||
for _, k := range keys {
|
||||
if ssh.FingerprintSHA256(k) == fp {
|
||||
comment = k.Comment
|
||||
break
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Check policy
|
||||
effective := a.broker.SessionPolicy("")
|
||||
if effective.Matches("", fp) {
|
||||
|
|
@ -132,9 +143,14 @@ func (a *approvalAgent) signWithApproval(key ssh.PublicKey, data []byte, flags a
|
|||
}
|
||||
|
||||
// Create pending request for approval
|
||||
label := comment
|
||||
if label == "" {
|
||||
label = fp
|
||||
}
|
||||
|
||||
req := &Request{
|
||||
ID: nextRequestID(),
|
||||
Cmd: fmt.Sprintf("ssh-sign: %s", fp),
|
||||
Cmd: fmt.Sprintf("ssh-sign: %s", label),
|
||||
Cwd: "",
|
||||
SessionID: "",
|
||||
CreatedAt: timeNow(),
|
||||
|
|
|
|||
Reference in New Issue