Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@

Toutes les évolutions notables de WarpgateSH sont documentées ici.

## Non publié

- Les changements de bannière SSH dans les commentaires de `ssh-keyscan` ne sont plus signalés comme une rotation des clés hôtes. Les modifications du matériel des clés restent refusées.
- Des tests de contrat couvrent les API utilisateur Warpgate 0.27.5, 0.28.6 et 0.29.1, ainsi que la conservation de l’état local en cas de réponse invalide ou d’erreur HTTP.

## 0.1.16 — 2026-09-10

- Une préférence d’authentification SSH par profil permet de conserver la validation navigateur après chaque régénération des alias, y compris pour les nouvelles cibles. Elle se règle avec `warpgatesh profile ssh-auth <profil> in-browser` et survit au renouvellement du jeton ainsi qu’au réenrôlement du profil. Les profils existants conservent le mode automatique.
Expand Down
24 changes: 24 additions & 0 deletions crates/warpgatesh-runtime/src/ssh.rs
Original file line number Diff line number Diff line change
Expand Up @@ -135,6 +135,7 @@ pub fn verify_host_keys(
fn key_material(known_hosts: &str) -> BTreeSet<(&str, &str)> {
known_hosts
.lines()
.filter(|line| !line.trim_start().starts_with('#'))
.filter_map(|line| {
let mut fields = line.split_whitespace();
let _hosts = fields.next()?;
Expand Down Expand Up @@ -333,6 +334,29 @@ mod tests {
assert!(!uninstall_managed_include(&paths).expect("second uninstall"));
}

#[test]
fn ignores_scan_banner_changes_when_comparing_pinned_keys() {
let pinned = "# gateway:2222 SSH-2.0-russh_0.62.5\n\
gateway ssh-ed25519 AAAA\n\
gateway ssh-rsa BBBB\n";
let presented = " # gateway:2222 SSH-2.0-russh_0.63.3\n\n\
gateway ssh-rsa BBBB\n\
gateway ssh-ed25519 AAAA\n";

assert_eq!(key_material(pinned), key_material(presented));
assert_eq!(key_material(pinned).len(), 2);
}

#[test]
fn still_detects_changed_keys_when_scan_banners_match() {
let pinned = "# gateway:2222 SSH-2.0-russh_0.63.3\n\
gateway ssh-ed25519 AAAA\n";
let presented = "# gateway:2222 SSH-2.0-russh_0.63.3\n\
gateway ssh-ed25519 CHANGED\n";

assert_ne!(key_material(pinned), key_material(presented));
}

#[test]
fn compares_host_keys_without_depending_on_host_labels_or_order() {
let pinned = "host-a ssh-ed25519 AAAA\nhost-a ssh-rsa BBBB\n";
Expand Down
26 changes: 26 additions & 0 deletions crates/warpgatesh-runtime/tests/fixtures/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Warpgate user API fixtures

These are synthetic responses, not captured production data. Hostnames use
`example.test`, usernames and UUIDs are invented, and no fixture contains a
credential. Test requests use a synthetic token.

Each `info.json` contains the required fields of the upstream `Info` schema
plus the authenticated metadata consumed by WarpgateSH. Each `targets.json`
includes all seven `TargetKind` values, required `TargetSnapshot` fields and
one synthetic target group. Optional fields not needed by these tests are
omitted. The 0.29.1 info fixture deliberately omits the removed
`minimize_password_login` field and includes the new MFA fields.

Source: `warpgate-web/src/gateway/lib/openapi-schema.json` in the official
[Warpgate repository](https://github.com/warp-tech/warpgate), reviewed 2026-10-02.

| Version | Immutable source commit |
| --- | --- |
| 0.27.5 | [a28faaa4f99e6a2a7bbb4db359b18b539536f78b](https://github.com/warp-tech/warpgate/blob/a28faaa4f99e6a2a7bbb4db359b18b539536f78b/warpgate-web/src/gateway/lib/openapi-schema.json) |
| 0.28.6 | [525c7caf2219d5f5e3913b5732e4cbad5d15cd34](https://github.com/warp-tech/warpgate/blob/525c7caf2219d5f5e3913b5732e4cbad5d15cd34/warpgate-web/src/gateway/lib/openapi-schema.json) |
| 0.29.1 | [54f93c807be2c161a94c0df764242849125161a8](https://github.com/warp-tech/warpgate/blob/54f93c807be2c161a94c0df764242849125161a8/warpgate-web/src/gateway/lib/openapi-schema.json) |

When adding a version, check the actual HTTP route mounting and token security
scheme too. Verify fixture required fields, types, enum values and target UUIDs
against its schema; do not infer future API shapes or label synthetic fixtures
as live-server validation. See the [compatibility review](../../../../docs/warpgate-api-compatibility.md).
27 changes: 27 additions & 0 deletions crates/warpgatesh-runtime/tests/fixtures/warpgate-0.27.5/info.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
{
"ports": {
"ssh": 2222,
"http": 443
},
"password_login_mode": "Enabled",
"minimize_password_login": false,
"authorized_via_ticket": false,
"authorized_via_sso_with_single_logout": false,
"own_credential_management_allowed": true,
"ticket_self_service_enabled": false,
"ticket_require_description": false,
"ticket_request_show_all_targets": false,
"target_click_action": "Connect",
"web_clients_enabled": false,
"has_ldap": false,
"should_prompt_analytics": false,
"banner": "",
"show_session_menu": true,
"version": "0.27.5",
"username": "alice",
"external_host": "gateway.example.test",
"external_hosts": {
"ssh": "ssh.example.test",
"http": "gateway.example.test"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
[
{
"id": "00000000-0000-4000-8000-000000000001",
"name": "http",
"description": "Synthetic Http target",
"kind": "Http"
},
{
"id": "00000000-0000-4000-8000-000000000002",
"name": "kubernetes",
"description": "Synthetic Kubernetes target",
"kind": "Kubernetes"
},
{
"id": "00000000-0000-4000-8000-000000000003",
"name": "mysql",
"description": "Synthetic MySql target",
"kind": "MySql"
},
{
"id": "00000000-0000-4000-8000-000000000004",
"name": "db",
"description": "Synthetic Ssh target",
"kind": "Ssh",
"group": {
"id": "00000000-0000-4000-8000-000000000100",
"name": "Servers",
"color": "Primary"
}
},
{
"id": "00000000-0000-4000-8000-000000000005",
"name": "postgres",
"description": "Synthetic Postgres target",
"kind": "Postgres"
},
{
"id": "00000000-0000-4000-8000-000000000006",
"name": "vnc",
"description": "Synthetic Vnc target",
"kind": "Vnc"
},
{
"id": "00000000-0000-4000-8000-000000000007",
"name": "rdp",
"description": "Synthetic Rdp target",
"kind": "Rdp"
}
]
28 changes: 28 additions & 0 deletions crates/warpgatesh-runtime/tests/fixtures/warpgate-0.28.6/info.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
{
"ports": {
"ssh": 2222,
"http": 443
},
"password_login_mode": "Enabled",
"minimize_password_login": false,
"authorized_via_ticket": false,
"authorized_via_sso_with_single_logout": false,
"own_credential_management_allowed": true,
"ticket_self_service_enabled": false,
"ticket_require_description": false,
"ticket_request_show_all_targets": false,
"target_click_action": "Connect",
"open_targets_in_new_tab": "DefaultOn",
"web_clients_enabled": false,
"has_ldap": false,
"should_prompt_analytics": false,
"banner": "",
"show_session_menu": true,
"version": "0.28.6",
"username": "alice",
"external_host": "gateway.example.test",
"external_hosts": {
"ssh": "ssh.example.test",
"http": "gateway.example.test"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
[
{
"id": "00000000-0000-4000-8000-000000000001",
"name": "http",
"description": "Synthetic Http target",
"kind": "Http"
},
{
"id": "00000000-0000-4000-8000-000000000002",
"name": "kubernetes",
"description": "Synthetic Kubernetes target",
"kind": "Kubernetes"
},
{
"id": "00000000-0000-4000-8000-000000000003",
"name": "mysql",
"description": "Synthetic MySql target",
"kind": "MySql"
},
{
"id": "00000000-0000-4000-8000-000000000004",
"name": "db",
"description": "Synthetic Ssh target",
"kind": "Ssh",
"group": {
"id": "00000000-0000-4000-8000-000000000100",
"name": "Servers",
"color": "Primary"
}
},
{
"id": "00000000-0000-4000-8000-000000000005",
"name": "postgres",
"description": "Synthetic Postgres target",
"kind": "Postgres"
},
{
"id": "00000000-0000-4000-8000-000000000006",
"name": "vnc",
"description": "Synthetic Vnc target",
"kind": "Vnc"
},
{
"id": "00000000-0000-4000-8000-000000000007",
"name": "rdp",
"description": "Synthetic Rdp target",
"kind": "Rdp"
}
]
29 changes: 29 additions & 0 deletions crates/warpgatesh-runtime/tests/fixtures/warpgate-0.29.1/info.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
{
"ports": {
"ssh": 2222,
"http": 443
},
"password_login_mode": "Enabled",
"authorized_via_ticket": false,
"authorized_via_sso_with_single_logout": false,
"own_credential_management_allowed": true,
"ticket_self_service_enabled": false,
"ticket_require_description": false,
"ticket_request_show_all_targets": false,
"target_click_action": "Connect",
"open_targets_in_new_tab": "DefaultOn",
"web_clients_enabled": false,
"has_ldap": false,
"needs_mfa_setup": false,
"otp_setup_enforced": false,
"should_prompt_analytics": false,
"banner": "",
"show_session_menu": true,
"version": "0.29.1",
"username": "alice",
"external_host": "gateway.example.test",
"external_hosts": {
"ssh": "ssh.example.test",
"http": "gateway.example.test"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
[
{
"id": "00000000-0000-4000-8000-000000000001",
"name": "http",
"description": "Synthetic Http target",
"kind": "Http"
},
{
"id": "00000000-0000-4000-8000-000000000002",
"name": "kubernetes",
"description": "Synthetic Kubernetes target",
"kind": "Kubernetes"
},
{
"id": "00000000-0000-4000-8000-000000000003",
"name": "mysql",
"description": "Synthetic MySql target",
"kind": "MySql"
},
{
"id": "00000000-0000-4000-8000-000000000004",
"name": "db",
"description": "Synthetic Ssh target",
"kind": "Ssh",
"group": {
"id": "00000000-0000-4000-8000-000000000100",
"name": "Servers",
"color": "Primary"
}
},
{
"id": "00000000-0000-4000-8000-000000000005",
"name": "postgres",
"description": "Synthetic Postgres target",
"kind": "Postgres"
},
{
"id": "00000000-0000-4000-8000-000000000006",
"name": "vnc",
"description": "Synthetic Vnc target",
"kind": "Vnc"
},
{
"id": "00000000-0000-4000-8000-000000000007",
"name": "rdp",
"description": "Synthetic Rdp target",
"kind": "Rdp"
}
]
Loading
Loading