fix: restore desktop remote authentication

Fixes switching and unlocking password-protected remote instances
Stores SSH forwarded host client tokens from saved UI passwords
Avoids unnecessary auth churn when no runtime headers are configured
This commit is contained in:
Bohdan Triapitsyn
2026-06-30 02:48:01 +03:00
parent c10930dfd0
commit 0e65a435ee
9 changed files with 338 additions and 22 deletions
+5 -1
View File
@@ -1517,9 +1517,10 @@ const extractCookieHeader = (response) => {
.join('; ');
};
const loginRemoteAndIssueClientToken = async ({ url, password, trustDevice }) => {
const loginRemoteAndIssueClientToken = async ({ url, password, trustDevice, requestHeaders }) => {
const baseUrl = normalizeHostUrl(String(url || ''));
const candidatePassword = typeof password === 'string' ? password : '';
const safeRequestHeaders = sanitizeRuntimeRequestHeaders(requestHeaders || {});
if (!baseUrl) throw new Error('Invalid URL');
if (!candidatePassword) throw new Error('Password is required');
@@ -1527,6 +1528,7 @@ const loginRemoteAndIssueClientToken = async ({ url, password, trustDevice }) =>
method: 'POST',
signal: AbortSignal.timeout(10_000),
headers: {
...safeRequestHeaders,
Accept: 'application/json',
'Content-Type': 'application/json',
},
@@ -1559,6 +1561,7 @@ const loginRemoteAndIssueClientToken = async ({ url, password, trustDevice }) =>
method: 'POST',
signal: AbortSignal.timeout(10_000),
headers: {
...safeRequestHeaders,
Accept: 'application/json',
'Content-Type': 'application/json',
Cookie: cookie,
@@ -3506,6 +3509,7 @@ const handleInvoke = async (browserWindow, command, args = {}) => {
url: args.url,
password: args.password,
trustDevice: args.trustDevice === true,
requestHeaders: args.requestHeaders || {},
});
case 'desktop_set_window_theme': {