Skip to content

feat(remote): cut off all managed endpoints on sign-out - #658

Merged
Ziinc merged 2 commits into
claude/prd-gaps-auth-revocation-cutofffrom
claude/prd-gaps-auth-revocation-cutoff-2
Oct 1, 2026
Merged

Ziinc merged 2 commits into
claude/prd-gaps-auth-revocation-cutofffrom
claude/prd-gaps-auth-revocation-cutoff-2

Conversation

@Ziinc

@Ziinc Ziinc commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #645.
Remote PRD AC9 / Mobile AC8. Signing out only cleared the relay token, so pooled managed SSH connections and their PTYs kept accepting exec and PTY traffic. This PR adds the native side of the fix. The next PR in the stack calls it from sign-out.

  • SshConnectionPool::cut_off_managed(reason) tears down every pooled connection to a managed endpoint through the existing force_cutoff, and sets a pool-wide flag that refuses new managed connections, pooled or not. Before this, a managed endpoint with no pooled connection could still reconnect. The flag clears when set_relay_access_token receives a token again, which happens on sign-in. Each torn-down endpoint stays cut off until its own reauthentication, as it does today.
  • The new Tauri command remote_cut_off_managed also closes the PTY sessions for those endpoints and emits remote://cutoff (session_ended) for each one, so the existing cutoff UI blocks them.
  • User-managed and alias endpoints are untouched.
    Checks run: cargo fmt --check, cargo clippy --all-targets -- -D warnings, cargo test --lib core::remote (166 passed, including the new cut_off_managed_tears_down_managed_endpoints_until_sign_in).
    🤖 Generated with Claude Code
    https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
    Generated by Claude Code

Signing out only cleared the relay token, so pooled managed SSH
connections and their PTYs kept accepting exec and PTY traffic.
SshConnectionPool::cut_off_managed tears down every pooled managed
connection and refuses new managed connections until a signed-in token
arrives. The remote_cut_off_managed command also closes the PTYs for those
endpoints and emits remote://cutoff (session_ended) for each one.
User-managed endpoints are untouched.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
The repo requires every Tauri command to ship with its api wrapper and
a caller, so remoteCutOffManaged and the authStore.signOut call move
here from the follow-up PR.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
@Ziinc
Ziinc merged commit 66ded5e into claude/prd-gaps-auth-revocation-cutoff Oct 1, 2026
21 checks passed
@Ziinc
Ziinc deleted the claude/prd-gaps-auth-revocation-cutoff-2 branch October 1, 2026 07:19

Ziinc commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Consolidated into #645 (managed auth cutoff). Closing.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants