Repository navigation
Conversation
Signing out only cleared the relay token, so pooled managed SSH connections and their PTYs kept accepting exec and PTY traffic. SshConnectionPool::cut_off_managed tears down every pooled managed connection and refuses new managed connections until a signed-in token arrives. The remote_cut_off_managed command also closes the PTYs for those endpoints and emits remote://cutoff (session_ended) for each one. User-managed endpoints are untouched. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
The repo requires every Tauri command to ship with its api wrapper and a caller, so remoteCutOffManaged and the authStore.signOut call move here from the follow-up PR. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
Ziinc
merged commit Oct 1, 2026
66ded5e
into
claude/prd-gaps-auth-revocation-cutoff
21 checks passed
Collaborator
Author
|
Consolidated into #645 (managed auth cutoff). Closing. Generated by Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #645.
Remote PRD AC9 / Mobile AC8. Signing out only cleared the relay token, so pooled managed SSH connections and their PTYs kept accepting exec and PTY traffic. This PR adds the native side of the fix. The next PR in the stack calls it from sign-out.
SshConnectionPool::cut_off_managed(reason)tears down every pooled connection to a managed endpoint through the existingforce_cutoff, and sets a pool-wide flag that refuses new managed connections, pooled or not. Before this, a managed endpoint with no pooled connection could still reconnect. The flag clears whenset_relay_access_tokenreceives a token again, which happens on sign-in. Each torn-down endpoint stays cut off until its own reauthentication, as it does today.remote_cut_off_managedalso closes the PTY sessions for those endpoints and emitsremote://cutoff(session_ended) for each one, so the existing cutoff UI blocks them.Checks run:
cargo fmt --check,cargo clippy --all-targets -- -D warnings,cargo test --lib core::remote(166 passed, including the newcut_off_managed_tears_down_managed_endpoints_until_sign_in).🤖 Generated with Claude Code
https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
Generated by Claude Code