mirror of
https://github.com/hansjone/netx.git
synced 2026-10-09 16:43:18 +08:00
fix(bastion): match OpenSSH username parsing for protocol-proxy hop
OpenSSH treats the last @ as user/host separator, so the SSH username must be hop@target@ip without duplicating hop_host. Legacy templates with {hop_host} are stripped automatically; connect logs now show bastion_ssh_cli for comparison with manual ssh.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
79ae5ff31c
commit
088e920f9d
7 changed files with 197 additions and 67 deletions
|
|
@ -194,7 +194,7 @@ const en = {
|
|||
"· password may be empty (required for direct login; optional for bastion-managed or batch proxy later).\n" +
|
||||
"· Recommended flow: import NEs first, select rows, then use Batch add proxy.\n\n" +
|
||||
"[Jump / bastion]\n" +
|
||||
"· Bastion SSH username template: {hop_user}@{target_user}@{target_ip}@{hop_host}; target account = NE Username.\n" +
|
||||
"· Bastion SSH username template: {hop_user}@{target_user}@{target_ip} (bastion host is separate); CLI: ssh user@target@ip@bastion-host.\n" +
|
||||
"· Bastion-managed: set Jump password (Vault); target password optional. Manual mode needs target password.\n" +
|
||||
"· JumpServer/CBH often use port 2222; some sites use 22.\n\n" +
|
||||
"[Connectivity / edit]\n" +
|
||||
|
|
@ -240,7 +240,7 @@ const en = {
|
|||
targetAuthHint: "Bastion-managed needs only bastion password; manual mode requires target NE password.",
|
||||
usernameTemplate: "SSH username template",
|
||||
templateHintBastion:
|
||||
"Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank. Example: bastion-user@target-user@2.2.2.2@1.1.1.1.",
|
||||
"Default {hop_user}@{target_user}@{target_ip}. Bastion address is the hop host field. CLI example: ssh bastion-user@target-user@2.2.2.2@1.1.1.1.",
|
||||
host: "Jump host",
|
||||
port: "Jump port",
|
||||
protocol: "Jump protocol",
|
||||
|
|
|
|||
|
|
@ -192,7 +192,7 @@ const zh = {
|
|||
"· password 可留空(直连需填;堡垒机托管或后续批量添加代理时可空)。\n" +
|
||||
"· 推荐流程:先导入网元 → 勾选网元 → 点「批量添加代理」统一配置跳板/堡垒机。\n\n" +
|
||||
"【跳板 / 堡垒机】\n" +
|
||||
"· 堡垒机 SSH 用户名模板:{hop_user}@{target_user}@{target_ip}@{hop_host};目标账号填网元「用户名」。\n" +
|
||||
"· 堡垒机 SSH 用户名模板:{hop_user}@{target_user}@{target_ip}(堡垒机地址单独填在跳板地址);命令行等价:ssh 用户@目标@IP@堡垒机。\n" +
|
||||
"· 堡垒机托管时填「跳板密码」(Vault 密码),目标密码可留空;手动模式需填目标密码。\n" +
|
||||
"· JumpServer/CBH 常用跳板端口 2222,部分现场为 22。\n\n" +
|
||||
"【连通性 / 编辑】\n" +
|
||||
|
|
@ -238,7 +238,7 @@ const zh = {
|
|||
targetAuthHint: "堡垒机托管时仅需堡垒机密码;手动模式需填写目标网元密码。",
|
||||
usernameTemplate: "SSH 用户名模板",
|
||||
templateHintBastion:
|
||||
"默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:bastion-user@target-user@2.2.2.2@1.1.1.1。",
|
||||
"默认 {hop_user}@{target_user}@{target_ip},堡垒机地址填「跳板地址」。命令行示例:ssh bastion-user@target-user@2.2.2.2@1.1.1.1。",
|
||||
host: "跳板地址",
|
||||
port: "跳板端口",
|
||||
protocol: "跳板协议",
|
||||
|
|
|
|||
|
|
@ -9,9 +9,11 @@ export type HopTargetAuthMode = "bastion_managed" | "manual";
|
|||
export const HOP_VENDORS: HopVendor[] = ["zte", "huawei", "cisco", "linux", "bastion"];
|
||||
|
||||
export function bastionHopTemplate(): string {
|
||||
return "{hop_user}@{target_user}@{target_ip}@{hop_host}";
|
||||
return "{hop_user}@{target_user}@{target_ip}";
|
||||
}
|
||||
|
||||
export const LEGACY_BASTION_HOP_TEMPLATE = "{hop_user}@{target_user}@{target_ip}@{hop_host}";
|
||||
|
||||
export function isBastionHopVendor(vendor: string): boolean {
|
||||
return String(vendor || "").toLowerCase() === "bastion";
|
||||
}
|
||||
|
|
|
|||
|
|
@ -42,6 +42,11 @@ export function isAutoHopTemplate(
|
|||
if (v === "huawei") return t === huaweiHopTemplate(protocol, vrf);
|
||||
if (v === "cisco") return t === ciscoHopTemplate(protocol, vrf);
|
||||
if (v === "linux") return t === "";
|
||||
if (v === "bastion") return t === "{hop_user}@{target_user}@{target_ip}@{hop_host}";
|
||||
if (v === "bastion") {
|
||||
return (
|
||||
t === "{hop_user}@{target_user}@{target_ip}"
|
||||
|| t === "{hop_user}@{target_user}@{target_ip}@{hop_host}"
|
||||
);
|
||||
}
|
||||
return t === zteHopTemplate(protocol, vrf);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue