ssh: add AuthCallback to ClientConfig Add ClientAuthCallback, a hook invoked before each authentication attempt that allows the client to dynamically select an auth method based on server capabilities, partial successes, or previous failures. clientAuthenticate tracks partial successes in a slice and passes them to AuthCallback via ClientAuthContext.PartialSuccessMethods, along with the list of failed methods and currently allowed methods. When AuthCallback returns a non-nil AuthMethod, it is used for the next attempt, bypassing the static findNext selection. When it returns (nil, nil), the static config.Auth selection proceeds as before. If AuthCallback returns (nil, error) the handshake aborts immediately with that error. To bound resource use when AuthCallback keeps supplying methods, the client caps the total number of authentication attempts (failures and partial successes combined) at 64; exceeding the cap aborts the handshake with an error. Fixes golang/go#76146 Change-Id: I0d02bea7b9dd724e95e5d9d49d85306666c0df7a Reviewed-on: https://go-review.googlesource.com/c/crypto/+/717140 Reviewed-by: Cherry Mui <cherryyz@google.com> Reviewed-by: Dmitri Shuralyov <dmitshur@google.com> Reviewed-by: Filippo Valsorda <filippo@golang.org> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
This repository holds supplementary Go cryptography packages.
This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.
The git repository is https://go.googlesource.com/crypto.
The main issue tracker for the crypto repository is located at https://go.dev/issues. Prefix your issue with “x/crypto:” in the subject line, so it is easy to find.
Note that contributions to the cryptography package receive additional scrutiny due to their sensitive nature. Patches may take longer than normal to receive feedback.