Skip to content

Releases: Lifailon/terminal-sftp

Terminal SFTP Browser

Choose a tag to compare

@Lifailon Lifailon released this 28 Sep 14:25
d3b8ed3

Connection

  • SFTP client built on libssh2 (SftpClient wrapper, thread-safe, UI/background threads)
  • Two-phase connection: TCP + SSH handshake → host-key confirmation → authentication
  • Authentication: password and private key (keyPath)
  • Server home directory resolution (HomeDirectory), fallback to /

Known-Host Verification

  • OpenSSH-style known_hosts file
  • Server fingerprint (HostKeyFingerprint) and key comparison (CheckKnownHost: Match/Mismatch/NotFound)
  • First-connect fingerprint confirmation dialog; TrustHost appends the record
  • Mismatch — hard refusal (MITM protection)

Encryption

  • Profile passwords encrypted with DPAPI (CryptProtectData/CryptUnprotectData), sftp-dpapi: marker, base64 blob
  • Legacy plaintext passwords recognized and decrypted unchanged (backward compatible)
  • Profile store: %LOCALAPPDATA%...\sftp-profiles.json (UTF-16 JSON)

File Operations

  • Navigation: listing (permissions, size, time), breadcrumbs, back/forward, refresh, folder entry
  • File download and upload with progress and cancellation (cancel, progress ring)
  • Mkdir, CreateNewFile, Unlink, Rmdir, Rename, Chmod
  • File properties GetFileInfo (owner/group, size, timestamps, symlink)
  • "Show hidden files" toggle

UI (SftpBrowserContent)

  • Connection form: host, port, username, password, key path
  • Profile picker/manage via profilesListView
  • Toolbar: connect/disconnect, back/forward, refresh, new file/folder, upload/download, open config, hidden files, close
  • Status bar, ProgressRing, input overlay dialog

Integration & Configuration

  • experimental.openSftpBrowser action + profile option to open the pane
  • Feature flag Feature_SftpBrowser (id 46617), AlwaysDisabled, enabled for Dev/Canary branding
  • Schema updated: doc\cascadia\profiles.schema.json

Tests

  • TAEF project SftpUnitTests (Sftp.Unit.Tests.dll): 5/5 Passed (DPAPI passwords, JSON profile serialization/deserialization)