Files
RouterOS/RouterOSAssistant/Core/Networking/SSHTransport.swift
T
KayandClaude Sonnet 5 c4ed26b8dd M2: Backup-Service + Sicherungen-Tab
Config-Export (/export terse) über eine dedizierte SSH-Verbindung,
unabhängig vom aktiven Live-Transport (REST oder SSH) — RouterOS' REST-API
hat keinen generischen Export-Endpunkt. Lokale Sicherungen unter
~/Library/Application Support/RouterOSAssistant/Backups/. Neuer
"Sicherungen"-Tab mit manuellem "Jetzt sichern"-Button, SessionStore
teilt die Zugangsdaten der aktiven Verbindung zwischen den Tabs.

Der bestehende Connect-Schritt dient bereits als reiner Lese-Modus
(nur GET-Aufrufe) — ein zusätzlicher Dry-Run-Schalter entfällt, da es
vor M3 noch keine Schreibpfade gibt.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HReLXMbmPvtQ23p1iWiJNW
2026-09-11 20:58:39 +02:00

60 lines
2.2 KiB
Swift

import Foundation
import Citadel
/// SSH+CLI transport fallback for RouterOS devices/firmware without the REST API (pre-7.1).
///
/// Known limitation (tracked for M7 hardening): host key validation currently accepts any key.
/// This is acceptable for now because REST already provides certificate TOFU on the primary
/// path and this fallback is used for local-network devices only, but it should get the same
/// trust-on-first-use treatment before wider distribution.
final class SSHTransport: RouterOSTransport {
let kind: RouterOSTransportKind = .ssh
private let credentials: RouterOSCredentials
private var client: SSHClient?
init(credentials: RouterOSCredentials) {
self.credentials = credentials
}
func connect() async throws {
do {
client = try await SSHClient.connect(
host: credentials.host,
port: credentials.sshPort,
authenticationMethod: .passwordBased(username: credentials.username, password: credentials.password),
hostKeyValidator: .acceptAnything(),
reconnect: .never
)
} catch {
throw RouterOSError.transportUnavailable("SSH-Verbindung fehlgeschlagen: \(error.localizedDescription)")
}
}
func fetchDeviceInfo() async throws -> RouterDeviceInfo {
let output = try await run("/system resource print without-paging")
return RouterOSCliParser.parseDeviceInfo(output)
}
func fetchInterfaces() async throws -> [NetworkInterface] {
let output = try await run("/interface print without-paging terse")
return RouterOSCliParser.parseInterfaces(output)
}
func disconnect() async {
try? await client?.close()
client = nil
}
/// Full human-readable config export (`/export terse`), used for local backups.
func exportConfiguration() async throws -> String {
try await run("/export terse")
}
private func run(_ command: String) async throws -> String {
guard let client else { throw RouterOSError.notConnected }
let buffer = try await client.executeCommand(command)
return String(buffer: buffer)
}
}