Diff
1diff --git a/config/auth.go b/config/auth.go
2index 54eb0df6bd291aebe75e16cb63fd86241d008187..a1ba59fe9de47cd8a9ca1981f9326da4560158e4 100644
3--- a/config/auth.go
4+++ b/config/auth.go
5@@ -6,6 +6,7 @@ import (
6
7 gm "github.com/charmbracelet/wish/git"
8 "github.com/gliderlabs/ssh"
9+ gossh "golang.org/x/crypto/ssh"
10 )
11
12 // Push registers Git push functionality for the given repo and key.
13@@ -47,6 +48,11 @@ func (cfg *Config) PasswordHandler(ctx ssh.Context, password string) bool {
14 return (cfg.AnonAccess != "no-access") && cfg.AllowKeyless
15 }
16
17+// KeyboardInteractiveHandler returns whether or not keyboard interactive is allowed.
18+func (cfg *Config) KeyboardInteractiveHandler(ctx ssh.Context, _ gossh.KeyboardInteractiveChallenge) bool {
19+ return (cfg.AnonAccess != "no-access") && cfg.AllowKeyless
20+}
21+
22 // PublicKeyHandler returns whether or not the given public key may access the
23 // repo.
24 func (cfg *Config) PublicKeyHandler(ctx ssh.Context, pk ssh.PublicKey) bool {
25diff --git a/server/server.go b/server/server.go
26index fed56f3588a4f037a50ec01d2741a73f07bf5d1f..c1e9d8c6081ac3647e0d77e6afe0a1708c8eed57 100644
27--- a/server/server.go
28+++ b/server/server.go
29@@ -45,7 +45,7 @@ func NewServer(cfg *config.Config) *Server {
30 }
31 s, err := wish.NewServer(
32 ssh.PublicKeyAuth(ac.PublicKeyHandler),
33- ssh.PasswordAuth(ac.PasswordHandler),
34+ ssh.KeyboardInteractiveAuth(ac.KeyboardInteractiveHandler),
35 wish.WithAddress(fmt.Sprintf("%s:%d", cfg.BindAddr, cfg.Port)),
36 wish.WithHostKeyPath(cfg.KeyPath),
37 wish.WithMiddleware(mw...),