The backend could already authenticate with a password, but only the API could
supply the field — the UI had no way in. It goes in "Advanced SSH" next to
Identity File: the two are answers to the same question, and seeing them together
is what makes the choice obvious. The hint says outright to prefer a key when one
exists.
Three details, each of which breaks something if skipped:
- the field is type="password" and is never populated from the server. GET is
redacted, so any code writing a value into this box can only be writing a
placeholder — and the next save would store that placeholder as the real
password.
- the value is deliberately not trimmed: leading or trailing spaces may be part
of the password.
- it is added to the remoteFields clearing list. Without that, a typed password
persists across forms and the next new host silently inherits it — credentials
from two different machines bleeding together.
Both submit paths are wired: the standalone "add remote host", and the one that
creates a host as part of the remote-case flow. Wiring only one leaves the other
silently key-only. Guard tests pin each of the above (including "must be both
paths" and "must never repopulate").