Telechore Usage What's new

Servers

A server is a saved connection: where the machine is, who you are on it, and how to log in.

On the start page, the button under Open a folder… reads Add a server while you have none and Manage servers once you have one. The Servers heading below it has the same two as icons: the plus opens the form for a new server, and the sliders open the list.

The page lists your saved servers. Add a server opens the form under the list, a row's Edit opens the same form for that server, and Close puts it away. An existing server shows its id instead of letting you edit it, because the id cannot change once saved.

A green dot before a server's name means it is connected. Beside Edit and Delete, New terminal (a terminal with a plus) opens a new terminal on that server; it is hidden while a form is open. A server with terminals you left open (see Keep in the terminal) lists them under its row, after Open terminals, as numbered chips: a green dot for one that is running, an amber dot and ended for one whose shell has ended. Tap a chip to go back to that terminal; on a desktop, one in a window of its own is listed too, and its chip brings that window forward.

Delete on a row removes the server from this device, with its saved password or passphrase, and closes its connection and any terminals you left open on it. It asks first; nothing on the server itself changes.

A server's folders

A server's folder is browsed like one on this device (see Tree and sidebar). Its header has New folder and Upload, which takes files from the system's picker, on a desktop and on Android, and never replaces a folder with a file. Each row's ⋯ has Delete…; a file's also has Download, and what this device keeps of it (see Files offline).

A folder whose connection has dropped connects again on its own when you next use it. On a phone that happens often: Android cuts the network a few seconds after the app leaves the screen, including while you choose files to upload. A download cut off that way picks up where it stopped once the app is back.

The free edition and Pro

A copy installed from an app store is the free edition, which saves a few servers: two from Google Play, four from the Microsoft Store. Where the store sells it, Unlock Pro saves as many as you like, for one payment with no subscription, and Restore purchase gets it back on a new device or after a reinstall. Google Play sells Pro; the Microsoft Store does not yet, so a copy from there keeps its four.

A copy downloaded as a file, such as the Windows .exe or an APK, has no store to buy from and no limit.

Past the limit, servers you already have keep working and can still be edited and deleted; only adding another needs Pro, where the store sells it. The free edition also keeps that many terminals running after you leave them (see Keep in the terminal); keeping more running needs Pro too, where the store sells it. Files, the terminal and keys are free either way.

Moving servers to another device

Export… on the list shows a QR image for another device running Telechore to scan. Tick what to include: which servers, their host keys, the passwords and passphrases saved on this device, and any key this app made that those servers use. A key this app did not make is never included in a configuration code, and the sheet names any server that will arrive without its key.

The meter shows how much fits. It measures size, not servers: a short host name with no host key takes a third of the room of a long one with a key. The limit is well below what a QR image can hold, because a denser image is harder to scan.

The password beside Export encrypts the code, and you type the same one on the other device. It is optional, and any length will do. A code with only servers and host keys hardly needs one: all it reveals is host names and user names. For a code that carries a password, a passphrase or a key, the sheet warns you when the box is empty or short, but still lets you go ahead. When there is no password, the sheet says so: anyone who photographs the QR image has what is inside.

The QR image stays on screen for a minute; closing the sheet removes it sooner. The other device can read the code for three minutes if it was scanned, and for fifteen if it was pasted as text, since text is usually sent by email or message. Nothing is written to disk on either device. The time limit stops the code being used again later, but it does not help against a photo someone has already taken: a photo can be turned back into text and pasted. Against that, only the password protects you.

Copy as text is beside the QR image on every device. The QR image is for a device in front of you; the text is for one that is not, and it is the only way to get a code from a phone to a desktop. It is the same code, and the same password opens it.

Import… reads a code. Paste it or scan it, and before anything is saved the next screen shows what the code holds: one row per server, with its state, then the host keys, secrets and keys that came with them. Untick anything you do not want.

Each server row has a state:

A row can be both already here and without its key; the label shows the first and the note under it the second.

Host keys are imported only for hosts this device has no key for yet. A host you have already verified keeps its key, whatever the code says.

If a key in the code has the same name as a different key on this device, it is saved under a free name, and the servers that use it are pointed at the new name. The same key arriving twice is saved only once.

In the free edition, servers over the limit arrive unticked. A renamed server counts as new; overwriting an existing one does not.

Nothing is saved until you press Import, and Cancel discards the code.

The form

The form has three tabs: Server, Auth and Terminal. The label and the id sit above them, and Save, Test, Disconnect and Close below. On a phone this keeps what you are typing into on screen above the keyboard.

If Save finds a problem, it opens the tab with the problem, so pressing Save with no host from the Terminal tab takes you to Server. A tab shows a dot while it holds a message you have not seen.

The fields

Above the tabs:

On the Server tab:

On the Terminal tab:

Under Advanced on that tab: TERM, the keepalive in seconds, and the environment variables for the server, one NAME=value per line.

These settings are sent along when you export the server. How the terminal uses them is in the terminal.

How a server logs in

The Auth tab lists every key on this device, and three rows that are not keys:

Picking a key only shows it; the server switches to it when you test, install or choose to use it (see Keys, below). A key with a passphrase shows a passphrase box.

Each key in the list shows what kind it is:

A path must start with / or ~, or be the name of a key you imported. Relative paths such as keys/mine are refused.

On a phone, a server that came from a desktop with a key path shows that row greyed out, since a phone has no such file. The same goes for a server whose key is no longer on this device. You can still pick the row to see why, but Save and Test stay disabled, with the reason beside them, until you choose a login this device can use.

Moving a server to another key does not delete the old key: it stays in the list until you remove it with Remove key "name".

Unlike ssh, the app does not use IdentityFile from ~/.ssh/config (choose the key here instead), and does not support ssh-agent.

A server that takes only keys says so when you connect, instead of asking for a password it would refuse. Choose a key for it. A server that wants a key and then a password (OpenSSH's AuthenticationMethods publickey,password) offers only the key at first, so it reads the same way: with a key chosen, the password is asked for after the key is accepted.

Where passwords are kept

Never in servers.toml, the list of servers. The form tells you where before you type anything:

If you leave the box empty, you are asked when connecting. That box has two buttons: Connect uses the secret once, and Save and connect also keeps it. Pressing Enter is Connect, so it never saves anything. Save and connect is not offered where there is nowhere to keep a secret, or for a one-time code.

A secret that works is also held in memory until the app closes, so a connection that has to reconnect does not ask again. One used with Connect and not saved shows as held until the app closes in the form, not as stored.

Forget it appears beside a saved secret. It removes the secret from this device and closes the connection it opened, so it cannot keep working. The box then says it will ask when connecting, since a saved secret is never shown.

Keys

Picking a key in the list only shows it: its public key, and what you can do with it. The server keeps logging in as before. A newly generated key is shown the same way.

To make a key the login, use one of the buttons in the key's card:

While a key is not yet the working login, its card is outlined in amber and says how the server logs in instead. In the list, the row the server is saved with has a current tag, and a key you picked but have not saved has a chosen tag. A saved key that nothing has logged in with yet shows not installed.

You can save at any time. Saving keeps the key you chose, and also keeps the current password or passphrase until something has logged in with the new key.

Under Add a key…:

Beside the public key:

A key code can carry a key you imported; a configuration code never does. Exporting servers sends only keys this app made, while a key code is one key you chose to send. Neither can carry a key file on this machine. A key keeps its kind on the other device: a key this app made can be sent on again, and an imported one is still never included when exporting servers.

Test and Disconnect

Test at the bottom of the form logs in once with the settings as they are on the form, including unsaved edits, and says what happened. It saves nothing, so a working test still needs Save. It always makes a fresh connection, so the answer is about what is on screen now.

Disconnect appears when the server is connected. It closes the connection, and any terminal or file view using it stops; the next thing that needs the server logs in again. Terminals you left open stay listed, marked ended, and Reconnect in one starts a new shell. A connection also closes when its secret is replaced or forgotten, or when you change which key the server uses.

Host keys

The server's identity is checked as in any SSH client. A new host asks you once. A host whose key has changed is refused, and the message shows the old key.

New hosts are saved in the app's own file; the one ssh uses is never changed. On a desktop, ~/.ssh/known_hosts is also read, so a host you have used from the command line does not ask again. A phone has no ~/.ssh, so every host is new the first time. Hashed host names, the default on Debian and Ubuntu, are read too.

Two kinds of line are treated specially:

A host with two keys of the same type on file, which is normal after a server is re-keyed, is accepted with either one.

The file behind the list

The list is servers.toml, in the app's configuration folder beside known_hosts and the keys. It is TOML, starting with version = 1, with one [[server]] block per server. You can edit it by hand, or copy it to another computer, since it holds no secrets.

It includes the [server.terminal] table from the Terminal tab, which holds only the settings you changed. Anything the app does not recognise, such as a misspelt name or a newer setting, is kept when the editor saves.