SFTP
Browse local and remote files side by side, transfer them, and edit remote files in the app or in your own editor with every save reviewed.
The SFTP view is a dual-pane file browser: this computer on one side, the server on the other, over the host’s existing SSH session. Every save to a remote file waits in a review sheet until you approve it.
Open the file browser
- On the host dashboard, click SFTP.
- Or choose SFTP in the left rail while a session is open.
The remote pane opens in the host’s SFTP start directory if you set one (host editor › Advanced), otherwise in the folder your login starts in, usually your home folder.
Browse
Each pane has a path box, a filter, sortable columns (name, size, modified), type badges and permissions. Click a pane to give it the keyboard.
| To | Do |
|---|---|
| Open a folder | Double-click it or press Enter |
| Go up a folder | Backspace |
| Show or hide dotfiles | ⇧⌘. (CtrlShift.) |
| Refresh | ⌘R (CtrlR) |
| Select everything | ⌘A (CtrlA) |
| Open a shell here | Right-click › Open in terminal (remote pane) |
The full list is in Keyboard shortcuts.
Transfer files
- Select files or folders in one pane.
- Upload or download:
- Right-click › Upload or Download, or
- ⌘↑ in the local pane uploads to the remote folder; ⌘↓ in the remote pane downloads to the local folder (Ctrl on Windows and Linux), or
- Drag them onto the other pane, or onto a folder in it, or
- Copy (⌘C) in one pane and paste (⌘V) in the other.
- Watch progress in the transfers dock.
You can also drop files from your desktop onto the remote pane, or right-click an empty part of it and choose Upload files… or Upload folder….
The preview of a file is capped at 2 MB. Download anything larger.
Manage files
Right-click a file or folder for:
- Rename… (F2), Duplicate (⌘D), Delete… (⌘⌫, or Del on Windows and Linux)
- Permissions… for owner, group and others, on one item or several
- Get info (⌘I), Copy path (⌥⌘C), Copy name
- New folder… (⇧⌘N) and New file… on the pane’s background
- Reveal in Finder or Show in folder for local files
Remote saves, renames, permission changes and deletes are written to the audit log with the host.
Edit a remote file
You can edit in the app or in any editor on your computer. Either way, nothing reaches the server until you approve it in the review sheet.
In the app
- Select a text file and press ⌘E (CtrlE), or right-click › Edit. Enter on a text file does the same.
- Make your changes. Tab inserts a tab character.
- Click Save for review or press ⌘S. This never writes the server; it opens the review sheet. Saving again replaces the version still waiting.
In a local editor
- Right-click a file › Edit with…, or press ⇧⌘E (CtrlShiftE).
- Pick an app from the list, Choose another application…, or Default app for whatever your system opens that file type with. Tick Always use this app for .conf files (or whichever extension) to skip this step next time; the menu then offers Edit in followed by that app’s name.
- Click Download & edit. A copy is downloaded and opened in that app.
- Edit and save as usual. Each save queues an upload that waits in the review sheet.
If the session drops before you approve, the unsent copy survives and waits for you.
The review sheet
Every remote save lands in one review sheet, whichever view is in front: a save from a local editor, from the in-app editor, or a change Farabi drafted.
The sheet shows the diff first. What it offers next depends on the file and on your login:
- An ordinary file your login can write: upload it.
- A config file Gatesys SSH knows, such as
sshd_config, nginx, sudoers or a systemd unit, with root or passwordlesssudo: the server’s own check on a staged copy, findings about your current login, a backup, and an optional safety net that puts the old file back unless you confirm. See Safe Change. - When checks cannot run, for example on an SFTP-only login: a plain upload, as before.
An upload sends exactly the bytes the sheet showed. A save made after you opened the review is reviewed first. If the file on the server changed since you started, the sheet says The file on the server changed and asks you to recheck.
The review sheet, the server’s check, backups and the safety net are part of every plan.
Open with sudo
When the server refuses to let your login read a config file, you can open it again with sudo. This is allowed only for files of a known kind, only into the in-app editor, and every read is audited. It is never allowed for secrets such as /etc/shadow, host keys, *.key or *.pem, and a symlink that points at a secret or at another kind of file is refused before anything is read.
Protected files on production hosts
On a production host, SFTP writes of sshd, sudoers, PAM and firewall files, and of the SSH service’s unit, are refused outside the review sheet: save, rename, delete, change permissions, copy and upload all say Use Edit — this file goes through review. So are delete, rename and permission changes on folders that hold them, such as /etc/ssh, /etc/pam.d or /etc.
Something unclear or wrong? Tell us.