Keep the mnemonic out of the ssh and sftp children (closes #16)
check / check (push) Failing after 0s
check / check (push) Failing after 0s
`keyfunc ssh to` and `keyfunc ssh install` started the system `ssh` and `sftp` with the tool's whole environment, so a mnemonic given in `KEYFUNC_MNEMONIC` stayed readable in the child's environment and could be forwarded to the host by a `SendEnv` line. Both children now get the environment with `KEYFUNC_MNEMONIC` and `KEYFUNC_MNEMONIC_COMMAND` removed, through one helper, `childEnv`, in the ssh cli package. The mnemonic command still runs with the full environment. Two tests drive the real commands against the stand-in `ssh` and `sftp` and check that a third variable still arrives. Model: opus-4-8 (implementation, review); fable-5-1 (merge message)
This commit was merged in pull request #29.
This commit is contained in:
@@ -3,9 +3,12 @@ package ssh
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"strings"
|
||||
|
||||
"git.eeqj.de/sneak/keyfunc/internal/cli/options"
|
||||
"git.eeqj.de/sneak/keyfunc/internal/derive"
|
||||
"git.eeqj.de/sneak/keyfunc/internal/mnemonic"
|
||||
"git.eeqj.de/sneak/keyfunc/internal/sshkey"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
@@ -84,6 +87,26 @@ func write(cmd *cobra.Command, text string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// childEnv is the tool's environment with the mnemonic variables taken
|
||||
// out, for the ssh and sftp children it starts. "ssh to" exists so the
|
||||
// private key never leaves the tool; the mnemonic, from either variable,
|
||||
// must not leave it either.
|
||||
func childEnv() []string {
|
||||
environ := os.Environ()
|
||||
kept := make([]string, 0, len(environ))
|
||||
|
||||
for _, entry := range environ {
|
||||
name, _, _ := strings.Cut(entry, "=")
|
||||
if name == mnemonic.Variable || name == mnemonic.CommandVariable {
|
||||
continue
|
||||
}
|
||||
|
||||
kept = append(kept, entry)
|
||||
}
|
||||
|
||||
return kept
|
||||
}
|
||||
|
||||
// addComment gives a command its comment flag.
|
||||
func addComment(cmd *cobra.Command) {
|
||||
cmd.Flags().String(
|
||||
|
||||
Reference in New Issue
Block a user