Make secret unlocker add pgp work on Linux (closes #88)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
CreatePGPUnlocker got the vault's long-term key from the keychain unlocker's helper, which on every platform but macOS is a stub that always fails. It now calls the vault's GetOrDeriveLongTermKey, as adding a passphrase unlocker does: from the mnemonic, checked against the vault, or else from the current unlocker. That method joins VaultInterface. The test GPG key gains an encryption subkey, and a new test adds a PGP unlocker with the long-term key from the mnemonic and from a passphrase unlocker, then reads a secret through it. Model: opus-5-5
This commit was merged in pull request #95.
This commit is contained in:
@@ -277,7 +277,7 @@ func CreatePGPUnlocker(
|
||||
// Step 2: Encrypt the long-term private key to the new keypair, and the
|
||||
// keypair's private key to the GPG key
|
||||
encryptedLtPrivKey, encryptedAgePrivKey, err := encryptPGPUnlockerKeys(
|
||||
fs, vault, ageIdentity, gpgKeyID)
|
||||
vault, ageIdentity, gpgKeyID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -316,14 +316,15 @@ func CreatePGPUnlocker(
|
||||
// to the new PGP unlocker's age keypair, and that keypair's private key
|
||||
// encrypted to the GPG key gpgKeyID.
|
||||
func encryptPGPUnlockerKeys(
|
||||
fs afero.Fs, vault VaultInterface,
|
||||
ageIdentity *age.X25519Identity, gpgKeyID string,
|
||||
vault VaultInterface, ageIdentity *age.X25519Identity, gpgKeyID string,
|
||||
) ([]byte, []byte, error) {
|
||||
// Get or derive the long-term private key
|
||||
ltPrivKeyData, err := getLongTermPrivateKey(fs, vault)
|
||||
// From the mnemonic or the current unlocker, as for a passphrase unlocker
|
||||
ltIdentity, err := vault.GetOrDeriveLongTermKey()
|
||||
if err != nil {
|
||||
return nil, nil, err
|
||||
return nil, nil, fmt.Errorf("failed to get long-term key: %w", err)
|
||||
}
|
||||
|
||||
ltPrivKeyData := memguard.NewBufferFromBytes([]byte(ltIdentity.String()))
|
||||
defer ltPrivKeyData.Destroy()
|
||||
|
||||
encryptedLtPrivKey, err := EncryptToRecipient(
|
||||
|
||||
Reference in New Issue
Block a user