check / check (push) Waiting to run
init and vault create put the mnemonic into the process environment for vault.CreateVault to read back, so every program they ran, gpg included, inherited it, and SB_SECRET_MNEMONIC and SB_UNLOCK_PASSPHRASE were read at 13 places and never unset. Each command that may need them now reads both once, in its RunE, into locked buffers on the CLI Instance, and unsets them at once. The buffers are passed down: vault.CreateVault takes the mnemonic, a Vault carries Mnemonic and UnlockPassphrase, and the PGP, keychain and Secure Enclave unlocker constructors take both; CreatePGPUnlocker sets them on the vault it loads through SetMnemonic and SetUnlockPassphrase, new in VaultInterface. README warns against both variables. Model: opus-5-5
88 lines
2.1 KiB
Go
88 lines
2.1 KiB
Go
//go:build !darwin
|
|
|
|
package secret
|
|
|
|
import (
|
|
"errors"
|
|
|
|
"filippo.io/age"
|
|
"github.com/awnumar/memguard"
|
|
"github.com/spf13/afero"
|
|
)
|
|
|
|
// seUnlockerType is the type string for Secure Enclave unlockers.
|
|
const seUnlockerType = "secure-enclave"
|
|
|
|
var errSENotSupported = errors.New(
|
|
"secure enclave unlockers are only supported on macOS",
|
|
)
|
|
|
|
// SecureEnclaveUnlockerMetadata is a stub for non-Darwin platforms.
|
|
type SecureEnclaveUnlockerMetadata struct {
|
|
UnlockerMetadata
|
|
|
|
SEKeyLabel string `json:"seKeyLabel"`
|
|
SEKeyHash string `json:"seKeyHash"`
|
|
}
|
|
|
|
// SecureEnclaveUnlocker is a stub for non-Darwin platforms.
|
|
type SecureEnclaveUnlocker struct {
|
|
Directory string
|
|
Metadata UnlockerMetadata
|
|
fs afero.Fs
|
|
}
|
|
|
|
// NewSecureEnclaveUnlocker creates a stub SecureEnclaveUnlocker on
|
|
// non-Darwin platforms. The returned instance's methods that require
|
|
// macOS functionality will return errors.
|
|
func NewSecureEnclaveUnlocker(
|
|
fs afero.Fs,
|
|
directory string,
|
|
metadata UnlockerMetadata,
|
|
) *SecureEnclaveUnlocker {
|
|
return &SecureEnclaveUnlocker{
|
|
Directory: directory,
|
|
Metadata: metadata,
|
|
fs: fs,
|
|
}
|
|
}
|
|
|
|
// GetIdentity returns an error on non-Darwin platforms.
|
|
func (s *SecureEnclaveUnlocker) GetIdentity() (*age.X25519Identity, error) {
|
|
return nil, errSENotSupported
|
|
}
|
|
|
|
// GetType returns the unlocker type.
|
|
func (s *SecureEnclaveUnlocker) GetType() string {
|
|
return seUnlockerType
|
|
}
|
|
|
|
// GetMetadata returns the unlocker metadata.
|
|
func (s *SecureEnclaveUnlocker) GetMetadata() UnlockerMetadata {
|
|
return s.Metadata
|
|
}
|
|
|
|
// GetDirectory returns the unlocker directory.
|
|
func (s *SecureEnclaveUnlocker) GetDirectory() string {
|
|
return s.Directory
|
|
}
|
|
|
|
// GetID returns the unlocker ID.
|
|
func (s *SecureEnclaveUnlocker) GetID() string {
|
|
return s.Metadata.CreatedAt.Format("2006-01-02.15.04") + "-" + seUnlockerType
|
|
}
|
|
|
|
// Remove returns an error on non-Darwin platforms.
|
|
func (s *SecureEnclaveUnlocker) Remove() error {
|
|
return errSENotSupported
|
|
}
|
|
|
|
// CreateSecureEnclaveUnlocker returns an error on non-Darwin platforms.
|
|
func CreateSecureEnclaveUnlocker(
|
|
_ afero.Fs,
|
|
_ string,
|
|
_, _ *memguard.LockedBuffer,
|
|
) (*SecureEnclaveUnlocker, error) {
|
|
return nil, errSENotSupported
|
|
}
|