check / check (push) Failing after 1s
A passphrase unlocker added to a vault that had one, and a PGP, keychain or Secure Enclave unlocker added on the same day as another of its type, were written into the existing unlocker's directory file by file, so a crash part-way left a current unlocker whose files did not belong together. Unlocker directories, keychain items and Secure Enclave keys are now named with the time to the nanosecond, and secret.WriteDir refuses a directory that exists. Adding a passphrase unlocker writes the new one, points current-unlocker at it, and only then removes the vault's other passphrase unlockers. Model: opus-5-5
35 lines
1.3 KiB
Go
35 lines
1.3 KiB
Go
// Package secret provides core types and constants for the secret application.
|
|
package secret
|
|
|
|
import "os"
|
|
|
|
const (
|
|
// AppID is the unique identifier for this application
|
|
AppID = "berlin.sneak.pkg.secret"
|
|
|
|
// EnvStateDir is the environment variable for specifying the state directory
|
|
EnvStateDir = "SB_SECRET_STATE_DIR"
|
|
// EnvMnemonic is the environment variable for providing the mnemonic phrase
|
|
EnvMnemonic = "SB_SECRET_MNEMONIC"
|
|
// EnvUnlockPassphrase is the environment variable for providing the unlock passphrase
|
|
//nolint:gosec // G101: env var name, not a credential
|
|
EnvUnlockPassphrase = "SB_UNLOCK_PASSPHRASE"
|
|
// EnvGPGKeyID is the environment variable for providing the GPG key ID
|
|
EnvGPGKeyID = "SB_GPG_KEY_ID"
|
|
|
|
// UnlockerTimeFormat is the layout of the time, in UTC, in the name of a
|
|
// new unlocker's directory, keychain item and Secure Enclave key. It runs
|
|
// to the nanosecond, so that every new unlocker, even one added right
|
|
// after another, gets a directory of its own.
|
|
UnlockerTimeFormat = "2006-01-02.15.04.05.000000000"
|
|
)
|
|
|
|
// File system permission constants
|
|
const (
|
|
// DirPerms is the permission used for directories (read-write-execute for owner only)
|
|
DirPerms os.FileMode = 0o700
|
|
|
|
// FilePerms is the permission used for sensitive files (read-write for owner only)
|
|
FilePerms os.FileMode = 0o600
|
|
)
|