-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathcrypt.nu
More file actions
103 lines (90 loc) · 2.83 KB
/
Copy pathcrypt.nu
File metadata and controls
103 lines (90 loc) · 2.83 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
# Cryptographic utilities and secure credential management with RAM-disk caching
def get-credential-cache-path [] {
let is_win = (sys host | get name | str lowercase) == "windows"
if $is_win {
$env.TEMP? | default "C:\\Temp" | path join "nu_creds_cache.json"
} else if ("/dev/shm" | path exists) {
$"/dev/shm/.nu_creds_cache_(sys host | get hostname).json"
} else {
$env.HOME | path join ".cache" "nu_creds_cache.json"
}
}
#crypt
export def nu-crypt [
file?
--encrypt(-e)
--decrypt(-d)
--output_file(-o):string #only for -d option
--no_ui(-n) #to ask for password in cli
] {
let input_file = if ($file | is-not-empty) { $file } else if ($in | is-not-empty) { $in } else { null }
if ($input_file | is-empty) {
error make { msg: "no file provided to nu-crypt" }
}
match [$encrypt,$decrypt] {
[true,false] => { gpg --pinentry-mode loopback --symmetric --armor --yes $input_file },
[false,true] => {
if ($output_file | is-empty) {
if $no_ui {
gpg --pinentry-mode loopback --decrypt --quiet $input_file
} else {
gpg --decrypt --quiet $input_file
}
} else {
if $no_ui {
gpg --pinentry-mode loopback --output $output_file --quiet --decrypt $input_file
} else {
gpg --output $output_file --quiet --decrypt $input_file
}
}
},
_ => { error make { msg: "flag combination not allowed in nu-crypt" } }
}
}
#open credentials with caching
export def open-credential [file?, --ui(-u), --no-cache] {
let input_file = if ($file | is-not-empty) { $file } else if ($in | is-not-empty) { $in } else { null }
let cache_path = (get-credential-cache-path)
if (not $no_cache) and ($cache_path | path exists) and ($input_file | is-not-empty) and ($input_file | path exists) {
let file_mtime = (ls -l $input_file | get 0.modified)
let cache_mtime = (ls -l $cache_path | get 0.modified)
if $cache_mtime >= $file_mtime {
let cached = try { open $cache_path } catch { null }
if ($cached | is-not-empty) {
return $cached
}
}
}
let decrypted = try {
if $ui {
nu-crypt -d $input_file | from json
} else {
nu-crypt -d $input_file -n | from json
}
} catch {
{}
}
if ($decrypted | is-not-empty) {
try {
$decrypted | to json | save -f $cache_path
chmod 600 $cache_path
} catch {}
}
return $decrypted
}
#save credentials
export def save-credential [content, field:string] {
if ($field | is-empty) or ($content | is-empty) {
error make { msg: "missing arguments in save-credential" }
}
let credentials_e = $env.MY_ENV_VARS.credentials | path join credentials.json.asc
let credentials = $env.MY_ENV_VARS.credentials | path join credentials.json
open-credential $credentials_e
| upsert $field $content
| save -f $credentials
nu-crypt -e $credentials
rm -f $credentials | ignore
# Invalidate cache
let cache_path = (get-credential-cache-path)
rm -f $cache_path | ignore
}