diff options
| author | Samuel Wilhelmsson <samuel.wilhelmsson@gmail.com> | 2025-01-11 23:28:34 +0100 |
|---|---|---|
| committer | Samuel Wilhelmsson <samuel.wilhelmsson@gmail.com> | 2025-01-11 23:28:34 +0100 |
| commit | e4fc03baf716f879b44c6ce18781d3dc702354c3 (patch) | |
| tree | dfca77b65123e5b858b81ca3f82ffdac898ce70b /internal/secrets/secrets.go | |
| parent | 7d4b7e629bd5a095148dfe448209b9ec1ee4643f (diff) | |
| download | tinygram-e4fc03baf716f879b44c6ce18781d3dc702354c3.tar.gz tinygram-e4fc03baf716f879b44c6ce18781d3dc702354c3.zip | |
add age encrypted secrets in binary
Diffstat (limited to 'internal/secrets/secrets.go')
| -rw-r--r-- | internal/secrets/secrets.go | 49 |
1 files changed, 49 insertions, 0 deletions
diff --git a/internal/secrets/secrets.go b/internal/secrets/secrets.go new file mode 100644 index 0000000..684456f --- /dev/null +++ b/internal/secrets/secrets.go @@ -0,0 +1,49 @@ +package secrets + +import ( + "fmt" + "io" + "os" + "path" + "strings" + + "filippo.io/age" +) + +func DecryptSecret(secret string) (string, error) { + homepath, err := os.UserHomeDir() + if err != nil { + fmt.Println("could not get home dir") + os.Exit(1) + } + + sshFolder := path.Join(homepath, ".ssh") + entries, err := os.ReadDir(sshFolder) + + var identities []*age.X25519Identity + for _, file := range entries { + if !strings.HasSuffix(".pub", file.Name()) { + keybytes, err := os.ReadFile(path.Join(sshFolder, file.Name())) + identity, err := age.ParseX25519Identity(strings.TrimSpace(string(keybytes))) + if err != nil { + continue + } + identities = append(identities, identity) + } + } + + if len(identities) == 0 { + return "", fmt.Errorf("could not parse any identities") + } + + for _, id := range identities { + result, err := age.Decrypt(strings.NewReader(secret), id) + if err != nil { + continue + } + b, _ := io.ReadAll(result) + return string(b), nil + } + + return "", fmt.Errorf("could not find identity") +} |
