2023-03-15 16:00:52 +00:00
|
|
|
// Copyright (c) HashiCorp, Inc.
|
|
|
|
// SPDX-License-Identifier: MPL-2.0
|
|
|
|
|
2015-12-14 21:23:04 +00:00
|
|
|
package token
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
|
|
|
"fmt"
|
|
|
|
"io"
|
|
|
|
"os"
|
2019-03-07 14:51:10 +00:00
|
|
|
"path/filepath"
|
2016-08-24 00:22:45 +00:00
|
|
|
"strings"
|
2015-12-14 21:23:04 +00:00
|
|
|
|
2019-01-09 00:48:57 +00:00
|
|
|
homedir "github.com/mitchellh/go-homedir"
|
2020-04-27 23:55:13 +00:00
|
|
|
"github.com/natefinch/atomic"
|
2015-12-14 21:23:04 +00:00
|
|
|
)
|
|
|
|
|
2017-09-05 03:50:45 +00:00
|
|
|
var _ TokenHelper = (*InternalTokenHelper)(nil)
|
|
|
|
|
2015-12-14 21:23:04 +00:00
|
|
|
// InternalTokenHelper fulfills the TokenHelper interface when no external
|
|
|
|
// token-helper is configured, and avoids shelling out
|
|
|
|
type InternalTokenHelper struct {
|
|
|
|
tokenPath string
|
2020-04-27 23:55:13 +00:00
|
|
|
homeDir string
|
2015-12-14 21:23:04 +00:00
|
|
|
}
|
|
|
|
|
2020-04-27 23:55:13 +00:00
|
|
|
func NewInternalTokenHelper() (*InternalTokenHelper, error) {
|
|
|
|
homeDir, err := homedir.Dir()
|
2015-12-14 21:23:04 +00:00
|
|
|
if err != nil {
|
2018-04-05 15:49:21 +00:00
|
|
|
panic(fmt.Sprintf("error getting user's home directory: %v", err))
|
2015-12-14 21:23:04 +00:00
|
|
|
}
|
2020-04-27 23:55:13 +00:00
|
|
|
return &InternalTokenHelper{homeDir: homeDir}, err
|
|
|
|
}
|
|
|
|
|
|
|
|
// populateTokenPath figures out the token path using homedir to get the user's
|
|
|
|
// home directory
|
|
|
|
func (i *InternalTokenHelper) populateTokenPath() {
|
|
|
|
i.tokenPath = filepath.Join(i.homeDir, ".vault-token")
|
2015-12-14 21:23:04 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (i *InternalTokenHelper) Path() string {
|
|
|
|
return i.tokenPath
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get gets the value of the stored token, if any
|
|
|
|
func (i *InternalTokenHelper) Get() (string, error) {
|
|
|
|
i.populateTokenPath()
|
|
|
|
f, err := os.Open(i.tokenPath)
|
|
|
|
if os.IsNotExist(err) {
|
|
|
|
return "", nil
|
|
|
|
}
|
|
|
|
if err != nil {
|
|
|
|
return "", err
|
|
|
|
}
|
|
|
|
defer f.Close()
|
|
|
|
|
|
|
|
buf := bytes.NewBuffer(nil)
|
|
|
|
if _, err := io.Copy(buf, f); err != nil {
|
|
|
|
return "", err
|
|
|
|
}
|
|
|
|
|
2016-08-24 00:22:45 +00:00
|
|
|
return strings.TrimSpace(buf.String()), nil
|
2015-12-14 21:23:04 +00:00
|
|
|
}
|
|
|
|
|
2020-04-27 23:55:13 +00:00
|
|
|
// Store stores the value of the token to the file. We always overwrite any
|
|
|
|
// existing file atomically to ensure that ownership and permissions are set
|
|
|
|
// appropriately.
|
2015-12-14 21:23:04 +00:00
|
|
|
func (i *InternalTokenHelper) Store(input string) error {
|
|
|
|
i.populateTokenPath()
|
2020-04-27 23:55:13 +00:00
|
|
|
tmpFile := i.tokenPath + ".tmp"
|
2021-04-08 16:43:39 +00:00
|
|
|
f, err := os.OpenFile(tmpFile, os.O_CREATE|os.O_TRUNC|os.O_WRONLY, 0o600)
|
2015-12-14 21:23:04 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer f.Close()
|
2020-04-27 23:55:13 +00:00
|
|
|
defer os.Remove(tmpFile)
|
2015-12-14 21:23:04 +00:00
|
|
|
|
2020-04-27 23:55:13 +00:00
|
|
|
_, err = io.WriteString(f, input)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
err = f.Close()
|
|
|
|
if err != nil {
|
2015-12-14 21:23:04 +00:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-04-27 23:55:13 +00:00
|
|
|
// We don't care so much about atomic writes here. We're using this package
|
|
|
|
// because we don't have a portable way of verifying that the target file
|
|
|
|
// is owned by the correct user. The simplest way of ensuring that is
|
|
|
|
// to simply re-write it, and the simplest way to ensure that we don't
|
|
|
|
// damage an existing working file due to error is the write-rename pattern.
|
|
|
|
// os.Rename on Windows will return an error if the target already exists.
|
|
|
|
return atomic.ReplaceFile(tmpFile, i.tokenPath)
|
2015-12-14 21:23:04 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Erase erases the value of the token
|
|
|
|
func (i *InternalTokenHelper) Erase() error {
|
|
|
|
i.populateTokenPath()
|
|
|
|
if err := os.Remove(i.tokenPath); err != nil && !os.IsNotExist(err) {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|