PAM lines written into login and passwd as blocks, so login unlocks the keyring on both workstations; no daemon of its own; gcr's ssh agent named for the session until the environment can say a runtime-directory path. Go tools unlocked, lock, collections and ssh-keys, never reading a secret.
58 lines
2.0 KiB
Go
58 lines
2.0 KiB
Go
// gnome-keyring's Go tools bundle (novox/hq ADR 0188, ADR 0193, ADR 0208): the secret service's
|
|
// tools, served by the node's runtime as the operator account. node-secret-service has no verbs yet
|
|
// (ADR 0208 §2), so every tool here is the module's own. None of them ever reads a secret: they ask the
|
|
// Secret Service for names, counts and lock states, and the ssh agent for fingerprints.
|
|
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
|
|
stdio "git.novox.be/novox/mesh-sdk/go"
|
|
)
|
|
|
|
func main() {
|
|
if err := stdio.Serve("", tools()); err != nil {
|
|
fmt.Fprintln(os.Stderr, err)
|
|
os.Exit(1)
|
|
}
|
|
}
|
|
|
|
func tools() []stdio.Tool {
|
|
return []stdio.Tool{
|
|
{
|
|
Name: "gnome_keyring_unlocked",
|
|
Description: "Is the operator's keyring unlocked: the login keyring and the default one, each locked " +
|
|
"or not, and whether the keyring daemon runs.",
|
|
Run: func(map[string]any) (any, error) { return Unlocked() },
|
|
},
|
|
{
|
|
Name: "gnome_keyring_lock",
|
|
Description: "Lock a keyring now (the login keyring unless another is named): programs must ask " +
|
|
"for its password again. Unlocking is the operator's, at their desktop.",
|
|
Input: map[string]any{
|
|
"collection": map[string]any{"type": "string", "description": "the keyring's id, as gnome_keyring_collections answers it (default login)"},
|
|
},
|
|
Run: func(args map[string]any) (any, error) {
|
|
c, err := text(args, "collection", false)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return Lock(c)
|
|
},
|
|
},
|
|
{
|
|
Name: "gnome_keyring_collections",
|
|
Description: "The operator's keyrings: each one's id, label, whether it is locked, how many items it " +
|
|
"holds, when it was created and changed, and which is the default. Never an item, never a secret.",
|
|
Run: func(map[string]any) (any, error) { return Collections() },
|
|
},
|
|
{
|
|
Name: "gnome_keyring_ssh_keys",
|
|
Description: "The keys the session's ssh agent (gcr's) holds, by fingerprint, size, type and comment. " +
|
|
"Never a key.",
|
|
Run: func(map[string]any) (any, error) { return SSHKeys() },
|
|
},
|
|
}
|
|
}
|