qbittorrent: the init writes the WebUI login in python, not awk
The keys carry backslashes (WebUI\Username); awk -v escape-processes them, so the edit matched nothing and the vault's credential never reached the software. Python edits the file literally and also sets BanDuration=60.
This commit is contained in:
@@ -83,7 +83,7 @@
|
||||
"type": "file",
|
||||
"path": "${dir:mesh-init}/10-mesh-webui-login.sh",
|
||||
"mode": "0755",
|
||||
"content": "#!/bin/bash\n# Written by the mesh (ADR 0158): this module's one credential is the vault's, shared with every\n# consumer; the file is applied here, before the service starts, on every start.\nset -euo pipefail\nCONF=/config/qBittorrent/qBittorrent.conf\nUSER='${setting:username}'\nPASS=$(cat /run/secrets/password)\nmkdir -p /config/qBittorrent\nHASH=$(python3 - \"$PASS\" <<'PY'\nimport sys, os, base64, hashlib\npw = sys.argv[1].encode(); salt = os.urandom(16)\ndk = hashlib.pbkdf2_hmac(\"sha512\", pw, salt, 100000, dklen=64)\nprint(\"@ByteArray(\" + base64.b64encode(salt).decode() + \":\" + base64.b64encode(dk).decode() + \")\")\nPY\n)\ntouch \"$CONF\"\ngrep -q '^\\[Preferences\\]' \"$CONF\" || printf '\\n[Preferences]\\n' >> \"$CONF\"\nfor kv in \"WebUI\\\\Username=$USER\" \"WebUI\\\\Password_PBKDF2=\\\"$HASH\\\"\" \"WebUI\\\\BanDuration=60\"; do\n key=${kv%%=*}\n if grep -q \"^${key//\\\\/\\\\\\\\}=\" \"$CONF\"; then\n awk -v kv=\"$kv\" -v key=\"$key\" 'BEGIN{FS=OFS=\"=\"} $1==key {print kv; next} {print}' \"$CONF\" > \"$CONF.mesh\" && mv \"$CONF.mesh\" \"$CONF\"\n else\n awk -v kv=\"$kv\" '{print} /^\\[Preferences\\]/ && !done {print kv; done=1}' \"$CONF\" > \"$CONF.mesh\" && mv \"$CONF.mesh\" \"$CONF\"\n fi\ndone\necho \"[mesh] qBittorrent WebUI login set for $USER from the vault's credential\"\n"
|
||||
"content": "#!/bin/bash\n# Written by the mesh (ADR 0158): this module's one credential is the vault's, shared with every\n# consumer; the WebUI login is written into qBittorrent.conf here, before the service starts, on\n# every start. Keys carry backslashes, so the edit is python's, not awk's.\nset -euo pipefail\nmkdir -p /config/qBittorrent\nUSERNAME='${setting:username}' python3 - <<'PY'\nimport os, re, base64, hashlib\nconf = \"/config/qBittorrent/qBittorrent.conf\"\npw = open(\"/run/secrets/password\", \"rb\").read().strip()\nsalt = os.urandom(16)\ndk = hashlib.pbkdf2_hmac(\"sha512\", pw, salt, 100000, dklen=64)\nhash_ = \"@ByteArray(\" + base64.b64encode(salt).decode() + \":\" + base64.b64encode(dk).decode() + \")\"\nwant = {\n \"WebUI\\\\Username\": os.environ[\"USERNAME\"],\n \"WebUI\\\\Password_PBKDF2\": '\"' + hash_ + '\"',\n \"WebUI\\\\BanDuration\": \"60\",\n}\ntext = open(conf).read() if os.path.exists(conf) else \"\"\nlines = text.splitlines()\nif \"[Preferences]\" not in lines:\n lines += [\"\", \"[Preferences]\"]\nout, seen = [], set()\nfor line in lines:\n key = line.split(\"=\", 1)[0] if \"=\" in line else None\n if key in want:\n out.append(key + \"=\" + want[key]); seen.add(key)\n else:\n out.append(line)\nmissing = [k for k in want if k not in seen]\nif missing:\n at = out.index(\"[Preferences]\") + 1\n out[at:at] = [k + \"=\" + want[k] for k in missing]\nopen(conf, \"w\").write(\"\\n\".join(out) + \"\\n\")\nprint(\"[mesh] qBittorrent WebUI login set for \" + os.environ[\"USERNAME\"] + \" from the vault's credential; ban duration 60s\")\nPY\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
|
||||
Reference in New Issue
Block a user