mirror of
https://github.com/rwinkhart/go-boilerplate.git
synced 2026-08-28 04:46:41 -04:00
Harden functions that potentially deal with sensitive information
This commit is contained in:
+10
-7
@@ -6,10 +6,12 @@ import (
|
|||||||
"io"
|
"io"
|
||||||
"os"
|
"os"
|
||||||
"os/exec"
|
"os/exec"
|
||||||
|
|
||||||
|
"github.com/rwinkhart/go-boilerplate/security"
|
||||||
)
|
)
|
||||||
|
|
||||||
// WriteToStdin is a utility function that writes a string to a command's stdin.
|
// WriteToStdin is a utility function that writes a byte slice to a command's stdin.
|
||||||
func WriteToStdin(cmd *exec.Cmd, input string) error {
|
func WriteToStdinAndZeroizeInput(cmd *exec.Cmd, input []byte) error {
|
||||||
stdin, err := cmd.StdinPipe()
|
stdin, err := cmd.StdinPipe()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return errors.New("unable to access stdin for system command: " + err.Error())
|
return errors.New("unable to access stdin for system command: " + err.Error())
|
||||||
@@ -18,16 +20,17 @@ func WriteToStdin(cmd *exec.Cmd, input string) error {
|
|||||||
defer func(stdin io.WriteCloser) {
|
defer func(stdin io.WriteCloser) {
|
||||||
_ = stdin.Close() // error ignored; if stdin could be accessed, it can probably be closed
|
_ = stdin.Close() // error ignored; if stdin could be accessed, it can probably be closed
|
||||||
}(stdin)
|
}(stdin)
|
||||||
_, _ = io.WriteString(stdin, input)
|
_, _ = stdin.Write(input)
|
||||||
|
security.ZeroizeBytes(input)
|
||||||
}()
|
}()
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// ReadFromStdin is a utility function that reads a string from stdin.
|
// ReadFromStdin is a utility function that reads a byte slice from stdin.
|
||||||
func ReadFromStdin() string {
|
func ReadFromStdin() []byte {
|
||||||
scanner := bufio.NewScanner(os.Stdin)
|
scanner := bufio.NewScanner(os.Stdin)
|
||||||
if scanner.Scan() {
|
if scanner.Scan() {
|
||||||
return scanner.Text()
|
return scanner.Bytes()
|
||||||
}
|
}
|
||||||
return ""
|
return nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
package back
|
|
||||||
|
|
||||||
// EraseBytesSecurely overwrites all
|
|
||||||
// bytes in a slice with zeros.
|
|
||||||
func EraseBytesSecurely(input []byte) {
|
|
||||||
for i := range input {
|
|
||||||
input[i] = 0
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
module github.com/rwinkhart/go-boilerplate
|
module github.com/rwinkhart/go-boilerplate
|
||||||
|
|
||||||
go 1.25.6
|
go 1.25.7
|
||||||
|
|
||||||
require golang.org/x/term v0.39.0
|
require golang.org/x/term v0.40.0
|
||||||
|
|
||||||
require golang.org/x/sys v0.40.0 // indirect
|
require golang.org/x/sys v0.41.0 // indirect
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
golang.org/x/sys v0.40.0 h1:DBZZqJ2Rkml6QMQsZywtnjnnGvHza6BTfYFWY9kjEWQ=
|
golang.org/x/sys v0.41.0 h1:Ivj+2Cp/ylzLiEU89QhWblYnOE9zerudt9Ftecq2C6k=
|
||||||
golang.org/x/sys v0.40.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
|
golang.org/x/sys v0.41.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
|
||||||
golang.org/x/term v0.39.0 h1:RclSuaJf32jOqZz74CkPA9qFuVTX7vhLlpfj/IGWlqY=
|
golang.org/x/term v0.40.0 h1:36e4zGLqU4yhjlmxEaagx2KuYbJq3EwY8K943ZsHcvg=
|
||||||
golang.org/x/term v0.39.0/go.mod h1:yxzUCTP/U+FzoxfdKmLaA0RV1WgE0VY7hXBwKtY/4ww=
|
golang.org/x/term v0.40.0/go.mod h1:w2P8uVp06p2iyKKuvXIm7N/y0UCRt3UfJTfZ7oOpglM=
|
||||||
|
|||||||
@@ -1,20 +1,20 @@
|
|||||||
package stringy
|
package security
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bytes"
|
||||||
"crypto/rand"
|
"crypto/rand"
|
||||||
"fmt"
|
"fmt"
|
||||||
"math"
|
"math"
|
||||||
"math/big"
|
"math/big"
|
||||||
"strings"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// StringGen generates a random string of a specified length and complexity.
|
// BytesGen generates a random byte slice of a specified length and complexity.
|
||||||
// Requires: complexity (minimum percentage of special characters to be returned in the generated string; set to 0 to generate a simple string),
|
// Requires: complexity (minimum percentage of special characters to be returned in the generated output; set to 0 for a "simple" result),
|
||||||
// complexCharsetLevel (1 = safe for filenames, 2 = safe for most password entries, 3 = safe only for well-made password entries)
|
// complexCharsetLevel (1 = safe for filenames, 2 = safe for most password entries, 3 = safe only for well-made password entries)
|
||||||
func StringGen(length int, complexity float64, complexCharsetLevel uint8) string {
|
func BytesGen(length int, complexity float64, complexCharsetLevel uint8) []byte {
|
||||||
var actualSpecialChars int // track the number of special characters in the generated string
|
var actualSpecialChars int // track the number of special characters in the generated output
|
||||||
var minSpecialChars int // track the minimum number of special characters to accept
|
var minSpecialChars int // track the minimum number of special characters to accept
|
||||||
var extendedCharset string // additions to character set used for complex strings
|
var extendedCharset string // additions to character set used for complex outputs
|
||||||
|
|
||||||
charset := "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789" // default character set used for all strings
|
charset := "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789" // default character set used for all strings
|
||||||
const extendedCharsetFiles = "!#$%&+,-.;=@_~^()[]{}`'" // additional special characters for complex strings (safe in file names)
|
const extendedCharsetFiles = "!#$%&+,-.;=@_~^()[]{}`'" // additional special characters for complex strings (safe in file names)
|
||||||
@@ -34,34 +34,34 @@ func StringGen(length int, complexity float64, complexCharsetLevel uint8) string
|
|||||||
charset += extendedCharset
|
charset += extendedCharset
|
||||||
}
|
}
|
||||||
|
|
||||||
// loop until a string of the desired complexity is generated
|
// loop until a byte slice of the desired complexity is generated
|
||||||
for {
|
for {
|
||||||
// generate a random string
|
// generate a random output
|
||||||
result := make([]byte, length)
|
result := make([]byte, length)
|
||||||
for i := range result {
|
for i := range result {
|
||||||
val, _ := rand.Int(rand.Reader, big.NewInt(int64(len(charset))))
|
val, _ := rand.Int(rand.Reader, big.NewInt(int64(len(charset))))
|
||||||
result[i] = charset[val.Int64()]
|
result[i] = charset[val.Int64()]
|
||||||
}
|
}
|
||||||
|
|
||||||
// return early if the string is not complex
|
// return early if the desired output is not complex
|
||||||
if complexity <= 0 {
|
if complexity <= 0 {
|
||||||
return string(result)
|
return result
|
||||||
}
|
}
|
||||||
|
|
||||||
// count the number of special characters in the generated string
|
// count the number of special characters in the generated output
|
||||||
for _, char := range string(result) {
|
for i := range result {
|
||||||
if strings.ContainsRune(extendedCharset, char) {
|
if bytes.Contains([]byte(extendedCharset), []byte{result[i]}) {
|
||||||
actualSpecialChars++
|
actualSpecialChars++
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// return the generated string if it contains enough special characters
|
// return the generated output if it contains enough special characters
|
||||||
if actualSpecialChars >= minSpecialChars {
|
if actualSpecialChars >= minSpecialChars {
|
||||||
return string(result)
|
return result
|
||||||
}
|
}
|
||||||
|
|
||||||
// reset special character counter
|
// reset special character counter
|
||||||
fmt.Println("Regenerating string until desired complexity is achieved...")
|
fmt.Println("Regenerating output until desired complexity is achieved...")
|
||||||
actualSpecialChars = 0
|
actualSpecialChars = 0
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
package security
|
||||||
|
|
||||||
|
// ZeroizeBytes overwrites all
|
||||||
|
// bytes in a slice with zeros.
|
||||||
|
func ZeroizeBytes(input []byte) {
|
||||||
|
for i := range input {
|
||||||
|
input[i] = 0
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user