Add sanity check to prevent data loss in the event the user mistypes their passphrase during encryption

This commit is contained in:
2025-05-03 19:36:23 -04:00
parent e4ae5b4a9d
commit baad84563e
+28
View File
@@ -0,0 +1,28 @@
package wrappers
import (
"errors"
"os"
)
// GenSanityCheck creates an encrypted file containing known plaintext
// to later be used for ensuring the user does not encrypt data with
// an incorrect passphrase.
func GenSanityCheck(path string, passphrase []byte) {
os.WriteFile(path, Encrypt([]byte("thx4usin'rcw"), passphrase), 0600)
}
// RunSanityCheck should be run before any encryption operation
// to ensure the user does not encrypt data with an incorrect passphrase.
// Failure to perform this check could result in data loss.
func RunSanityCheck(path string, passphrase []byte) error {
encBytes, err := os.ReadFile(path)
if err != nil {
return errors.New("Failed to read sanity check file (" + path + ")")
}
decBytes, err := Decrypt(encBytes, passphrase)
if string(decBytes) == "thx4usin'rcw" {
return nil
}
return errors.New("Sanity check failed (likely due to inconsistent passphrase)")
}