diff --git a/wrappers/sanityCheck.go b/wrappers/sanityCheck.go new file mode 100644 index 0000000..82eadb5 --- /dev/null +++ b/wrappers/sanityCheck.go @@ -0,0 +1,28 @@ +package wrappers + +import ( + "errors" + "os" +) + +// GenSanityCheck creates an encrypted file containing known plaintext +// to later be used for ensuring the user does not encrypt data with +// an incorrect passphrase. +func GenSanityCheck(path string, passphrase []byte) { + os.WriteFile(path, Encrypt([]byte("thx4usin'rcw"), passphrase), 0600) +} + +// RunSanityCheck should be run before any encryption operation +// to ensure the user does not encrypt data with an incorrect passphrase. +// Failure to perform this check could result in data loss. +func RunSanityCheck(path string, passphrase []byte) error { + encBytes, err := os.ReadFile(path) + if err != nil { + return errors.New("Failed to read sanity check file (" + path + ")") + } + decBytes, err := Decrypt(encBytes, passphrase) + if string(decBytes) == "thx4usin'rcw" { + return nil + } + return errors.New("Sanity check failed (likely due to inconsistent passphrase)") +}