Delete sshyp-mfa directory

This commit is contained in:
Randall Winkhart
2023-06-27 14:52:35 -04:00
committed by GitHub
parent 19ff50a5db
commit 0bbcda37f2
6 changed files with 0 additions and 463 deletions
-44
View File
@@ -1,44 +0,0 @@
.TH sshyp-mfa 1 "04 March 2023" "v1.4.0.1" "sshyp-mfa man page"
.SH NAME
sshyp-mfa \- An MFA (TOTP/Steam) key generator for the sshyp password manager.
.SH SYNOPSIS
Extension Usage: sshyp </entry name> copy -m
Direct Usage: sshyp-mfa </entry name>
.SH DESCRIPTION
sshyp-mfa is an extension for the sshyp password manager that reads MFA data from sshyp entries and generates generic TOTP and Steam keys.
.SH EXAMPLES
Generating and copying an MFA key for an existing entry saved as ~/.local/share/sshyp-mfa/development/github.gpg
sshyp /development/github copy -m
sshyp-mfa /development/github
.SH SETUP
sshyp-mfa requires a pre-existing functional sshyp setup.
MFA keys are generated off of MFA data placed in the second line of a sshyp entry's notes field. This data needs to be added manually, through sshyp, and must be in Authenticator backup format.
It might be easiest to import all of your MFA keys into Authenticator, export them into plain text, then add all of the exported MFA data into the second notes line in their respective sshyp entries.
.SH FORMAT
Format: otpauth://<OTP METHOD>/<ACCOUNT NAME, NOT USED>?secret=<SECRET>&issuer=<ISSUER, NOT USED>&algorithm=<ALGORITHM>&digits=<DIGITS>&period=<REFRESH PERIOD>
Help! What do I put in each of those spaces?
<OTP METHOD> is almost always 'totp', but in the case of Steam, it needs to be set to 'steam'.
<ACCOUNT NAME, NOT USED> is a part of the Authenticator backup format, but it is not used in sshyp-mfa. Set to anything.
<SECRET> refers to the secret used to generate your MFA key. This is usually directly provided by the issuer, but it is sometimes hidden and more easily retrieved by copying it from a QR-compatible MFA app (such as Aegis).
<ISSUER, NOT USED> is a part of the Authenticator backup format, but it is not used in sshyp-mfa. Set to anything.
<ALGORITHM> refers to the algorithm used to generate your MFA key based on your secret. This is almost always 'sha1'.
<DIGITS> refers to the intended length of your MFA key. This is almost always '6', but in the case of Steam, it needs to be set to '5'.
<REFRESH PERIOD> refers to the interval at which a new MFA key needs to be generated. This is almost always '30', for 30 seconds.
Example configuration (for most services, see above for differences regarding Steam):
otpauth://totp/MyNameIsBob?secret=YUGBSG65SG9SDBSDF56SBFVSC86SBVD6&issuer=Github&algorithm=sha1&digits=6&period=30
.SH AUTHOR
Randall Winkhart (https://github.com/rwinkhart)
-3
View File
@@ -1,3 +0,0 @@
[config]
input = copy -m
output = sshyp-mfa
-90
View File
@@ -1,90 +0,0 @@
#!/usr/bin/env python3
from base64 import b32decode
from configparser import ConfigParser
from os import environ, listdir, uname
from os.path import expanduser, isdir, isfile
from sshyp import decrypt, whitelist_verify
from subprocess import PIPE, Popen, run
from sys import argv, exit as s_exit
from time import sleep, strftime, time
home = expanduser("~")
def totp(_secret, _algo, _digits, _period): # uses provided information to generate a standard totp key
from hmac import new as new_mac
from struct import pack, unpack
_secret = b32decode(_secret.upper() + '=' * ((8 - len(_secret)) % 8))
_counter = pack('>Q', int(time() / _period))
_mac = new_mac(_secret, _counter, _algo).digest()
_offset = _mac[-1] & 0x0f
_binary = unpack('>L', _mac[_offset:_offset + 4])[0] & 0x7fffffff
return str(_binary)[-_digits:].zfill(_digits)
def mfa_read_shortcut(): # extracts MFA info from the user-specified sshyp entry
if not isfile(f"{directory}{arguments[0]}.gpg"):
print(f"\n\u001b[38;5;9merror: entry ({arguments[0]}) does not exist\u001b[0m\n")
s_exit(1)
if quick_unlock_enabled == 'true':
_mfa_data = decrypt(directory + arguments[0], _quick_pass=whitelist_verify(port, username_ssh, ip, device_id))
else:
_mfa_data = decrypt(directory + arguments[0])
try:
_type = _mfa_data[4].split('otpauth://')[1].split('/')[0]
_secret = _mfa_data[4].split('?secret=')[1].split('&issuer=')[0]
_algo = _mfa_data[4].split('&algorithm=')[1].split('&digits=')[0]
_digits = int(_mfa_data[4].split('&digits=')[1].split('&period=')[0])
_period = int(_mfa_data[4].split('&period=')[1])
return _type, _secret, _algo, _digits, _period
except IndexError:
print(f"\n\u001b[38;5;9merror: entry ({arguments[0]}) does not contain valid mfa data\u001b[0m\n")
s_exit(1)
if __name__ == '__main__':
# argument fetcher
arguments = argv[1:]
if len(arguments) < 1 or not arguments[0].startswith('/'):
print("\nsshyp-mfa extension usage: sshyp </entry name> copy -m\n\nrun 'man sshyp-mfa' for more information\n")
s_exit(1)
# user data fetcher
sshyp_data = ConfigParser()
sshyp_data.read(f"{home}/.config/sshyp/sshyp.ini")
quick_unlock_enabled = sshyp_data.get('CLIENT-ONLINE', 'quick_unlock_enabled')
username_ssh = sshyp_data.get('SSHYNC', 'user')
ip = sshyp_data.get('SSHYNC', 'ip')
port = sshyp_data.get('SSHYNC', 'port')
directory = sshyp_data.get('SSHYNC', 'local_dir')
device_id = listdir(f"{home}/.config/sshyp/devices")[0]
# main process: runs functions to generate MFA key, then continuously copies up-to-date MFA key to clipboard
try:
mfa_data, copied = mfa_read_shortcut(), None
print('\nmfa key copied to clipboard\n\nuntil this process is closed, your clipboard will be automatically '
'updated with the newest mfa key')
while True:
if str(int(strftime('%S'))/mfa_data[4]).endswith('.0') or copied is None:
if copied is None:
copied = 1
if mfa_data[0] == 'steam':
from steam.guard import generate_twofactor_code as steam_totp
_mfa_key = steam_totp(b32decode(mfa_data[1]))
else:
_mfa_key = totp(mfa_data[1], mfa_data[2], mfa_data[3], mfa_data[4])
if 'WSL_DISTRO_NAME' in environ: # WSL clipboard detection
run(('powershell.exe', '-c', 'Set-Clipboard', _mfa_key))
elif 'WAYLAND_DISPLAY' in environ: # Wayland clipboard detection
run(('wl-copy', _mfa_key))
elif uname()[0] == 'Haiku': # Haiku clipboard detection
run(('clipboard', '-c', _mfa_key))
elif uname()[0] == 'Darwin': # MacOS clipboard detection
run('pbcopy', stdin=Popen(('printf', _mfa_key), stdout=PIPE).stdout)
elif isdir("/data/data/com.termux"): # Termux (Android) clipboard detection
run(('termux-clipboard-set', _mfa_key))
else: # X11 clipboard detection
run(('xclip', '-sel', 'c'), stdin=Popen(('printf', _mfa_key), stdout=PIPE).stdout)
sleep(1)
except KeyboardInterrupt:
print('\n')
s_exit(0)
-311
View File
@@ -1,311 +0,0 @@
#!/bin/sh
version=$(sed -n '1{p;q}' ../version)
if [ -z "$2" ]; then
revision=1
else
revision="$2"
fi
_create_generic() {
printf '\npackaging as generic...\n'
mkdir -p output/generictemp/usr/bin \
output/generictemp/usr/lib/sshyp \
output/generictemp/usr/share/man/man1
cp -r lib/. output/generictemp/usr/lib/sshyp/
ln -s /usr/lib/sshyp/sshyp-mfa.py output/generictemp/usr/bin/sshyp-mfa
cp -r share output/generictemp/usr/
cp extra/manpage output/generictemp/usr/share/man/man1/sshyp-mfa.1
gzip output/generictemp/usr/share/man/man1/sshyp-mfa.1
XZ_OPT=-e6 tar -C output/generictemp -cvJf output/GENERIC-sshyp-mfa-"$version".tar.xz usr/
rm -rf output/generictemp
sha512="$(sha512sum output/GENERIC-sshyp-mfa-"$version".tar.xz | awk '{print $1;}')"
printf '\ngeneric packaging complete\n\n'
} &&
_create_pkgbuild() {
printf '\ngenerating PKGBUILD...\n'
if [ "$1" = 'Deb' ]; then
local source='https://github.com/rwinkhart/sshyp-labs/releases/download/v"$pkgver"/UBUNTU-sshyp-mfa_"$pkgver"-"$pkgrel"_all.deb'
local decomp_target='data.tar.xz'
else
local source='https://github.com/rwinkhart/sshyp-labs/releases/download/v"$pkgver"/GENERIC-sshyp-mfa-"$pkgver".tar.xz'
local decomp_target='GENERIC-sshyp-"$pkgver".tar.xz'
fi
printf "# Maintainer: Randall Winkhart <idgr at tutanota dot com>
pkgname=sshyp-mfa
pkgver="$version"
pkgrel="$revision"
pkgdesc='An MFA (TOTP/Steam) key generator for the sshyp password manager'
url='https://github.com/rwinkhart/sshyp-labs'
arch=('any')
license=('GPL-3.0-only')
depends=(sshyp)
source=(\""$source"\")
sha512sums=('"$sha512"')
package() {
tar -xf $decomp_target -C "\"\${pkgdir}\""
}
" > output/PKGBUILD
printf '\nPKGBUILD generated\n\n'
} &&
_create_apkbuild() {
printf '\ngenerating APKBUILD...\n'
if [ "$1" = 'Deb' ]; then
local source="https://github.com/rwinkhart/sshyp-labs/releases/download/v\"\$pkgver\"/UBUNTU-sshyp-mfa_\"\$pkgver\"-"$revision"_all.deb"
local sumsname="UBUNTU-sshyp-mfa_\"\$pkgver\"-"$revision"_all.deb"
local processing='mkdir -p "$pkgdir"
7z x "$srcdir"/* -o"$srcdir"
tar -xf "$srcdir"/data.tar -C "$pkgdir"
else
local source='https://github.com/rwinkhart/sshyp-labs/releases/download/v"$pkgver"/GENERIC-sshyp-mfa-"$pkgver".tar.xz'
local sumsname='GENERIC-sshyp-"$pkgver".tar.xz'
local processing='mkdir -p "$pkgdir"
cp -r "$srcdir/usr/" "$pkgdir"'
fi
printf "# Maintainer: Randall Winkhart <idgr@tutanota.com>
pkgname=sshyp-mfa
pkgver="$version"
pkgrel="$((revision-1))"
pkgdesc='An MFA (TOTP/Steam) key generator for the sshyp password manager'
options=!check
url='https://github.com/rwinkhart/sshyp-labs'
arch='noarch'
license='GPL-3.0-only'
depends='sshyp'
source=\""$source"\"
package() {
$processing
}
sha512sums=\"
"$sha512" "$sumsname"
\"
" > output/APKBUILD
printf '\nAPKBUILD generated\n\n'
} &&
_create_hpkg() {
printf '\npackaging for Haiku...\n'
mkdir -p output/haikutemp/bin \
output/haikutemp/lib/sshyp \
output/haikutemp/documentation/man/man1 \
output/haikutemp/documentation/packages/sshyp-mfa
printf "name sshypmfa
version "$version"-"$revision"
architecture any
summary \"An MFA (TOTP/Steam) key generator for the sshyp password manager\"
description \"sshyp-mfa is an extension for the sshyp password manager that reads MFA data from sshyp entries and generates generic TOTP and Steam keys.\"
packager \"Randall Winkhart <idgr at tutanota dot com>\"
vendor \"Randall Winkhart\"
licenses {
\"GNU GPL v3\"
}
copyrights {
\"2021-2023 Randall Winkhart\"
}
provides {
sshypmfa = "$version"
cmd:sshypmfa
}
requires {
sshyp
}
urls {
\"https://github.com/rwinkhart/sshyp-labs\"
}
" > output/haikutemp/.PackageInfo
cp -r lib/. output/haikutemp/lib/sshyp/
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshyp-mfa.py
ln -s /system/lib/sshyp/sshyp-mfa.py output/haikutemp/bin/sshyp-mfa
cp -r share/licenses/sshyp-mfa/. output/haikutemp/documentation/packages/sshyp-mfa/
cp extra/manpage output/haikutemp/documentation/man/man1/sshyp-mfa.1
gzip output/haikutemp/documentation/man/man1/sshyp-mfa.1
cd output/haikutemp
package create -b HAIKU-sshyp-mfa-"$version"-"$revision"_all.hpkg
package add HAIKU-sshyp-mfa-"$version"-"$revision"_all.hpkg bin lib documentation
cd ../..
mv output/haikutemp/HAIKU-sshyp-mfa-"$version"-"$revision"_all.hpkg output/
rm -rf output/haikutemp
printf "\nHaiku packaging complete\n\n"
} &&
_create_deb() {
printf '\npackaging for Debian/Ubuntu...\n'
mkdir -p output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/DEBIAN \
output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/lib/sshyp \
output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/bin \
output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/share/man/man1
printf "Package: sshyp-mfa
Version: $version
Section: utils
Architecture: all
Maintainer: Randall Winkhart <idgr at tutanota dot com>
Description: An MFA (TOTP/Steam) key generator for the sshyp password manager
Depends: sshyp
Priority: optional
Installed-Size: 100
" > output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/DEBIAN/control
cp -r lib/. output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/lib/sshyp/
ln -s /usr/lib/sshyp/sshyp-mfa.py output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/bin/sshyp-mfa
cp -r share output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/
cp extra/manpage output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/share/man/man1/sshyp-mfa.1
gzip output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/usr/share/man/man1/sshyp-mfa.1
dpkg-deb --build --root-owner-group -z6 -Sextreme -Zxz output/debiantemp/sshyp-mfa_"$version"-"$revision"_all/
mv output/debiantemp/sshyp-mfa_"$version"-"$revision"_all.deb output/UBUNTU-sshyp_"$version"-"$revision"_all.deb
rm -rf output/debiantemp
sha512="$(sha512sum output/UBUNTU-sshyp-mfa_"$version"-"$revision"_all.deb | awk '{print $1;}')"
printf '\nDebian/Ubuntu packaging complete\n\n'
} &&
_create_termux() {
printf '\npackaging for Termux...\n'
mkdir -p output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/DEBIAN \
output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/lib/sshyp \
output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/bin \
output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1
printf "Package: sshyp-mfa
Version: $version
Section: utils
Architecture: all
Maintainer: Randall Winkhart <idgr at tutanota dot com>
Description: An MFA (TOTP/Steam) key generator for the sshyp password manager
Depends: sshyp
Priority: optional
Installed-Size: 100
" > output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/DEBIAN/control
cp -r lib/. output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/lib/sshyp/
ln -s /data/data/com.termux/files/usr/lib/sshyp/sshyp-mfa.py output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/bin/sshyp-mfa
cp -r share output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
cp extra/manpage output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp-mfa.1
gzip output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp-mfa.1
dpkg-deb --build --root-owner-group output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux/
mv output/termuxtemp/sshyp-mfa_"$version"-"$revision"_all_termux.deb output/TERMUX-sshyp_"$version"-"$revision"_all.deb
rm -rf output/termuxtemp
printf '\nTermux packaging complete\n\n'
} &&
_create_rpm() {
printf '\npackaging for Fedora...\n'
rm -rf ~/rpmbuild
rpmdev-setuptree
mkdir -p output/fedoratemp/usr/bin \
output/fedoratemp/usr/lib/sshyp/extensions \
mkdir -p output/fedoratemp/usr/bin \
output/fedoratemp/usr/lib/sshyp \
output/fedoratemp/usr/share/man/man1
printf "Name: sshyp-mfa
Version: "$version"
Release: "$revision"
Summary: An MFA (TOTP/Steam) key generator for the sshyp password manager
BuildArch: noarch
License: GPL-3.0-only
URL: https://github.com/rwinkhart/sshyp-labs
Source0: GENERIC-FEDORA-sshyp-mfa-"$version".tar.xz
Requires: sshyp
%%description
sshyp-mfa is an extension for the sshyp password manager that reads MFA data from sshyp entries and generates generic TOTP and Steam keys.
%%install
tar xf %%{_sourcedir}/GENERIC-FEDORA-sshyp-mfa-"$version".tar.xz -C %%{_sourcedir}
cp -r %%{_sourcedir}/usr %%{buildroot}
%%files
/usr/bin/sshyp-mfa
/usr/lib/sshyp/sshyp-mfa.py
/usr/lib/sshyp/extensions/sshyp-mfa
%%license /usr/share/licenses/sshyp-mfa/license
%%doc /usr/share/man/man1/sshyp-mfa.1.gz
" > ~/rpmbuild/SPECS/sshyp-mfa.spec
ln -s /usr/lib/sshyp/sshyp-mfa.py output/fedoratemp/usr/bin/sshyp-mfa
cp -r share output/fedoratemp/usr/
cp extra/manpage output/fedoratemp/usr/share/man/man1/sshyp-mfa.1
gzip output/fedoratemp/usr/share/man/man1/sshyp-mfa.1
XZ_OPT=-e6 tar -C output/fedoratemp -cvJf output/GENERIC-FEDORA-sshyp-mfa-"$version".tar.xz usr/
rm -rf output/fedoratemp
cp output/GENERIC-FEDORA-sshyp-mfa-"$version".tar.xz ~/rpmbuild/SOURCES
rpmbuild -bb ~/rpmbuild/SPECS/sshyp-mfa.spec
mv ~/rpmbuild/RPMS/noarch/sshyp-mfa-"$version"-"$revision".noarch.rpm output/FEDORA-sshyp-mfa-"$version"-"$revision".noarch.rpm
rm -rf ~/rpmbuild
printf '\nFedora packaging complete\n\n'
} &&
_create_freebsd_pkg() {
printf '\npackaging for FreeBSD...\n'
mkdir -p output/freebsdtemp/usr/lib/sshyp \
output/freebsdtemp/usr/bin \
output/freebsdtemp/usr/share/man/man1
printf "name: sshyp-mfa
version: \""$version"\"
abi = \"FreeBSD:13:*\";
arch = \"freebsd:13:*\";
origin: security/sshyp-mfa
comment: \"a sshyp extension\"
desc: \"an MFA (TOTP/Steam) key generator for the sshyp password manager\"
maintainer: <idgr at tutanota dot com>
www: https://github.com/rwinkhart/sshyp-labs
prefix: /
\"deps\" : {
\"sshyp\" : {
\"origin\" : \"security/sshyp\"
},
},
" > output/freebsdtemp/+MANIFEST
printf "/usr/bin/sshyp-mfa
/usr/lib/sshyp/sshyp-mfa.py
/usr/lib/sshyp/extensions/sshyp-mfa
/usr/share/licenses/sshyp-mfa/license
/usr/share/man/man1/sshyp-mfa.1.gz
" > output/freebsdtemp/plist
cp -r lib/. output/freebsdtemp/usr/lib/sshyp/
ln -s /usr/lib/sshyp/sshyp-mfa.py output/freebsdtemp/usr/bin/sshyp-mfa
cp -r share output/freebsdtemp/usr/
cp extra/manpage output/freebsdtemp/usr/share/man/man1/sshyp-mfa.1
gzip output/freebsdtemp/usr/share/man/man1/sshyp-mfa.1
pkg create -m output/freebsdtemp/ -r output/freebsdtemp/ -p output/freebsdtemp/plist -o output/
mv output/sshyp-mfa-"$version".pkg output/FREEBSD-sshyp-mfa-"$version"-"$revision".pkg
rm -rf output/freebsdtemp
printf '\nFreeBSD packaging complete\n\n'
} &&
case "$1" in
pkgbuild)
_create_deb
_create_pkgbuild Deb
;;
apkbuild)
_create_deb
_create_apkbuild Deb
;;
haiku)
_create_hpkg
;;
debian)
_create_deb
;;
termux)
_create_termux
;;
fedora)
_create_rpm
;;
freebsd)
_create_freebsd_pkg
;;
buildable-arch)
_create_deb
_create_pkgbuild Deb
_create_apkbuild Deb
case "$(pacman -Q freebsd-pkg)" in
freebsd-pkg*)
_create_freebsd_pkg
;;
esac
;;
*)
printf '\nusage: package.sh [target] <revision>\n\ntargets:\n mainline: pkgbuild apkbuild fedora debian haiku freebsd\n experimental: termux\n groups: buildable-arch\n\n'
;;
esac
-1
View File
@@ -1 +0,0 @@
steam[client]
@@ -1,14 +0,0 @@
sshyp-mfa is a FOSS extension for the sshyp password manager.
Copyright (C) 2022-2023 Randall Winkhart idgr@tutanota.com
This program is free software: you can redistribute it and/or modify
it under the terms of version 3 (only) of the GNU General Public License
as published by the Free Software Foundation.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.