mirror of
https://github.com/rwinkhart/sshyp.git
synced 2026-09-03 15:47:18 -04:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
921630f5a8 | ||
|
|
627c6a1a14 | ||
|
|
a9f4435493 | ||
|
|
7d639ecca9 | ||
|
|
eefe5e39b5 | ||
|
|
c28b836c2a | ||
|
|
b53370a3e2 | ||
|
|
9776961f2a | ||
|
|
1a35aaf33b | ||
|
|
66b15ac22c | ||
|
|
56db2e65f8 | ||
|
|
1be67d404b | ||
|
|
a279819260 | ||
|
|
578f7dee14 | ||
|
|
5bec4fdaa9 | ||
|
|
5f903966da | ||
|
|
cfd551ef7c | ||
|
|
4d22b5b5a8 | ||
|
|
46d5f8d515 | ||
|
|
02ee2a5c0e | ||
|
|
fb1c3844a8 | ||
|
|
213ca41582 | ||
|
|
b8dc5c4f89 | ||
|
|
574637392a | ||
|
|
c6f31da6d4 | ||
|
|
0f4c57bec3 | ||
|
|
51b1b8c6ec | ||
|
|
5f0a40efc0 | ||
|
|
05c034652f | ||
|
|
1d185b1723 | ||
|
|
bca2af0ed8 | ||
|
|
d301cf6298 | ||
|
|
89c9a03cc1 | ||
|
|
3392e3ceea | ||
|
|
176ee623cf | ||
|
|
42abb7b674 | ||
|
|
3a6655e977 | ||
|
|
9d1f0a065b | ||
|
|
8298966d8f | ||
|
|
d4d9fb88fd | ||
|
|
2beeb1dc38 | ||
|
|
86ad4e5cad | ||
|
|
e55c812a06 | ||
|
|
a0351d19d3 | ||
|
|
90c15bcda8 | ||
|
|
cb754c5ba7 | ||
|
|
9979de26d0 | ||
|
|
4207ecb555 | ||
|
|
8bcfd3fcd8 | ||
|
|
78588f686e | ||
|
|
4753bb4c37 | ||
|
|
81ccdf71ea | ||
|
|
67eb1a44ca | ||
|
|
8af7de10a7 | ||
|
|
3108a072dd | ||
|
|
65be0eaf6f | ||
|
|
bb34025c31 | ||
|
|
278231fe40 | ||
|
|
7356777e50 | ||
|
|
5a33eb26f0 | ||
|
|
d796c48ede | ||
|
|
b1fd934b96 | ||
|
|
9848d38a0b | ||
|
|
2ab409e95e | ||
|
|
64d46f1746 | ||
|
|
e9c787cfe3 | ||
|
|
c200b5bbec | ||
|
|
b6593e609b | ||
|
|
32b0c39fb6 | ||
|
|
6b8e24b0b2 | ||
|
|
2d47f42414 | ||
|
|
a773056202 | ||
|
|
097aca8c43 | ||
|
|
275b07e53f | ||
|
|
46d539f386 | ||
|
|
0adf00d81e | ||
|
|
46b212988f | ||
|
|
3e8772786a | ||
|
|
3a01157cb3 | ||
|
|
079a1412ae | ||
|
|
359edcd46c | ||
|
|
60c2920f3c | ||
|
|
a3cd6a1f17 | ||
|
|
8c2b7df1da | ||
|
|
994eaee49b | ||
|
|
8f0eb1134a | ||
|
|
c95643ca89 | ||
|
|
35ea8bf7d7 | ||
|
|
60431b623c | ||
|
|
185ae4ebff | ||
|
|
1e290a1f26 | ||
|
|
71157633df | ||
|
|
03487348ea | ||
|
|
2d20ddbb97 | ||
|
|
21287ca57f | ||
|
|
612f288904 | ||
|
|
0fbe084ff7 | ||
|
|
fdf90e043a | ||
|
|
b89158d0bb | ||
|
|
dede7cf8ac | ||
|
|
6d3ba2714b | ||
|
|
09991a2a30 | ||
|
|
c5884024de | ||
|
|
1e2166ddaf | ||
|
|
86487b8ae5 | ||
|
|
fa05312d49 | ||
|
|
71d942ffae | ||
|
|
cc1a099363 | ||
|
|
d6342faf84 | ||
|
|
c7cae5303a | ||
|
|
1d80cb08ce | ||
|
|
8163aee868 | ||
|
|
7c061f561f | ||
|
|
339d20bc3e | ||
|
|
434f5f85cd | ||
|
|
22d9605781 | ||
|
|
d644f8df01 | ||
|
|
551789636d | ||
|
|
9ab175a8d8 | ||
|
|
e5a4d80e3b | ||
|
|
0920dcf004 | ||
|
|
e18b3b4d0a | ||
|
|
ffccc88a1d | ||
|
|
e1ec834e5c | ||
|
|
018d0c511d | ||
|
|
55b94fc4cc | ||
|
|
3f9c4e2c8d | ||
|
|
166ac50f42 | ||
|
|
df1c6482a8 | ||
|
|
38c6ef3d1b | ||
|
|
7bea6093b8 | ||
|
|
f9ca6f8e94 | ||
|
|
75d8eb7b7d | ||
|
|
39316d04a2 | ||
|
|
3e9a4c0403 | ||
|
|
3bc07b48ef | ||
|
|
5234e8c048 | ||
|
|
b7c3535955 | ||
|
|
1f52c45c43 | ||
|
|
7723baa69e | ||
|
|
b680cc96d6 | ||
|
|
f750fe1e4d | ||
|
|
b96db3ad92 | ||
|
|
224fc1fc6d | ||
|
|
0bd2e45dba | ||
|
|
6410843911 | ||
|
|
3dda6d8428 | ||
|
|
4f31af5eff | ||
|
|
bfb830c5e5 | ||
|
|
790121e7ea | ||
|
|
4168b800f8 | ||
|
|
801d515697 | ||
|
|
379970d53b | ||
|
|
4abb3ed718 | ||
|
|
6690fd15c9 | ||
|
|
1582e73a98 | ||
|
|
dfe1703e62 | ||
|
|
7a76130b26 | ||
|
|
98dcbf57c6 | ||
|
|
a5946d558a | ||
|
|
30fb5ed041 | ||
|
|
fb1f5b92c3 | ||
|
|
61b2186b0a | ||
|
|
2113b93481 | ||
|
|
2030d90114 | ||
|
|
75071601e6 | ||
|
|
9a0a261d55 | ||
|
|
4ca2d89464 | ||
|
|
f90ec5c900 | ||
|
|
fa0a4fe0b8 | ||
|
|
c85a9d2ccd |
@@ -1,7 +1,13 @@
|
|||||||

|

|
||||||
|
|
||||||
|
[](https://github.com/rwinkhart/sshyp/releases)
|
||||||
|

|
||||||
|
[](https://github.com/rwinkhart/sshyp/releases)
|
||||||
|
|
||||||
[](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml)
|
[](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml)
|
||||||
|
|
||||||
|
pronounced as: 'sheep', 'shēp'
|
||||||
|
|
||||||
sshyp is a very simple self-hosted, synchronized password manager for UNIX(-like) systems (currently Haiku/FreeBSD/Linux).
|
sshyp is a very simple self-hosted, synchronized password manager for UNIX(-like) systems (currently Haiku/FreeBSD/Linux).
|
||||||
|
|
||||||
sshyp is compatible with entries created by pass/password-store, as its original goal was to be like pass/password-store, but far more user-friendly to synchronize with a self-hosted server.
|
sshyp is compatible with entries created by pass/password-store, as its original goal was to be like pass/password-store, but far more user-friendly to synchronize with a self-hosted server.
|
||||||
@@ -24,15 +30,11 @@ What sshyp can do:
|
|||||||
|
|
||||||
- securely manage a collection of encrypted passwords and notes via CLI
|
- securely manage a collection of encrypted passwords and notes via CLI
|
||||||
- generate new, secure passwords to the user's choice in length and complexity
|
- generate new, secure passwords to the user's choice in length and complexity
|
||||||
- securely sync said passwords and notes seamlessly between devices
|
- securely sync said passwords and notes seamlessly between devices (or just manage them offline)
|
||||||
|
- utilize [extensions](https://github.com/rwinkhart/sshyp-labs) to interact with your entries is additional ways (such as generating TOTP keys or managing your entries in a GUI)
|
||||||
- everything above with entries created by pass/password-store!
|
- everything above with entries created by pass/password-store!
|
||||||
- everything above on Haiku, FreeBSD, Linux, and Termux (an Android terminal emulator)!
|
- everything above on Haiku, FreeBSD, Linux, and Termux (an Android terminal emulator)!
|
||||||
|
|
||||||
What sshyp will likely do:
|
|
||||||
|
|
||||||
- (planned v1.1.0) 2FA/MFA management (beneficial for reducing phone usage)
|
|
||||||
- (planned v1.2.0) everything it already does, but also in a GUI for Linux/Haiku
|
|
||||||
|
|
||||||
What sshyp definitely won't do:
|
What sshyp definitely won't do:
|
||||||
|
|
||||||
- Non-UNIX(-like) support, e.g. Windows (I'd be happy to link to third-party ports, if someone were to make them)
|
- Non-UNIX(-like) support, e.g. Windows (I'd be happy to link to third-party ports, if someone were to make them)
|
||||||
@@ -40,10 +42,14 @@ What sshyp definitely won't do:
|
|||||||
# Installation
|
# Installation
|
||||||
Please see the [installation guide](https://github.com/rwinkhart/sshyp/wiki/Installation) in the sshyp wiki for directions specific to your distribution/OS.
|
Please see the [installation guide](https://github.com/rwinkhart/sshyp/wiki/Installation) in the sshyp wiki for directions specific to your distribution/OS.
|
||||||
|
|
||||||
Pre-built packages exist for Haiku, FreeBSD, Arch Linux, Debian/Ubuntu Linux, Fedora Linux, and Termux. These can be downloaded from the releases page.
|
Pre-built packages exist for Haiku, FreeBSD, Alpine Linux, Arch Linux, Debian/Ubuntu Linux, Fedora Linux, and Termux. These can be downloaded from the releases page.
|
||||||
|
|
||||||
Requests for additional distribution/OS support can be filed as issues.
|
Requests for additional distribution/OS support can be filed as issues.
|
||||||
|
|
||||||
|
Extensions are available in the [sshyp-labs](https://github.com/rwinkhart/sshyp-labs) repository.
|
||||||
|
|
||||||
|
Bash completions can be enabled by installing your distribution's "bash-completion" package and restarting your terminal.
|
||||||
|
|
||||||
# Building
|
# Building
|
||||||
Since sshyp is written entirely in Python, it doesn't need to be compiled. It does, however, need to be packaged for installation.
|
Since sshyp is written entirely in Python, it doesn't need to be compiled. It does, however, need to be packaged for installation.
|
||||||
|
|
||||||
@@ -52,7 +58,7 @@ A packaging script is included in the root directory of the repo in order to pac
|
|||||||
```
|
```
|
||||||
git clone https://github.com/rwinkhart/sshyp.git
|
git clone https://github.com/rwinkhart/sshyp.git
|
||||||
cd sshyp
|
cd sshyp
|
||||||
./package.sh
|
./package.sh [target] <revision>
|
||||||
```
|
```
|
||||||
|
|
||||||
The packaging script has been tested on Arch Linux with "dpkg" as a dependency for Debian/Ubuntu and Termux packaging and "freebsd-pkg" as a dependency for FreeBSD packaging.
|
The packaging script has been tested on Arch Linux with "dpkg" as a dependency for Debian/Ubuntu and Termux packaging and "freebsd-pkg" as a dependency for FreeBSD packaging.
|
||||||
@@ -61,7 +67,7 @@ Haiku and Fedora packaging must be done on their own respective distributions.
|
|||||||
|
|
||||||
The AUR version and the packages attatched to the release tags were already packaged using this script.
|
The AUR version and the packages attatched to the release tags were already packaged using this script.
|
||||||
|
|
||||||
Currently, the script can create packages for Haiku, FreeBSD, Arch Linux (PKGBUILD), Debian/Ubuntu Linux, Fedora Linux, Termux, and generic.
|
Currently, the script can create packages for Haiku, FreeBSD, Alpine Linux (APKBUILD), Arch Linux (PKGBUILD), Debian/Ubuntu Linux, Fedora Linux, Termux, and generic.
|
||||||
|
|
||||||
# Usage
|
# Usage
|
||||||
Upon initial installation (on both the server and client devices), be sure to run:
|
Upon initial installation (on both the server and client devices), be sure to run:
|
||||||
@@ -89,10 +95,10 @@ man sshyp
|
|||||||
# Roadmap
|
# Roadmap
|
||||||
Short-term Goals:
|
Short-term Goals:
|
||||||
|
|
||||||
- 2FA/MFA management
|
- a minimal GUI app - being made as an [extension](https://github.com/rwinkhart/sshyp-labs)
|
||||||
- create minimal GUI apps (Linux x86_64, Linux aarch64, Haiku x86_64)
|
- improved extension integration (allow extensions to add new arguments)
|
||||||
- various optimizations/bug fixes
|
|
||||||
|
|
||||||
Long-term Goals:
|
Long-term Goals:
|
||||||
|
|
||||||
|
- a fun surprise
|
||||||
- seize the thrones, shear the humans
|
- seize the thrones, shear the humans
|
||||||
|
|||||||
-103
@@ -1,103 +0,0 @@
|
|||||||
#!/bin/python3
|
|
||||||
|
|
||||||
# external modules
|
|
||||||
|
|
||||||
from os import path, system, walk
|
|
||||||
from os.path import expanduser, getmtime, join
|
|
||||||
from pathlib import Path
|
|
||||||
from sys import exit as s_exit
|
|
||||||
|
|
||||||
|
|
||||||
# utility functions
|
|
||||||
|
|
||||||
def get_titles_mods(_directory, _destination, _user_data):
|
|
||||||
_title_list, _mod_list = [], []
|
|
||||||
Path(path.expanduser('~/.config/sshync')).mkdir(0o700, parents=True, exist_ok=True) # create config directory
|
|
||||||
# local fetching
|
|
||||||
if _destination == 'l':
|
|
||||||
open(expanduser('~/.config/sshync/database'), 'w').write('') # blanks out database file
|
|
||||||
for _root, _directories, _files in walk(_directory):
|
|
||||||
for _filename in _files:
|
|
||||||
_title_list.append(join(_root.replace(_directory, '', 1), _filename))
|
|
||||||
_mod_list.append(int(getmtime(join(_root, _filename))))
|
|
||||||
for _title in _title_list:
|
|
||||||
open(expanduser('~/.config/sshync/database'), 'a').write(str(_title) + '\n')
|
|
||||||
open(expanduser('~/.config/sshync/database'), 'a').write('^&*\n')
|
|
||||||
for _mod in _mod_list:
|
|
||||||
open(expanduser('~/.config/sshync/database'), 'a').write(str(_mod) + '\n')
|
|
||||||
# remote fetching
|
|
||||||
if _destination == 'r':
|
|
||||||
system(f"ssh -i '{_user_data[5]}' -p {_user_data[2]} {_user_data[0]}@{_user_data[1]} \"cd /bin; python -c 'impo"
|
|
||||||
f"rt sshync; sshync.get_titles_mods(\"'\"{_user_data[4]}\"'\", \"'\"l\"'\", \"'\"{_user_data}\"'\")'\"")
|
|
||||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' {_user_data[0]}@{_user_data[1]}:"
|
|
||||||
f"'/home/{_user_data[0]}/.config/sshync/database' '{expanduser('~/.config/sshync/')}'")
|
|
||||||
_titles, _sep, _mods = '*&^'.join(open(expanduser('~/.config/sshync/database')).readlines()).replace('\n', '')\
|
|
||||||
.partition('^&*')
|
|
||||||
_title_list, _mod_list = _titles.split('*&^')[:-1], _mods.split('*&^')[1:]
|
|
||||||
return _title_list, _mod_list
|
|
||||||
|
|
||||||
|
|
||||||
def sort_titles_mods(_list_1, _list_2):
|
|
||||||
_title_list_2_sorted, _mod_list_2_sorted = [], []
|
|
||||||
# title sorting
|
|
||||||
for _title in _list_1[0]:
|
|
||||||
if _title in _list_2[0]:
|
|
||||||
_title_list_2_sorted.append(_title)
|
|
||||||
for _title in _list_2[0]:
|
|
||||||
if _title not in _title_list_2_sorted:
|
|
||||||
_title_list_2_sorted.append(_title)
|
|
||||||
# mod time sorting
|
|
||||||
for _title in _title_list_2_sorted:
|
|
||||||
_mod_list_2_sorted.append(_list_2[1][_list_2[0].index(_title)])
|
|
||||||
return _title_list_2_sorted, _mod_list_2_sorted
|
|
||||||
|
|
||||||
|
|
||||||
def make_profile(_profile_dir, _local_dir, _remote_dir, _identity, _ip, _port, _user):
|
|
||||||
open(_profile_dir, 'w').write(_user + '\n' + _ip + '\n' + _port + '\n' + _local_dir + '\n' + _remote_dir + '\n' +
|
|
||||||
_identity + '\n')
|
|
||||||
|
|
||||||
|
|
||||||
def get_profile(_profile_dir):
|
|
||||||
try:
|
|
||||||
_profile_data = open(_profile_dir).readlines()
|
|
||||||
except (FileNotFoundError, IndexError):
|
|
||||||
print('\n\u001b[38;5;9merror: the profile does not exist or is corrupted.\u001b[0m\n')
|
|
||||||
_profile_data = None
|
|
||||||
s_exit(1)
|
|
||||||
# extract data from profile
|
|
||||||
_user = _profile_data[0].replace('\n', '')
|
|
||||||
_ip = _profile_data[1].replace('\n', '')
|
|
||||||
_port = _profile_data[2].replace('\n', '')
|
|
||||||
_local_dir = _profile_data[3].replace('\n', '')
|
|
||||||
_remote_dir = _profile_data[4].replace('\n', '')
|
|
||||||
_identity = _profile_data[5].replace('\n', '')
|
|
||||||
return _user, _ip, _port, _local_dir, _remote_dir, _identity
|
|
||||||
|
|
||||||
|
|
||||||
def run_profile(_profile_dir):
|
|
||||||
_user_data = get_profile(_profile_dir)
|
|
||||||
_remote_titles_mods_saver = get_titles_mods(_user_data[4], 'r', _user_data) # saved to prevent re-walking directory
|
|
||||||
_index_l = sort_titles_mods(_remote_titles_mods_saver, get_titles_mods(_user_data[3], 'l', _user_data))
|
|
||||||
_index_r = sort_titles_mods(_index_l, _remote_titles_mods_saver)
|
|
||||||
_i = -1
|
|
||||||
for _title in _index_l[0]:
|
|
||||||
_i += 1
|
|
||||||
if _title in _index_r[0]:
|
|
||||||
# compare mod times and sync
|
|
||||||
if int(_index_l[1][_i]) > int(_index_r[1][_i]):
|
|
||||||
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is newer locally, uploading...")
|
|
||||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[3]}{_title}' "
|
|
||||||
f"'{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
|
||||||
elif int(_index_l[1][_i]) < int(_index_r[1][_i]):
|
|
||||||
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is newer remotely, downloading...")
|
|
||||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[0]}@{_user_data[1]}:"
|
|
||||||
f"{_user_data[4]}{_title}' '{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
|
||||||
else:
|
|
||||||
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is not on remote server, uploading...")
|
|
||||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[3]}{_title}' "
|
|
||||||
f"'{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
|
||||||
for _title in _index_r[0]:
|
|
||||||
if _title not in _index_l[0]:
|
|
||||||
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is not in local directory, downloading...")
|
|
||||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[0]}@{_user_data[1]}:"
|
|
||||||
f"{_user_data[4]}{_title}' '{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
|
||||||
@@ -1,739 +0,0 @@
|
|||||||
#!/bin/python3
|
|
||||||
|
|
||||||
# external modules
|
|
||||||
|
|
||||||
from os import environ, listdir, path, remove, system, uname, walk
|
|
||||||
from pathlib import Path
|
|
||||||
import random
|
|
||||||
from shutil import get_terminal_size, move, rmtree
|
|
||||||
import sshync
|
|
||||||
import string
|
|
||||||
from subprocess import CalledProcessError, Popen, PIPE, run
|
|
||||||
from sys import argv, exit as s_exit
|
|
||||||
from textwrap import fill
|
|
||||||
|
|
||||||
|
|
||||||
# utility functions
|
|
||||||
|
|
||||||
def entry_list_gen(): # generates and prints a list of all folders and entries
|
|
||||||
print('\n\u001b[38;5;0;48;5;15msshyp entries:\u001b[0m\n')
|
|
||||||
_entry_list, _color_alternator = [], 1
|
|
||||||
for _entry in sorted(listdir(path.expanduser('~/.password-pasture'))):
|
|
||||||
if Path(path.expanduser(f"~/.password-pasture/{_entry}")).is_file():
|
|
||||||
if _color_alternator == 1:
|
|
||||||
_entry_list.append(f"{_entry.replace('.gpg', '')}")
|
|
||||||
_color_alternator = 2
|
|
||||||
else:
|
|
||||||
_entry_list.append(f"\u001b[38;5;8m{_entry.replace('.gpg', '')}\u001b[0m")
|
|
||||||
_color_alternator = 1
|
|
||||||
_real = len(' '.join(_entry_list)) - (5.5 * len(_entry_list))
|
|
||||||
if _real <= get_terminal_size()[0]:
|
|
||||||
_width = len(' '.join(_entry_list))
|
|
||||||
else:
|
|
||||||
_width = (len(' '.join(_entry_list)) / (_real / get_terminal_size()[0]) - 25)
|
|
||||||
try:
|
|
||||||
print(fill(' '.join(_entry_list), width=_width) + '\n')
|
|
||||||
except ValueError:
|
|
||||||
pass
|
|
||||||
for _root, _directories, _files in walk(path.expanduser('~/.password-pasture')):
|
|
||||||
for _dir in sorted(_directories):
|
|
||||||
_inner_dir = f"{_root.replace(path.expanduser('~/.password-pasture'), '')}/{_dir}"
|
|
||||||
print(f"\u001b[38;5;15;48;5;238m{_inner_dir}/\u001b[0m")
|
|
||||||
_entry_list, _color_alternator = [], 1
|
|
||||||
for _s_root, _s_directories, _s_files in walk(path.expanduser(f"~/.password-pasture{_inner_dir}")):
|
|
||||||
for _entry in sorted(_s_files):
|
|
||||||
if _color_alternator == 1:
|
|
||||||
_entry_list.append(f"{_entry.replace('.gpg', '')}")
|
|
||||||
_color_alternator = 2
|
|
||||||
else:
|
|
||||||
_entry_list.append(f"\u001b[38;5;8m{_entry.replace('.gpg', '')}\u001b[0m")
|
|
||||||
_color_alternator = 1
|
|
||||||
_real = len(' '.join(_entry_list)) - (5.5 * len(_entry_list))
|
|
||||||
if _real <= get_terminal_size()[0]:
|
|
||||||
_width = len(' '.join(_entry_list))
|
|
||||||
else:
|
|
||||||
_width = (len(' '.join(_entry_list)) / (_real / get_terminal_size()[0]) - 25)
|
|
||||||
try:
|
|
||||||
print(fill(' '.join(_entry_list), width=_width) + '\n')
|
|
||||||
except ValueError:
|
|
||||||
print('\u001b[38;5;9m-empty directory-\u001b[0m\n')
|
|
||||||
|
|
||||||
|
|
||||||
def entry_reader(_decrypted_entry):
|
|
||||||
_entry_lines, _notes_flag = open(_decrypted_entry, 'r').readlines(), 0
|
|
||||||
print()
|
|
||||||
for _num in range(len(_entry_lines)):
|
|
||||||
try:
|
|
||||||
if _num == 0 and _entry_lines[1] != '\n':
|
|
||||||
print(f"\u001b[38;5;15;48;5;238musername:\u001b[0m\n{_entry_lines[1]}")
|
|
||||||
elif _num == 1 and _entry_lines[0] != '\n':
|
|
||||||
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0]}")
|
|
||||||
elif _num == 2 and _entry_lines[2] != '\n':
|
|
||||||
print(f"\u001b[38;5;15;48;5;238murl:\u001b[0m\n{_entry_lines[_num]}")
|
|
||||||
elif _num >= 3 and _entry_lines[_num] != '\n' and _notes_flag != 1:
|
|
||||||
_notes_flag = 1
|
|
||||||
print('\u001b[38;5;15;48;5;238mnotes:\u001b[0m\n' + _entry_lines[_num].replace('\n', ''))
|
|
||||||
elif _num >= 3 and _notes_flag == 1:
|
|
||||||
print(_entry_lines[_num].replace('\n', ''))
|
|
||||||
if _notes_flag == 1:
|
|
||||||
try:
|
|
||||||
_line_test = _entry_lines[_num + 1]
|
|
||||||
except IndexError:
|
|
||||||
print()
|
|
||||||
except IndexError:
|
|
||||||
if _num == 0:
|
|
||||||
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0]}")
|
|
||||||
|
|
||||||
|
|
||||||
def replace_line(file_name, line_num, text): # replaces text in a given line with different text
|
|
||||||
_lines = open(file_name, 'r').readlines()
|
|
||||||
_lines[line_num] = text
|
|
||||||
open(file_name, 'w').writelines(_lines)
|
|
||||||
|
|
||||||
|
|
||||||
def entry_name_fetch(_entry_name_location):
|
|
||||||
if type(_entry_name_location) == str:
|
|
||||||
entry_list_gen()
|
|
||||||
_entry_name = str(input(_entry_name_location))
|
|
||||||
elif _entry_name_location == 0:
|
|
||||||
_entry_name = argument
|
|
||||||
else:
|
|
||||||
_entry_name_split = argument.split(' ')
|
|
||||||
del _entry_name_split[:_entry_name_location]
|
|
||||||
_entry_name = ' '.join(_entry_name_split)
|
|
||||||
if _entry_name.startswith('/'):
|
|
||||||
return _entry_name.replace('/', '', 1)
|
|
||||||
else:
|
|
||||||
return _entry_name
|
|
||||||
|
|
||||||
|
|
||||||
def shm_gen(): # generates a random temporary folder for security and returns random names for the folder and temp file
|
|
||||||
_shm_folder_gen = ''.join(random.SystemRandom().choice(string.ascii_letters + string.digits)
|
|
||||||
for _ in range(random.randint(10, 30)))
|
|
||||||
_shm_entry_gen = ''.join(random.SystemRandom().choice(string.ascii_letters + string.digits)
|
|
||||||
for _ in range(random.randint(10, 30)))
|
|
||||||
Path(tmp_dir + _shm_folder_gen).mkdir(0o700)
|
|
||||||
return _shm_folder_gen, _shm_entry_gen
|
|
||||||
|
|
||||||
|
|
||||||
def pass_gen():
|
|
||||||
def _pass_gen_function(__complexity, __length):
|
|
||||||
if __complexity.lower() == 's':
|
|
||||||
__character_pool = string.ascii_letters + string.digits
|
|
||||||
else:
|
|
||||||
__character_pool = string.ascii_letters + string.digits + string.punctuation
|
|
||||||
__gen = ''.join(random.SystemRandom().choice(__character_pool) for _ in range(__length))
|
|
||||||
__min_special, __special = round(.2 * __length), 0
|
|
||||||
for __character in __gen:
|
|
||||||
if not __character.isalpha():
|
|
||||||
__special += 1
|
|
||||||
if __special < __min_special:
|
|
||||||
__gen = _pass_gen_function(__complexity, __length)
|
|
||||||
return __gen
|
|
||||||
try:
|
|
||||||
_length = int(input('password length: '))
|
|
||||||
except ValueError:
|
|
||||||
print(f"\n\u001b[38;5;9merror: a non-integer value was input for password length\u001b[0m\n")
|
|
||||||
_gen = pass_gen()
|
|
||||||
return _gen
|
|
||||||
if _length > 840:
|
|
||||||
_length = 840
|
|
||||||
print('\n\u001b[38;5;9mpassword length has been limited to the maximum of 840 characters\u001b[0m\n')
|
|
||||||
_complexity = str(input('password complexity - simple (for compatibility) or complex (for security)? (s/C) '))
|
|
||||||
_gen = _pass_gen_function(_complexity, _length)
|
|
||||||
return _gen
|
|
||||||
|
|
||||||
|
|
||||||
def encrypt(_shm_folder, _shm_entry, _location):
|
|
||||||
system(f"{gpg} -qr {str(gpg_id)} -e '{tmp_dir}{_shm_folder}/{_shm_entry}'")
|
|
||||||
move(f"{tmp_dir}{_shm_folder}/{_shm_entry}.gpg", f"{directory}{_location}.gpg")
|
|
||||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
|
||||||
|
|
||||||
|
|
||||||
def decrypt(_entry_dir, _shm_folder, _shm_entry):
|
|
||||||
if _shm_folder == 0 and _shm_entry == 0:
|
|
||||||
_command = f"{gpg} -qd --output /dev/null {path.expanduser('~/.config/sshyp/lock.gpg')}"
|
|
||||||
else:
|
|
||||||
_command = f"{gpg} -qd --output {tmp_dir}{_shm_folder}/{_shm_entry} {_entry_dir}.gpg"
|
|
||||||
try:
|
|
||||||
run(_command, shell=True, stderr=PIPE, check=True, close_fds=True)
|
|
||||||
except CalledProcessError:
|
|
||||||
print(f"\n\u001b[38;5;9merror: could not decrypt - ensure the correct gpg key is present\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
|
|
||||||
|
|
||||||
def edit_note(_shm_folder, _shm_entry):
|
|
||||||
lines = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}").readlines()
|
|
||||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(lines[0:3])
|
|
||||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'w').writelines(lines[3:])
|
|
||||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
|
||||||
edit_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n").read()
|
|
||||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'a').write(edit_notes)
|
|
||||||
|
|
||||||
|
|
||||||
def copy_name_check(_port, _username_ssh, _ip, _client_device_name):
|
|
||||||
_command = f"ssh -o ConnectTimeout=3 -i '{path.expanduser('~/.ssh/sshyp')}' -p {_port} {_username_ssh}@{_ip} " \
|
|
||||||
f"\"touch '/home/{_username_ssh}/.config/sshyp/devices/{_client_device_name}'\""
|
|
||||||
try:
|
|
||||||
run(_command, shell=True, stderr=PIPE, check=True, close_fds=True)
|
|
||||||
except CalledProcessError:
|
|
||||||
print('\n\u001b[38;5;9mwarning: ssh connection could not be made - ensure the public key (~/.ssh/sshyp.pub) is '
|
|
||||||
'registered on the remote server and that the entered ip, port, and username are correct\n\nsyncing '
|
|
||||||
'functionality will be disabled until this is addressed\u001b[0m\n')
|
|
||||||
open(path.expanduser('~/.config/sshyp/ssh-error'), 'w').write('1')
|
|
||||||
return 1
|
|
||||||
open(path.expanduser('~/.config/sshyp/ssh-error'), 'w').write('0')
|
|
||||||
return 0
|
|
||||||
|
|
||||||
# argument-specific functions
|
|
||||||
|
|
||||||
|
|
||||||
def tweak(): # runs configuration wizard
|
|
||||||
# storage/config directory creation
|
|
||||||
Path(path.expanduser('~/.password-pasture')).mkdir(0o700, parents=True, exist_ok=True)
|
|
||||||
Path(path.expanduser('~/.config/sshyp/devices')).mkdir(0o700, parents=True, exist_ok=True)
|
|
||||||
if not Path(f"{path.expanduser('~/.config/sshyp/tmp')}").exists():
|
|
||||||
if uname()[0] == 'Haiku' or uname()[0] == 'FreeBSD':
|
|
||||||
system(f"ln -s /tmp {path.expanduser('~/.config/sshyp/tmp')}")
|
|
||||||
elif Path("/data/data/com.termux").exists():
|
|
||||||
system(f"ln -s '/data/data/com.termux/files/usr/tmp' {path.expanduser('~/.config/sshyp/tmp')}")
|
|
||||||
else:
|
|
||||||
system(f"ln -s /dev/shm {path.expanduser('~/.config/sshyp/tmp')}")
|
|
||||||
# device type configuration
|
|
||||||
_device_type = input('\nclient or server installation? (C/s) ')
|
|
||||||
if _device_type.lower() == 's':
|
|
||||||
open(path.expanduser('~/.config/sshyp/sshyp-device'), 'w').write(_device_type)
|
|
||||||
Path(path.expanduser('~/.config/sshyp/deleted')).mkdir(0o700, parents=True, exist_ok=True)
|
|
||||||
print('\nmake sure the ssh service is running and properly configured\n\nconfiguration complete\n')
|
|
||||||
s_exit(0)
|
|
||||||
else:
|
|
||||||
# device type configuration
|
|
||||||
_device_type = 'c' # ensure device type flag is properly set
|
|
||||||
open(path.expanduser('~/.config/sshyp/sshyp-device'), 'w').write(_device_type)
|
|
||||||
|
|
||||||
# gpg configuration
|
|
||||||
_gpg_id = input('\nsshyp requires the use of a unique gpg key - do you already have one that you are '
|
|
||||||
'willing to use? (y/N) ')
|
|
||||||
if _gpg_id.lower() != 'y':
|
|
||||||
print('\na unique gpg key has been generated for you.')
|
|
||||||
system(f"{gpg} --full-generate-key")
|
|
||||||
_gpg_id = str(input('\nplease input the id of your gpg key: '))
|
|
||||||
open(path.expanduser('~/.config/sshyp/sshyp-gpg'), 'w').write(_gpg_id + '\n')
|
|
||||||
|
|
||||||
# lock file generation
|
|
||||||
open(path.expanduser('~/.config/sshyp/lock'), 'w')
|
|
||||||
system(f"{gpg} -qr {str(_gpg_id)} -e {path.expanduser('~/.config/sshyp/lock')}")
|
|
||||||
remove(f"{path.expanduser('~/.config/sshyp')}/lock")
|
|
||||||
|
|
||||||
# ssh key configuration
|
|
||||||
_ssh_gen = (input('\nmake sure the ssh service on the remote server is running and properly configured'
|
|
||||||
'\n\nsync support requires a unique ssh key - would you like to have this automatically '
|
|
||||||
'generated? (Y/n) '))
|
|
||||||
if _ssh_gen.lower() != 'n':
|
|
||||||
if uname()[0] == 'Haiku':
|
|
||||||
Path(f"{path.expanduser('~')}/.ssh").mkdir(0o700, exist_ok=True)
|
|
||||||
system('ssh-keygen -t ed25519 -f ~/.ssh/sshyp')
|
|
||||||
else:
|
|
||||||
print(f"\nensure that the key file you are using is located at {path.expanduser('~/.ssh/sshyp')}")
|
|
||||||
|
|
||||||
# ssh ip+port configuration
|
|
||||||
_ip_port = str(input('\nexample input: 10.10.10.10:9999\n\nip and ssh port of the remote server: '))
|
|
||||||
_ip, _sep, _port = _ip_port.partition(':')
|
|
||||||
|
|
||||||
# ssh user configuration
|
|
||||||
_username_ssh = str(input('\nusername of the remote server: '))
|
|
||||||
print(f"\nentry directory: /home/{_username_ssh}/.password-pasture/")
|
|
||||||
|
|
||||||
# sshync profile generation
|
|
||||||
sshync.make_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'),
|
|
||||||
path.expanduser('~/.password-pasture/'), f"/home/{_username_ssh}/.password-pasture/",
|
|
||||||
path.expanduser('~/.ssh/sshyp'), _ip, _port, _username_ssh)
|
|
||||||
|
|
||||||
# device name configuration
|
|
||||||
for _name in listdir(path.expanduser('~/.config/sshyp/devices')): # remove existing device name
|
|
||||||
remove(f"{path.expanduser('~/.config/sshyp/devices/')}{_name}")
|
|
||||||
print('\n\u001b[4;1mimportant:\u001b[0m This name \u001b[4;1mmust\u001b[0m be unique amongst your client '
|
|
||||||
'devices\n\nthis is used to keep track of which devices have up-to-date databases.\n')
|
|
||||||
_client_device_name = str(input('device name: '))
|
|
||||||
open(f"{path.expanduser('~/.config/sshyp/devices/')}{_client_device_name}", 'w')
|
|
||||||
copy_name_check(_port, _username_ssh, _ip, _client_device_name)
|
|
||||||
|
|
||||||
print('\nconfiguration complete\n')
|
|
||||||
|
|
||||||
|
|
||||||
def print_info(): # prints help text based on argument
|
|
||||||
if argument_list[0] == 'help' or argument_list[0] == '--help' or argument_list[0] == '-h':
|
|
||||||
print('\n\u001b[1msshyp copyright (c) 2021-2022 randall winkhart\u001b[0m\n')
|
|
||||||
print("this is free software, and you are welcome to redistribute it under certain conditions;\nthis program "
|
|
||||||
"comes with absolutely no warranty;\ntype `sshyp license' for details")
|
|
||||||
print('\n\u001b[1musage:\u001b[0m sshyp [option [flag] [<entry name>]] | [/<entry name>]\n')
|
|
||||||
print('\u001b[1moptions:\u001b[0m')
|
|
||||||
print('help/--help/-h bring up this menu')
|
|
||||||
print('version/-v display sshyp version info')
|
|
||||||
print('tweak configure sshyp')
|
|
||||||
print('add add an entry')
|
|
||||||
print('gen generate a new password')
|
|
||||||
print('edit edit an existing entry')
|
|
||||||
print('copy copy details of an entry to your clipboard')
|
|
||||||
print('shear/-rm delete an existing entry')
|
|
||||||
print('sync/-s manually sync the entry directory via sshync\n')
|
|
||||||
print('\u001b[1mflags:\u001b[0m')
|
|
||||||
print('add:')
|
|
||||||
print(' password/-p add a password entry')
|
|
||||||
print(' note/-n add a note entry')
|
|
||||||
print(' folder/-f add a new folder for entries')
|
|
||||||
print('edit:')
|
|
||||||
print(' rename/relocate/-r rename or relocate an entry')
|
|
||||||
print(' username/-u change the username of an entry')
|
|
||||||
print(' password/-p change the password of an entry')
|
|
||||||
print(' note/-n change the note attached to an entry')
|
|
||||||
print(' url/-l change the url attached to an entry')
|
|
||||||
print('copy:')
|
|
||||||
print(' username/-u copy the username of an entry to your clipboard')
|
|
||||||
print(' password/-p copy the password of an entry to your clipboard')
|
|
||||||
print(' url/-l copy the url of an entry to your clipboard')
|
|
||||||
print(' note/-n copy the note of an entry to your clipboard')
|
|
||||||
print('gen:')
|
|
||||||
print(' update/-u generate a password for an existing entry\n')
|
|
||||||
print("\u001b[1mtip:\u001b[0m you can quickly read an entry with 'sshyp /<entry name>'")
|
|
||||||
elif argument_list[0] == 'version' or argument_list[0] == '-v':
|
|
||||||
print('\nsshyp is a simple, self-hosted, sftp-synchronized password manager\nfor unix(-like) systems (haiku/'
|
|
||||||
'freebsd/linux/termux)\n\nsshyp is a viable alternative to (and compatible with) pass/password-store\n')
|
|
||||||
print(" .. \u001b[38;5;9m♥♥ ♥♥\u001b[0m ..\n .''.''/()\\ \u001b[38;5;13m"
|
|
||||||
"♥♥♥♥♥♥♥\u001b[0m /()\\''.''.\n * : \u001b[38;5;9m♥♥♥♥♥\u001b[0m : *"
|
|
||||||
"\n `..'..' \u001b[38;5;13m♥♥♥\u001b[0m `..'..'\n // \\\\ "
|
|
||||||
"\u001b[38;5;9m♥\u001b[0m // \\\\")
|
|
||||||
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m')
|
|
||||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
|
||||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
|
||||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8msshyp copyright (c) 2021-2022 '
|
|
||||||
'randall winkhart\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
|
||||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
|
||||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
|
||||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mversion 1.0.1'
|
|
||||||
'\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
|
||||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mthe polished trotters '
|
|
||||||
'update\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
|
||||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
|
||||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
|
||||||
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m\n')
|
|
||||||
print('see https://github.com/rwinkhart/sshyp for more information\n')
|
|
||||||
elif argument_list[0] == 'license':
|
|
||||||
print('\nThis program is free software: you can redistribute it and/or modify it under the terms of the GNU '
|
|
||||||
'General\nPublic License as published by the Free Software Foundation, either version 3 of the License,'
|
|
||||||
'\nor (at your option) any later version.\n\nThis program is distributed in the hope that it will be '
|
|
||||||
'useful, but WITHOUT ANY WARRANTY;\nwithout even the implied warranty of MERCHANTABILITY or FITNESS FOR A'
|
|
||||||
' PARTICULAR PURPOSE.\nSee the GNU General Public License for more details.'
|
|
||||||
'\n\nhttps://opensource.org/licenses/GPL-3.0\n')
|
|
||||||
elif argument_list[0] == 'add':
|
|
||||||
print('\n\u001b[1musage:\u001b[0m sshyp add [flag [<entry name>]]\u001b[0m\n')
|
|
||||||
print('\u001b[1mflags:\u001b[0m')
|
|
||||||
print('add:')
|
|
||||||
print(' password/-p add a password entry')
|
|
||||||
print(' note/-n add a note entry')
|
|
||||||
print(' folder/-f add a new folder for entries\n')
|
|
||||||
elif argument_list[0] == 'edit':
|
|
||||||
print('\n\u001b[1musage:\u001b[0m sshyp edit [flag [<entry name>]]\u001b[0m\n')
|
|
||||||
print('\u001b[1mflags:\u001b[0m')
|
|
||||||
print('edit:')
|
|
||||||
print(' rename/relocate/-r rename or relocate an entry')
|
|
||||||
print(' username/-u change the username of an entry')
|
|
||||||
print(' password/-p change the password of an entry')
|
|
||||||
print(' url/-l change the url attached to an entry')
|
|
||||||
print(' note/-n change the note attached to an entry\n')
|
|
||||||
elif argument_list[0] == 'copy':
|
|
||||||
print('\n\u001b[1musage:\u001b[0m sshyp copy [flag [<entry name>]]\u001b[0m\n')
|
|
||||||
print('\u001b[1mflags:\u001b[0m')
|
|
||||||
print('copy:')
|
|
||||||
print(' username/-u copy the username of an entry to your clipboard')
|
|
||||||
print(' password/-p copy the password of an entry to your clipboard')
|
|
||||||
print(' url/-l copy the url of an entry to your clipboard')
|
|
||||||
print(' note/-n copy the note of an entry to your clipboard\n')
|
|
||||||
|
|
||||||
|
|
||||||
def no_arg(): # displays a list of entries and gives an option to select one for viewing
|
|
||||||
print("\nfor a list of usable commands, run 'sshyp help'")
|
|
||||||
_entry_name = entry_name_fetch('entry to read: ')
|
|
||||||
if not Path(f"{directory}{_entry_name}.gpg").exists():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
|
||||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
|
||||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
|
||||||
|
|
||||||
|
|
||||||
def read_shortcut(): # shortcut to quickly read an entry
|
|
||||||
if not Path(f"{directory}{argument.replace('/', '', 1)}.gpg").exists():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({argument.replace('/', '', 1)}) does not exist\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
decrypt(directory + argument.replace('/', '', 1), _shm_folder, _shm_entry)
|
|
||||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
|
||||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
|
||||||
|
|
||||||
|
|
||||||
def sync(): # calls sshync to sync changes to the user's server
|
|
||||||
print('\nsyncing entries with the server device...\n')
|
|
||||||
# check for deletions
|
|
||||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /bin; python -c "
|
|
||||||
f"'import sshypRemote; sshypRemote.deletion_check(\"'\"{client_device_name}\"'\")'\"")
|
|
||||||
system(f"scp -pqs -P {port} -i '{path.expanduser('~/.ssh/sshyp')}' {username_ssh}@{ip}:'/home/{username_ssh}"
|
|
||||||
f"/.config/sshyp/deletion_database' {path.expanduser('~/.config/sshyp/')}")
|
|
||||||
try:
|
|
||||||
_deletion_database = open(path.expanduser('~/.config/sshyp/deletion_database')).readlines()
|
|
||||||
except (FileNotFoundError, IndexError):
|
|
||||||
print('\n\u001b[38;5;9merror: the deletion database does not exist or is corrupted\u001b[0m\n')
|
|
||||||
_deletion_database = None
|
|
||||||
s_exit(1)
|
|
||||||
for _file in _deletion_database:
|
|
||||||
if _file[:-1].endswith('/'):
|
|
||||||
try:
|
|
||||||
if silent_sync != 1:
|
|
||||||
print(f"\u001b[38;5;208m{_file[:-1]}\u001b[0m has been sheared, removing...")
|
|
||||||
rmtree(f"{path.expanduser('~/.password-pasture/')}{_file[:-1]}")
|
|
||||||
except FileNotFoundError:
|
|
||||||
if silent_sync != 1:
|
|
||||||
print('folder does not exist locally.')
|
|
||||||
else:
|
|
||||||
try:
|
|
||||||
if silent_sync != 1:
|
|
||||||
print(f"\u001b[38;5;208m{_file[:-1]}\u001b[0m has been sheared, removing...")
|
|
||||||
remove(f"{path.expanduser('~/.password-pasture/')}{_file[:-1]}.gpg")
|
|
||||||
except (FileNotFoundError, IsADirectoryError):
|
|
||||||
if silent_sync != 1:
|
|
||||||
print('file does not exist locally.')
|
|
||||||
# check for new folders
|
|
||||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /bin; python -c "
|
|
||||||
f"'import sshypRemote; sshypRemote.folder_check()'\"")
|
|
||||||
system(f"scp -pqs -P {port} -i '{path.expanduser('~/.ssh/sshyp')}' {username_ssh}@{ip}:'/home/{username_ssh}"
|
|
||||||
f"/.config/sshyp/folder_database' {path.expanduser('~/.config/sshyp/')}")
|
|
||||||
try:
|
|
||||||
_folder_database = open(path.expanduser('~/.config/sshyp/folder_database')).readlines()
|
|
||||||
except (FileNotFoundError, IndexError):
|
|
||||||
print('\n\u001b[38;5;9merror: the folder database does not exist or is corrupted\u001b[0m\n')
|
|
||||||
_folder_database = None
|
|
||||||
s_exit(1)
|
|
||||||
for _folder in _folder_database:
|
|
||||||
if Path(f"{path.expanduser('~')}{_folder[:-1]}").is_dir():
|
|
||||||
pass
|
|
||||||
else:
|
|
||||||
print(f"\u001b[38;5;2m{_folder.replace('/.password-pasture/', '')[:-1]}/\u001b[0m does not exist locally, "
|
|
||||||
f"creating...")
|
|
||||||
Path(f"{path.expanduser('~')}{_folder[:-1]}").mkdir(0o700, parents=True, exist_ok=True)
|
|
||||||
# set permissions before uploading
|
|
||||||
system('find ' + directory + ' -type d -exec chmod -R 700 {} +')
|
|
||||||
system('find ' + directory + ' -type f -exec chmod -R 600 {} +')
|
|
||||||
sshync.run_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'))
|
|
||||||
|
|
||||||
|
|
||||||
def add_entry(): # adds a new entry
|
|
||||||
_shm_folder, _shm_entry = None, None # sets base-line values to avoid errors
|
|
||||||
if len(argument_list) < 3:
|
|
||||||
_entry_name = entry_name_fetch('name of new entry: ')
|
|
||||||
else:
|
|
||||||
_entry_name = entry_name_fetch(2)
|
|
||||||
if Path(f"{directory}{_entry_name}.gpg").is_file():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) already exists\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
if argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
|
||||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
|
||||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines('\n\n\n' + _notes)
|
|
||||||
elif argument_list[1] == 'password' or argument_list[1] == '-p':
|
|
||||||
_username = str(input('username: '))
|
|
||||||
_password = str(input('password: '))
|
|
||||||
_url = str(input('url: '))
|
|
||||||
_add_note = input('add a note to this entry? (y/N) ')
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
if _add_note.lower() == 'y':
|
|
||||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
|
||||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
|
||||||
else:
|
|
||||||
_notes = ''
|
|
||||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_password + '\n' + _username + '\n' + _url +
|
|
||||||
'\n' + _notes)
|
|
||||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
|
||||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
|
||||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
|
||||||
|
|
||||||
|
|
||||||
def add_folder(): # creates a new folder
|
|
||||||
if len(argument_list) < 3:
|
|
||||||
_entry_name = entry_name_fetch('name of new folder: ')
|
|
||||||
else:
|
|
||||||
_entry_name = entry_name_fetch(2)
|
|
||||||
Path(directory + _entry_name).mkdir(0o700)
|
|
||||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"mkdir -p '{directory_ssh}"
|
|
||||||
f"{_entry_name}'\"")
|
|
||||||
|
|
||||||
|
|
||||||
def rename(): # renames an entry or folder
|
|
||||||
if argument == 'edit rename' or argument == 'edit relocate' or argument == 'edit -r':
|
|
||||||
_entry_name = entry_name_fetch('entry/folder to rename/relocate: ')
|
|
||||||
else:
|
|
||||||
_entry_name = entry_name_fetch(2)
|
|
||||||
if not Path(f"{directory}{_entry_name}.gpg").is_file() and not Path(f"{directory}{_entry_name}").is_dir():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
_new_name = str(input('new name: '))
|
|
||||||
print(f"{directory}{_new_name}")
|
|
||||||
if Path(f"{directory}{_new_name}.gpg").is_file() or Path(f"{directory}{_new_name}").is_dir():
|
|
||||||
print(f"\n\u001b[38;5;9merror: ({_new_name}) already exists\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
if _entry_name.endswith('/'):
|
|
||||||
move(f"{directory}{_entry_name}", f"{directory}{_new_name}")
|
|
||||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"mkdir -p '{directory_ssh}"
|
|
||||||
f"{_new_name}'\"")
|
|
||||||
else:
|
|
||||||
move(f"{directory}{_entry_name}.gpg", f"{directory}{_new_name}.gpg")
|
|
||||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /bin; python -c "
|
|
||||||
f"'import sshypRemote; sshypRemote.delete(\"'\"{_entry_name}\"'\")'\"")
|
|
||||||
|
|
||||||
|
|
||||||
def edit(): # edits the contents of an entry
|
|
||||||
_shm_folder, _shm_entry = None, None # sets base-line values to avoid errors
|
|
||||||
if len(argument_list) < 3:
|
|
||||||
_entry_name = entry_name_fetch('entry to edit: ')
|
|
||||||
else:
|
|
||||||
_entry_name = entry_name_fetch(2)
|
|
||||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
|
||||||
|
|
||||||
# compatibility check for GNU pass entries (ensuring they have at least four lines)
|
|
||||||
_lines = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines()
|
|
||||||
if len(_lines) < 3:
|
|
||||||
while len(_lines) < 3:
|
|
||||||
_lines.append('\n')
|
|
||||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_lines)
|
|
||||||
|
|
||||||
if argument_list[1] == 'username' or argument_list[1] == '-u':
|
|
||||||
_detail = str(input('new username: '))
|
|
||||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 1, _detail + '\n')
|
|
||||||
elif argument_list[1] == 'password' or argument_list[1] == '-p':
|
|
||||||
_detail = str(input('new password: '))
|
|
||||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 0, _detail + '\n')
|
|
||||||
elif argument_list[1] == 'url' or argument_list[1] == '-l':
|
|
||||||
_detail = str(input('new url: '))
|
|
||||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 2, _detail + '\n')
|
|
||||||
elif argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
edit_note(_shm_folder, _shm_entry)
|
|
||||||
remove(f"{directory}{_entry_name}.gpg")
|
|
||||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
|
||||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
|
||||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
|
||||||
|
|
||||||
|
|
||||||
def gen(): # generates a password for a new or an existing entry
|
|
||||||
_username, _url, _notes = None, None, None # sets base-line values to avoid errors
|
|
||||||
if argument == 'gen update' or argument == 'gen -u' or argument == 'gen':
|
|
||||||
_entry_name = entry_name_fetch('name of entry: ')
|
|
||||||
elif argument_list[1] == 'update' or argument_list[1] == '-u':
|
|
||||||
_entry_name = entry_name_fetch(2)
|
|
||||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
else:
|
|
||||||
_entry_name = entry_name_fetch(1)
|
|
||||||
if len(argument_list) == 1 or (not argument_list[1] == 'update' and not argument_list[1] == '-u'):
|
|
||||||
if Path(f"{directory}{_entry_name}.gpg").is_file():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) already exists\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
_username = str(input('username: '))
|
|
||||||
_password = pass_gen()
|
|
||||||
_url = str(input('url: '))
|
|
||||||
_add_note = input('add a note to this entry? (y/N) ')
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
if _add_note.lower() == 'y':
|
|
||||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
|
||||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
|
||||||
else:
|
|
||||||
_notes = ''
|
|
||||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_password + '\n' + _username + '\n' + _url + '\n'
|
|
||||||
+ _notes)
|
|
||||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
|
||||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
|
||||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
|
||||||
else:
|
|
||||||
_password = pass_gen()
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
|
||||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 0, _password + '\n')
|
|
||||||
remove(f"{directory}{_entry_name}.gpg")
|
|
||||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
|
||||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
|
||||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
|
||||||
|
|
||||||
|
|
||||||
def copy_data(): # copies a specified field of an entry to the clipboard
|
|
||||||
if len(argument_list) < 3:
|
|
||||||
_entry_name = entry_name_fetch('entry to copy: ')
|
|
||||||
else:
|
|
||||||
_entry_name = entry_name_fetch(2)
|
|
||||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
|
||||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
_shm_folder, _shm_entry = shm_gen()
|
|
||||||
decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
|
||||||
_copy_line = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines()
|
|
||||||
if uname()[0] == 'Haiku': # Haiku clipboard detection
|
|
||||||
if argument_list[1] == 'username' or argument_list[1] == '-u':
|
|
||||||
system('clipboard -c ' + "'" + _copy_line[1].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'password' or argument_list[1] == '-p':
|
|
||||||
system('clipboard -c ' + "'" + _copy_line[0].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'url' or argument_list[1] == '-l':
|
|
||||||
system('clipboard -c ' + "'" + _copy_line[2].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
system('clipboard -c ' + "'" + _copy_line[3].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
Popen('sleep 30; clipboard -r', shell=True, close_fds=True)
|
|
||||||
elif Path("/data/data/com.termux").exists(): # Termux (Android) clipboard detection
|
|
||||||
if argument_list[1] == 'username' or argument_list[1] == '-u':
|
|
||||||
system('termux-clipboard-set ' + "'" + _copy_line[1].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'password' or argument_list[1] == '-p':
|
|
||||||
system('termux-clipboard-set ' + "'" + _copy_line[0].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'url' or argument_list[1] == '-l':
|
|
||||||
system('termux-clipboard-set ' + "'" + _copy_line[2].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
system('termux-clipboard-set ' + "'" + _copy_line[3].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
Popen("sleep 30; termux-clipboard-set ''", shell=True, close_fds=True)
|
|
||||||
elif environ.get('WAYLAND_DISPLAY') == 'wayland-0': # Wayland clipboard detection
|
|
||||||
if argument_list[1] == 'username' or argument_list[1] == '-u':
|
|
||||||
system('wl-copy ' + "'" + _copy_line[1].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'password' or argument_list[1] == '-p':
|
|
||||||
system('wl-copy ' + "'" + _copy_line[0].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'url' or argument_list[1] == '-l':
|
|
||||||
system('wl-copy ' + "'" + _copy_line[2].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
elif argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
system('wl-copy ' + "'" + _copy_line[3].replace('\n', '').replace("'", "'\\''") + "'")
|
|
||||||
Popen('sleep 30; wl-copy -c', shell=True, close_fds=True)
|
|
||||||
else: # X11 clipboard detection
|
|
||||||
if argument_list[1] == 'username' or argument_list[1] == '-u':
|
|
||||||
system('echo -n ' + "'" + _copy_line[1].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
|
||||||
elif argument_list[1] == 'password' or argument_list[1] == '-p':
|
|
||||||
system('echo -n ' + "'" + _copy_line[0].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
|
||||||
elif argument_list[1] == 'url' or argument_list[1] == '-l':
|
|
||||||
system('echo -n ' + "'" + _copy_line[2].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
|
||||||
elif argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
system('echo -n ' + "'" + _copy_line[3].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
|
||||||
Popen("sleep 30; echo -n '' | xclip -sel c", shell=True, close_fds=True)
|
|
||||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
|
||||||
|
|
||||||
|
|
||||||
def remove_data(): # deletes an entry from the server and flags it for local deletion on sync
|
|
||||||
if argument == 'shear' or argument == '-rm':
|
|
||||||
_entry_name = entry_name_fetch('entry/folder to shear: ')
|
|
||||||
else:
|
|
||||||
_entry_name = entry_name_fetch(1)
|
|
||||||
decrypt(path.expanduser('~/.config/sshyp/lock.gpg'), 0, 0)
|
|
||||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /bin; python -c "
|
|
||||||
f"'import sshypRemote; sshypRemote.delete(\"'\"{_entry_name}\"'\")'\"")
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
try:
|
|
||||||
silent_sync, ssh_error = 0, 0
|
|
||||||
# retrieve typed argument
|
|
||||||
argument_list, argument = argv, ''
|
|
||||||
del argument_list[0]
|
|
||||||
for _argument in argument_list:
|
|
||||||
argument += _argument + ' '
|
|
||||||
argument = argument[:-1]
|
|
||||||
if uname()[0] == 'Haiku': # set proper gpg command for OS
|
|
||||||
gpg = 'gpg --pinentry-mode loopback'
|
|
||||||
else:
|
|
||||||
gpg = 'gpg'
|
|
||||||
|
|
||||||
# import saved userdata
|
|
||||||
if argument != 'tweak':
|
|
||||||
device_type = ''
|
|
||||||
tmp_dir = path.expanduser('~/.config/sshyp/tmp/')
|
|
||||||
try:
|
|
||||||
device_type = open(path.expanduser('~/.config/sshyp/sshyp-device')).read().strip()
|
|
||||||
if device_type == 'c':
|
|
||||||
ssh_info = sshync.get_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'))
|
|
||||||
username_ssh = ssh_info[0].replace('\n', '')
|
|
||||||
ip = ssh_info[1].replace('\n', '')
|
|
||||||
port = ssh_info[2].replace('\n', '')
|
|
||||||
directory = str(ssh_info[3].replace('\n', ''))
|
|
||||||
directory_ssh = '/home/' + username_ssh + '/.password-pasture/'
|
|
||||||
client_device_name = listdir(path.expanduser('~/.config/sshyp/devices'))[0]
|
|
||||||
gpg_id = open(path.expanduser('~/.config/sshyp/sshyp-gpg')).read().strip()
|
|
||||||
ssh_error = int(open(path.expanduser('~/.config/sshyp/ssh-error')).read().strip())
|
|
||||||
if ssh_error != 0:
|
|
||||||
ssh_error = copy_name_check(port, username_ssh, ip, client_device_name)
|
|
||||||
except (FileNotFoundError, IndexError):
|
|
||||||
if device_type.lower() != 's':
|
|
||||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
|
||||||
print("not all necessary configuration files are present - please run 'sshyp tweak'")
|
|
||||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
|
||||||
s_exit(1)
|
|
||||||
else:
|
|
||||||
tweak()
|
|
||||||
s_exit(0)
|
|
||||||
|
|
||||||
# run function based on arguments
|
|
||||||
if argument.startswith('/'):
|
|
||||||
read_shortcut()
|
|
||||||
elif argument == '':
|
|
||||||
no_arg()
|
|
||||||
elif argument == 'help' or argument == '--help' or argument == '-h' or argument == 'license' or argument \
|
|
||||||
== 'version' or argument == '-v':
|
|
||||||
print_info()
|
|
||||||
elif argument_list[0] == 'add':
|
|
||||||
if len(argument_list) == 1:
|
|
||||||
print_info()
|
|
||||||
elif argument_list[1] == 'note' or argument_list[1] == '-n' or argument_list[1] == 'password' or \
|
|
||||||
argument_list[1] == '-p':
|
|
||||||
add_entry()
|
|
||||||
elif argument_list[1] == 'folder' or argument_list[1] == '-f':
|
|
||||||
add_folder()
|
|
||||||
else:
|
|
||||||
print_info()
|
|
||||||
s_exit(0)
|
|
||||||
elif argument_list[0] == 'edit':
|
|
||||||
if len(argument_list) == 1:
|
|
||||||
print_info()
|
|
||||||
elif argument_list[1] == 'rename' or argument_list[1] == 'relocate' or argument_list[1] == '-r':
|
|
||||||
silent_sync = 1
|
|
||||||
rename()
|
|
||||||
elif argument_list[1] == 'username' or argument_list[1] == '-u' or argument_list[1] == 'password' or \
|
|
||||||
argument_list[1] == '-p' or argument_list[1] == 'url' or argument_list[1] == '-l' or \
|
|
||||||
argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
edit()
|
|
||||||
else:
|
|
||||||
print_info()
|
|
||||||
s_exit(0)
|
|
||||||
elif argument_list[0] == 'gen':
|
|
||||||
gen()
|
|
||||||
elif argument_list[0] == 'copy':
|
|
||||||
if len(argument_list) == 1:
|
|
||||||
print_info()
|
|
||||||
elif argument_list[1] == 'username' or argument_list[1] == '-u' or argument_list[1] == 'password' or \
|
|
||||||
argument_list[1] == '-p' or argument_list[1] == 'url' or argument_list[1] == '-l' or \
|
|
||||||
argument_list[1] == 'note' or argument_list[1] == '-n':
|
|
||||||
copy_data()
|
|
||||||
else:
|
|
||||||
print_info()
|
|
||||||
elif argument_list[0] == 'shear' or argument_list[0] == '-rm':
|
|
||||||
remove_data()
|
|
||||||
elif argument_list[0] != 'sync' and argument_list[0] != '-s':
|
|
||||||
print(f"\n\u001b[38;5;9merror: invalid argument - run 'sshyp help' to list usable commands\u001b[0m\n")
|
|
||||||
s_exit(1)
|
|
||||||
|
|
||||||
# sync if any changes were made
|
|
||||||
if len(argument_list) > 0 and ssh_error == 0 and \
|
|
||||||
((argument_list[0] == 'sync' or argument_list[0] == '-s' or argument_list[0] == 'gen' or
|
|
||||||
argument_list[0] == 'shear' or argument_list[0] == '-rm') or ((argument_list[0] == 'add'
|
|
||||||
or argument_list[0] == 'edit')
|
|
||||||
and len(argument_list) > 1)):
|
|
||||||
sync()
|
|
||||||
|
|
||||||
s_exit(0)
|
|
||||||
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
print('\n')
|
|
||||||
s_exit(0)
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
#!/bin/python3
|
|
||||||
|
|
||||||
# external modules
|
|
||||||
|
|
||||||
from os import listdir, remove, walk
|
|
||||||
from os.path import expanduser
|
|
||||||
from shutil import rmtree
|
|
||||||
|
|
||||||
|
|
||||||
# utility functions
|
|
||||||
|
|
||||||
def delete(_file_path):
|
|
||||||
if _file_path.endswith('/'):
|
|
||||||
try:
|
|
||||||
rmtree(f"{expanduser('~/.password-pasture/')}{_file_path}")
|
|
||||||
except FileNotFoundError:
|
|
||||||
print('folder does not exist remotely')
|
|
||||||
else:
|
|
||||||
try:
|
|
||||||
remove(f"{expanduser('~/.password-pasture/')}{_file_path}.gpg")
|
|
||||||
except FileNotFoundError:
|
|
||||||
print('file does not exist remotely')
|
|
||||||
for _device_name in listdir(expanduser('~/.config/sshyp/devices')):
|
|
||||||
open(f"{expanduser('~/.config/sshyp/deleted/')}{_file_path.replace('/', '@')}^&*{_device_name}", 'w')
|
|
||||||
|
|
||||||
|
|
||||||
def deletion_check(_client_device_name):
|
|
||||||
open(expanduser('~/.config/sshyp/deletion_database'), 'w').write('')
|
|
||||||
for _file in listdir(expanduser('~/.config/sshyp/deleted')):
|
|
||||||
_file_path = _file.replace('@', '/').split('^&*')[0]
|
|
||||||
_device = _file.split('^&*')[1]
|
|
||||||
if _device == _client_device_name:
|
|
||||||
try:
|
|
||||||
remove(f"{expanduser('~/.config/sshyp/deleted/')}{_file}")
|
|
||||||
except FileNotFoundError:
|
|
||||||
pass
|
|
||||||
open(expanduser('~/.config/sshyp/deletion_database'), 'a').write(_file_path + '\n')
|
|
||||||
|
|
||||||
|
|
||||||
def folder_check():
|
|
||||||
open(expanduser('~/.config/sshyp/folder_database'), 'w').write('')
|
|
||||||
for _root, _directories, _files in walk(expanduser('~/.password-pasture')):
|
|
||||||
for _dir in _directories:
|
|
||||||
open(expanduser('~/.config/sshyp/folder_database'), 'a')\
|
|
||||||
.write(f"{_root.replace(expanduser('~'), '')}/{_dir}\n")
|
|
||||||
Executable → Regular
+187
@@ -1,3 +1,190 @@
|
|||||||
|
sshyp v1.3.0
|
||||||
|
|
||||||
|
the serious shepherd update
|
||||||
|
|
||||||
|
this release ties up many of sshyp's loose ends where there was
|
||||||
|
room for major performance, compatibility, and security improvements
|
||||||
|
|
||||||
|
compatibility-breaking changes:
|
||||||
|
|
||||||
|
- due to a near full re-write of the syncing functionality, all clients and servers
|
||||||
|
must be updated to this release (v1.3.0 is not backwards compatible with any prior release)
|
||||||
|
- it is recommended to either delete the contents of ~/.config/sshyp/deleted (on the server-side)
|
||||||
|
or sync all of your clients before updating
|
||||||
|
^ old entries in this folder will throw errors with v1.3.0
|
||||||
|
|
||||||
|
user-facing features:
|
||||||
|
|
||||||
|
- none - all changes were under-the-hood - the user experience should be
|
||||||
|
exactly the same as v1.2.0 - just faster, less buggy, and more secure
|
||||||
|
|
||||||
|
major fixes/optimizations:
|
||||||
|
|
||||||
|
- a near full re-write of the syncing functionality
|
||||||
|
^ all syncing logic has been moved into sshync.py (from sshyp.py and sshypRemote.py)
|
||||||
|
^ in my setup, a dry, local "sshyp sync" went from 2.00+ seconds (v1.2.0) to 0.36 seconds (v1.3.0)
|
||||||
|
^ the performance improvements are even greater when syncing from outside your local network
|
||||||
|
- the following character sequences will no longer break the syncing logic: "@", "^&*", and "*&^"
|
||||||
|
^ ASCII separator characters 29-31 are now used, instead
|
||||||
|
- os.system has been replaced with subprocess.run in all cases, shell=True is no longer used with subprocess.run
|
||||||
|
^ this protects against shell escape attacks and potentially makes sshyp more compatible with some environments
|
||||||
|
- replaced shell commands with python built-in library functions where applicable
|
||||||
|
^ this brings speed and compatibility improvements
|
||||||
|
- sshyp should no longer incorrectly assume an X11 environment when Wayland is in use
|
||||||
|
^ this fixes clipboard support in some Wayland environments, such as Sway (Plasma/Gnome/Phosh were unaffected)
|
||||||
|
- sshyp now uses the default pinentry on Haiku thanks to haikuports/haikuports#7457
|
||||||
|
^ this brings the Haiku port in-line with the other sshyp packages in terms of security
|
||||||
|
- "python3" is now called over ssh, rather than "python"
|
||||||
|
^ some environments do not have a "python" symlink, or it links to "python2" - changing this increases compatibility
|
||||||
|
- fixed an issue from v1.2.0 where renaming threw an error if not in offline mode
|
||||||
|
|
||||||
|
other notable changes:
|
||||||
|
|
||||||
|
- quick-unlock password input is now hidden while the user is typing
|
||||||
|
^ user input is now invisible to prevent snooping
|
||||||
|
- lots of smaller optimizations not listed here
|
||||||
|
|
||||||
|
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||||
|
|
||||||
|
sshyp v1.2.0
|
||||||
|
|
||||||
|
the brisk bahh update
|
||||||
|
|
||||||
|
this release focuses on speeding up the sshyp user experience by adding
|
||||||
|
new features that reduce wasted time
|
||||||
|
|
||||||
|
compatibility-breaking changes:
|
||||||
|
|
||||||
|
- new configuration options (quick-unlock, offline mode) have been added and
|
||||||
|
the configuration files have been reorganized
|
||||||
|
^ simply running "sshyp tweak" and following the setup wizard will correct any compatibility
|
||||||
|
issues
|
||||||
|
- for quick-unlock security, device names have been replaced with more secure device ids
|
||||||
|
^ older device names are still compatible, but for security reasons it is recommended
|
||||||
|
to delete any pre-existing device names from the server and allow "sshyp tweak" to re-register
|
||||||
|
your devices
|
||||||
|
|
||||||
|
user-facing features:
|
||||||
|
|
||||||
|
- quick-unlock mode has been added
|
||||||
|
^ this allows you to use a shortened version of your password by verifying that your device
|
||||||
|
is whitelisted on your sshyp server - it's both faster and more secure than standard unlock,
|
||||||
|
but it requires an active connection to your sshyp server to authenticate (otherwise it will
|
||||||
|
fall back to standard unlock)
|
||||||
|
- full support for offline usage
|
||||||
|
^ though sshyp could be used without a server before, it now can be configured to not attempt
|
||||||
|
to find one ever - this saves time and hides sync failure error messages
|
||||||
|
- bash completions have been added
|
||||||
|
^ if you have bash-completion installed, you can now use the tab key in bash to auto-complete
|
||||||
|
sshyp arguments and entry names (client only, not added for server-specific arguments)
|
||||||
|
^ if you do not have bash-completion installed, you can source
|
||||||
|
/usr/share/bash-completion/completions/sshyp (Linux/BSD) or
|
||||||
|
/boot/system/data/bash-completion/completions/sshyp (Haiku) in your ~/.bashrc to
|
||||||
|
use this feature
|
||||||
|
|
||||||
|
fixes/optimizations:
|
||||||
|
|
||||||
|
- fixed entries with multi-word titles failing to decrypt
|
||||||
|
- password generation is now much faster and more resource efficient
|
||||||
|
- there is no longer a length limit on generated passwords
|
||||||
|
- improved visual consistency of help menus
|
||||||
|
- rarely used modules are now imported only when needed
|
||||||
|
- sshyp now uses one fewer configuration file
|
||||||
|
|
||||||
|
other notable changes:
|
||||||
|
|
||||||
|
- sshyp is now specifically licensed under the GPL-3.0-only (keyword: only)
|
||||||
|
- sshyp now has some possible arguments and its own help menu when running in server mode
|
||||||
|
- temporary files in /dev/shm are now generated with more complex names
|
||||||
|
- sshyp now installs in /usr/lib/sshyp (Linux/BSD) or /system/lib/sshyp (Haiku) instead of
|
||||||
|
/usr/bin or /bin (it is still symlinked to the old directories)
|
||||||
|
|
||||||
|
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||||
|
|
||||||
|
sshyp v1.1.2
|
||||||
|
|
||||||
|
the sheecrets update - patch two
|
||||||
|
|
||||||
|
this is a general polish/bugfix release
|
||||||
|
|
||||||
|
user-facing features:
|
||||||
|
|
||||||
|
- packaging support for Alpine Linux/postmarketOS
|
||||||
|
- the rename() function is no longer unnecessarily verbose
|
||||||
|
- handled exception for when the user attempts to copy an entry field that does not exist
|
||||||
|
|
||||||
|
fixes/optimizations:
|
||||||
|
|
||||||
|
- replaced shebang with "#!/usr/bin/env python3" for improved compatibility with various systems
|
||||||
|
^ does not affect Haiku packaging
|
||||||
|
- fixed the generic package not actually being compressed
|
||||||
|
- reduced lines of code used for cross-device entry deletion
|
||||||
|
|
||||||
|
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||||
|
|
||||||
|
sshyp v1.1.1
|
||||||
|
|
||||||
|
the sheecrets update - patch one
|
||||||
|
|
||||||
|
this is a polish/bug fix release that makes tweaks to the entry format (without breaking compatibility)
|
||||||
|
|
||||||
|
compatibility-breaking changes:
|
||||||
|
|
||||||
|
- none; the entry format tweaks are backward compatible with sshyp v1.0.0+
|
||||||
|
^ the new format is slightly more efficient in terms of storage space
|
||||||
|
^ if you would like to upgrade to it, run this script (after updating to v1.1.1):
|
||||||
|
https://raw.githubusercontent.com/rwinkhart/sshyp-labs/main/extra/conversion-scripts/sshyp-refresh-1.1.1%2B.py
|
||||||
|
|
||||||
|
user-facing features:
|
||||||
|
|
||||||
|
- entries (when editing or adding) are now run through the new optimized_edit() function to strip trailing new lines
|
||||||
|
and ensure the format of the entries is fully compatible with all of sshyp's functions
|
||||||
|
|
||||||
|
fixes:
|
||||||
|
|
||||||
|
- when adding a note to an entry, there is no longer a chance the first note line will be added as a url
|
||||||
|
if the entry is using an older format/pass format
|
||||||
|
- the gpg auto-generation file temporarily created by sshyp no longer includes extra spaces
|
||||||
|
^ seems to serve no functional purpose - fixed for the sake of polish
|
||||||
|
|
||||||
|
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||||
|
|
||||||
|
sshyp v1.1.0
|
||||||
|
|
||||||
|
the sheecrets update
|
||||||
|
|
||||||
|
the main focus of this release was adding extension support (particularly for sshyp-mfa)
|
||||||
|
and cleaning up the configuration experience
|
||||||
|
|
||||||
|
compatibility-breaking changes:
|
||||||
|
|
||||||
|
- the entry directory has been moved from ~/.password-pasture to ~/.local/share/sshyp
|
||||||
|
as a means of complying with the XDG base directory spec
|
||||||
|
^ this requires the user to move their entry directory to the new location manually
|
||||||
|
^ if this is not done, sshyp will not be able to find entries made prior to v1.1.0
|
||||||
|
- due to a new configuration option (preferred text editor), 'sshyp tweak' must be run after updating
|
||||||
|
|
||||||
|
user-facing features:
|
||||||
|
|
||||||
|
- extension support
|
||||||
|
^ some of sshyp's critical functions can now be imported into other programs to extend
|
||||||
|
upon sshyp's functionality
|
||||||
|
^ the first usecase of this is sshyp-mfa, which can be found at https://github.com/rwinkhart/sshyp-labs
|
||||||
|
- a new configuration experience
|
||||||
|
^ the 'sshyp tweak' menu has been made much more readable, and now the automatically generated
|
||||||
|
gpg key has its id automatically input, making the process easier for the user
|
||||||
|
- customizable text editor
|
||||||
|
^ the text editor used for editing notes can now be set to any editor preferred by the user
|
||||||
|
^ this means that nano was dropped as a dependency
|
||||||
|
|
||||||
|
fixes:
|
||||||
|
|
||||||
|
- to avoid exceptions on server devices, all arguments (apart from 'tweak') have been disabled on servers
|
||||||
|
- fixed entry readout not printing blank lines between fields under certain conditions
|
||||||
|
- various optimizations
|
||||||
|
|
||||||
|
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||||
|
|
||||||
sshyp v1.0.1
|
sshyp v1.0.1
|
||||||
|
|
||||||
The Polished Trotters Update - Patch 1
|
The Polished Trotters Update - Patch 1
|
||||||
|
|||||||
+69
-32
@@ -1,41 +1,52 @@
|
|||||||
.TH sshyp 1 "20 June 2022" "v1.0.0" "sshyp man page"
|
.TH sshyp 1 "14 December 2022" "v1.3.0" "sshyp man page"
|
||||||
.SH NAME
|
.SH NAME
|
||||||
sshyp \- A very simple self-hosted, synchronized password manager for UNIX(-like) systems. Alternative to (and compatible with) pass/password-store.
|
sshyp \- A very simple self-hosted, synchronized password manager for UNIX(-like) systems. Alternative to (and compatible with) pass/password-store.
|
||||||
.SH SYNOPSIS
|
.SH SYNOPSIS
|
||||||
sshyp [OPTION] [[FLAG]] [/<entry name>]
|
Client Usage: sshyp [option [flag] [<entry name>]] | [/<entry name>]
|
||||||
|
|
||||||
|
Server Usage: sshyp [option [flag] [<device id>]]
|
||||||
.SH DESCRIPTION
|
.SH DESCRIPTION
|
||||||
sshyp is a lightweight password and note management program written in Python. sshyp is used via CLI and is self-hosted with a client-server model. sshyp expects that you have access to a personal server with a properly configured ssh server, ideally accepting remote connections.
|
sshyp is a lightweight password and note management program written in Python. sshyp is used via CLI and is self-hosted with a client-server model. sshyp expects that you have access to a personal server with a properly configured ssh server, ideally accepting remote connections.
|
||||||
.SH EXAMPLES
|
.SH EXAMPLES (CLIENT)
|
||||||
Setting up sshyp for the first time or altering its configuration (also recommended after major updates):
|
Setting up sshyp for the first time or altering its configuration (also recommended after major updates):
|
||||||
sshyp tweak
|
sshyp tweak
|
||||||
|
|
||||||
Viewing the entry database:
|
Viewing the entry database:
|
||||||
sshyp
|
sshyp
|
||||||
|
|
||||||
Reading an existing entry saved as ~/.password-pasture/development/github.gpg:
|
Reading an existing entry saved as ~/.local/share/sshyp/development/github.gpg:
|
||||||
sshyp /development/github
|
sshyp /development/github
|
||||||
|
|
||||||
Copying the password of an existing entry saved as ~/.password-pasture/financial/bank.gpg:
|
Copying the password of an existing entry saved as ~/.local/share/sshyp/financial/bank.gpg:
|
||||||
sshyp copy -p /financial/bank
|
sshyp copy -p /financial/bank
|
||||||
|
|
||||||
Editing the username of an existing entry saved as ~/.password-pasture/game.gpg:
|
Editing the username of an existing entry saved as ~/.local/share/sshyp/game.gpg:
|
||||||
sshyp edit -u game
|
sshyp edit -u game
|
||||||
|
|
||||||
Making a new entry saved as ~/.password-pasture/school/university.gpg using the built-in password generator:
|
Making a new entry saved as ~/.local/share/sshyp/school/university.gpg using the built-in password generator:
|
||||||
sshyp gen /school/university
|
sshyp gen /school/university
|
||||||
|
|
||||||
Creating a note-only entry saved as ~/.password-pasture/notes/testNote.gpg:
|
Creating a note-only entry saved as ~/.local/share/sshyp/notes/testNote.gpg:
|
||||||
sshyp add -n /notes/testNote
|
sshyp add -n /notes/testNote
|
||||||
|
|
||||||
Manually syncing entries with the server:
|
Manually syncing entries with the server:
|
||||||
sshyp sync
|
sshyp sync
|
||||||
|
|
||||||
Removing an existing folder saved as ~/.password-pasture/social:
|
Removing an existing folder saved as ~/.local/share/sshyp/social:
|
||||||
sshyp shear social/
|
sshyp shear social/
|
||||||
|
.SH EXAMPLES (SERVER)
|
||||||
|
Setting up the quick-unlock whitelist:
|
||||||
|
sshyp whitelist setup
|
||||||
|
|
||||||
.SH OPTIONS
|
Checking the quick-unlock whitelist status of all registered client devices:
|
||||||
USAGE: sshyp [OPTION [FLAG] [<entry name>]] | [/<entry name>]
|
sshyp whitelist list
|
||||||
|
|
||||||
|
Adding a device with the id "laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_" to the quick-unlock whitelist:
|
||||||
|
sshyp whitelist add 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_'
|
||||||
|
|
||||||
|
Removing a device with the id "laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_" from the quick-unlock whitelist:
|
||||||
|
sshyp whitelist del 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_'
|
||||||
|
.SH OPTIONS (CLIENT)
|
||||||
help/--help/-h bring up the help menu
|
help/--help/-h bring up the help menu
|
||||||
version/-v display sshyp version info
|
version/-v display sshyp version info
|
||||||
tweak configure sshyp
|
tweak configure sshyp
|
||||||
@@ -45,38 +56,49 @@ USAGE: sshyp [OPTION [FLAG] [<entry name>]] | [/<entry name>]
|
|||||||
copy copy details of an entry to your clipboard
|
copy copy details of an entry to your clipboard
|
||||||
shear/-rm delete an existing entry
|
shear/-rm delete an existing entry
|
||||||
sync/-s manually sync the entry directory via sshync
|
sync/-s manually sync the entry directory via sshync
|
||||||
.SH FLAGS
|
.SH FLAGS (CLIENT)
|
||||||
add:
|
add:
|
||||||
password/-p add a password entry
|
password/-p add a password entry
|
||||||
note/-n add a note entry
|
note/-n add a note entry
|
||||||
folder/-f add a new folder for entries
|
folder/-f add a new folder for entries
|
||||||
edit:
|
|
||||||
rename/relocate/-r rename or relocate an entry
|
|
||||||
username/-u change the username of an entry
|
|
||||||
password/-p change the password of an entry
|
|
||||||
note/-n change the note attached to an entry
|
|
||||||
url/-l change the url attached to an entry
|
|
||||||
copy:
|
|
||||||
username/-u copy the username of an entry to your clipboard
|
|
||||||
password/-p copy the password of an entry to your clipboard
|
|
||||||
url/-l copy the URL of an entry to your clipboard
|
|
||||||
note/-n copy the note of an entry to your clipboard
|
|
||||||
gen:
|
|
||||||
update/-u generate a password for an existing entry
|
|
||||||
.SH LIMITATIONS
|
|
||||||
The following characters/character sequences are not supported in entry/folder titles:
|
|
||||||
|
|
||||||
@ ^&* *&^
|
edit:
|
||||||
|
rename/relocate/-r rename or relocate an entry
|
||||||
|
username/-u change the username of an entry
|
||||||
|
password/-p change the password of an entry
|
||||||
|
note/-n change the note attached to an entry
|
||||||
|
url/-l change the url attached to an entry
|
||||||
|
|
||||||
|
copy:
|
||||||
|
username/-u copy the username of an entry to your clipboard
|
||||||
|
password/-p copy the password of an entry to your clipboard
|
||||||
|
url/-l copy the URL of an entry to your clipboard
|
||||||
|
note/-n copy the note of an entry to your clipboard
|
||||||
|
|
||||||
|
gen:
|
||||||
|
update/-u generate a password for an existing entry
|
||||||
|
.SH OPTIONS (SERVER)
|
||||||
|
help/--help/-h bring up this menu
|
||||||
|
version/-v display sshyp version info
|
||||||
|
tweak configure sshyp
|
||||||
|
whitelist manage the quick-unlock whitelist
|
||||||
|
.SH FLAGS (SERVER)
|
||||||
|
whitelist:
|
||||||
|
setup set up the quick-unlock whitelist
|
||||||
|
list/-l view all registered device ids and their quick-unlock whitelist status
|
||||||
|
add whitelist a device id for quick-unlock
|
||||||
|
delete/del remove a device id from the quick-unlock whitelist
|
||||||
.SH SETUP
|
.SH SETUP
|
||||||
sshyp operates on a client-server model, and thus requires you to have access to your own server (whether it be a physical home server or a cloud rental) with remote access via SSH.
|
sshyp operates on a client-server model, and thus requires you to have access to your own server (whether it be a physical home server or a cloud rental) with remote access via SSH.
|
||||||
|
|
||||||
The sshyp package includes modes for operating on both client and server devices, so only one package is necessary.
|
The sshyp package includes modes for operating on both client and server devices, so only one package is necessary.
|
||||||
|
|
||||||
Server setup:
|
Server setup:
|
||||||
Configure an OpenSSH server (if sshyp was installed from the Debian package, the ssh server was not installed as a dependency and needs to be installed manually)
|
Configure an OpenSSH server (if sshyp was installed from the Debian package, openssh-server and openssh-sftp-server must be installed manually - if sshyp was installed from the Fedora package, openssh-server must be installed manually)
|
||||||
Allow remote access to the SSH server w/public key authentication (disabling password-only authentication recommended)
|
Allow remote access to the SSH server w/public key authentication (disabling password-only authentication recommended)
|
||||||
Install sshyp
|
Install sshyp
|
||||||
Run "sshyp tweak" and set the device type as server
|
Run "sshyp tweak" and set the device type as server
|
||||||
|
Optionally, run "sshyp whitelist setup" and configure quick-unlock
|
||||||
Done!
|
Done!
|
||||||
|
|
||||||
Client setup:
|
Client setup:
|
||||||
@@ -84,8 +106,23 @@ Client setup:
|
|||||||
Run "sshyp tweak" and follow the prompts
|
Run "sshyp tweak" and follow the prompts
|
||||||
Copy the generated public SSH key (located at ~/.ssh/sshyp.pub) to the server using preferred method (manually adding to authorized_keys, ssh-copy-id, etc.)
|
Copy the generated public SSH key (located at ~/.ssh/sshyp.pub) to the server using preferred method (manually adding to authorized_keys, ssh-copy-id, etc.)
|
||||||
If you already have entries on the server, sync them using "sshyp sync"
|
If you already have entries on the server, sync them using "sshyp sync"
|
||||||
|
Optionally, Bash completions can be enabled by installing your distribution's "bash-completion" package and restarting your terminal
|
||||||
Done!
|
Done!
|
||||||
|
|
||||||
Please note that the server setup intentionally does not allow the reading of entries (it does not allow adding a gpg decryption key). For security purposes, only clients can read entries.
|
Please note that the server setup intentionally does not allow the reading of entries (it does not allow adding a gpg decryption key). For security purposes, only clients can read entries.
|
||||||
|
.SH EXIT CODES
|
||||||
|
0 - no error
|
||||||
|
|
||||||
|
1 - argument error
|
||||||
|
|
||||||
|
2 - configuration error
|
||||||
|
|
||||||
|
3 - data not found error
|
||||||
|
|
||||||
|
4 - data already exists error
|
||||||
|
|
||||||
|
5 - decryption/encryption error
|
||||||
|
|
||||||
|
6 - server connection error
|
||||||
.SH AUTHOR
|
.SH AUTHOR
|
||||||
Randall Winkhart (https://github.com/rwinkhart)
|
Randall Winkhart (https://github.com/rwinkhart)
|
||||||
|
|||||||
Executable
+50
@@ -0,0 +1,50 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
_path_gen() {
|
||||||
|
local sshyp_path="$HOME/.local/share/sshyp"
|
||||||
|
local sshyp_path_length="$(("${#sshyp_path}" + 1))"
|
||||||
|
readarray -t full_paths < <(find "$sshyp_path" -type f -exec ls {} \;)
|
||||||
|
for path in "${full_paths[@]}"; do
|
||||||
|
trimmed_path=$(echo ${path%????} | cut -c"$sshyp_path_length"-)
|
||||||
|
trimmed_path=$(echo ${trimmed_path// /\\ })
|
||||||
|
trimmed_paths+=("$trimmed_path")
|
||||||
|
done
|
||||||
|
} &&
|
||||||
|
|
||||||
|
# from this point, this completions script was partially generated by
|
||||||
|
# completely (https://github.com/dannyben/completely)
|
||||||
|
|
||||||
|
_sshyp_completions() {
|
||||||
|
if [ "${#COMP_WORDS[@]}" -gt "4" ]; then
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
local cur=${COMP_WORDS[COMP_CWORD]}
|
||||||
|
local compline="${COMP_WORDS[@]:1:$COMP_CWORD-1}"
|
||||||
|
|
||||||
|
case "$compline" in
|
||||||
|
'add password'* | 'add -p'* | 'add note'* | 'add -n'* | 'add folder'*| 'add -f'* | 'edit relocate'* | 'edit -r'* | 'edit username'* | 'edit -u'* | 'edit password'* | 'edit -p'* | 'edit url'* | 'edit -l'* | 'edit note'* | 'edit -n'* | 'copy username'* | 'copy -u'* | 'copy password'* | 'copy -p'* | 'copy note'* | 'copy -n'* | 'copy url'* | 'copy -l'* | 'gen update'* | 'gen -u'*)
|
||||||
|
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "$(printf "'%s' " "${trimmed_paths[@]}")" -- "$cur" )
|
||||||
|
;;
|
||||||
|
|
||||||
|
'edit'*)
|
||||||
|
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "relocate username password note url" -- "$cur" )
|
||||||
|
;;
|
||||||
|
|
||||||
|
'copy'*)
|
||||||
|
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "username password url note" -- "$cur" )
|
||||||
|
;;
|
||||||
|
|
||||||
|
'add'*)
|
||||||
|
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "password note folder" -- "$cur" )
|
||||||
|
;;
|
||||||
|
|
||||||
|
'gen'*)
|
||||||
|
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "update" -- "$cur" )
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "help version tweak add gen edit copy shear sync $(printf "'%s' " "${trimmed_paths[@]}")" -- "$cur" )
|
||||||
|
;;
|
||||||
|
|
||||||
|
esac
|
||||||
|
} &&
|
||||||
|
_path_gen && complete -F _sshyp_completions sshyp
|
||||||
@@ -1,48 +0,0 @@
|
|||||||
#!/bin/python3
|
|
||||||
|
|
||||||
from os import path, remove, system, walk
|
|
||||||
from pathlib import Path
|
|
||||||
from shutil import move, rmtree
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
gpg_id = input('\nWhat is the ID of the GPG key you would like to use for re-encryption?\n\nID: ')
|
|
||||||
pasture = path.expanduser('~/.password-pasture')
|
|
||||||
if Path(f"{pasture}.new").exists():
|
|
||||||
rmtree(f"{pasture}.new")
|
|
||||||
if Path(f"{pasture}.old").exists():
|
|
||||||
rmtree(f"{pasture}.old")
|
|
||||||
if path.isdir(pasture):
|
|
||||||
for dirPath, dirNames, filenames in walk(pasture):
|
|
||||||
for filename in sorted(filenames):
|
|
||||||
Path(dirPath.replace(pasture, pasture + '.new')).mkdir(0o700, parents=True, exist_ok=True)
|
|
||||||
system(f"gpg -d '{dirPath}/{filename}' "
|
|
||||||
f"> '{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}'")
|
|
||||||
_old_contents, _new_contents = \
|
|
||||||
open(f"{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}", 'r').readlines(), ''
|
|
||||||
for _num in range(len(_old_contents)):
|
|
||||||
if _num == 0:
|
|
||||||
try:
|
|
||||||
_new_contents += _old_contents[1]
|
|
||||||
except IndexError:
|
|
||||||
_new_contents += '\n'
|
|
||||||
elif _num == 1:
|
|
||||||
_new_contents += _old_contents[0]
|
|
||||||
elif _num == 3:
|
|
||||||
if _old_contents[_num] == ' ' or _old_contents[_num] == '\n':
|
|
||||||
pass
|
|
||||||
else:
|
|
||||||
_new_contents += _old_contents[_num]
|
|
||||||
else:
|
|
||||||
_new_contents += _old_contents[_num]
|
|
||||||
for _num in reversed(range(len(_new_contents))):
|
|
||||||
if _new_contents[_num] == '\n' or _new_contents[_num] == '':
|
|
||||||
_new_contents = _new_contents[:-1]
|
|
||||||
else:
|
|
||||||
break
|
|
||||||
open(f"{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}", 'w').writelines(_new_contents)
|
|
||||||
system(f"gpg -qr {str(gpg_id)} -e '{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}'")
|
|
||||||
remove(f"{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}")
|
|
||||||
else:
|
|
||||||
print(f"\nError: no entry folder ({pasture}) found\n")
|
|
||||||
move(pasture, f"{pasture}.old")
|
|
||||||
move(f"{pasture}.new", pasture)
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
af6236472791614ed41bf13318a2d1c41228855c
|
|
||||||
@@ -1,41 +0,0 @@
|
|||||||
#!/bin/python3
|
|
||||||
|
|
||||||
from os import path, remove, system, walk
|
|
||||||
from pathlib import Path
|
|
||||||
from shutil import move, rmtree
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
gpg_id = input('\nWhat is the ID of the GPG key you would like to use for re-encryption?\n\nID: ')
|
|
||||||
pasture = path.expanduser('~/.password-pasture')
|
|
||||||
if Path(f"{pasture}.new").exists():
|
|
||||||
rmtree(f"{pasture}.new")
|
|
||||||
if Path(f"{pasture}.old").exists():
|
|
||||||
rmtree(f"{pasture}.old")
|
|
||||||
if path.isdir(pasture):
|
|
||||||
for dirPath, dirNames, filenames in walk(pasture):
|
|
||||||
for filename in sorted(filenames):
|
|
||||||
Path(dirPath.replace(pasture, pasture + '.new')).mkdir(0o700, parents=True, exist_ok=True)
|
|
||||||
system(f"gpg -d '{dirPath}/{filename}' "
|
|
||||||
f"> '{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}'")
|
|
||||||
_old_contents, _new_contents = \
|
|
||||||
open(f"{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}", 'r').readlines(), ''
|
|
||||||
for _num in range(len(_old_contents)):
|
|
||||||
if _num == 3:
|
|
||||||
if _old_contents[_num] == ' ' or _old_contents[_num] == '\n':
|
|
||||||
pass
|
|
||||||
else:
|
|
||||||
_new_contents += _old_contents[_num]
|
|
||||||
else:
|
|
||||||
_new_contents += _old_contents[_num]
|
|
||||||
for _num in reversed(range(len(_new_contents))):
|
|
||||||
if _new_contents[_num] == '\n' or _new_contents[_num] == '':
|
|
||||||
_new_contents = _new_contents[:-1]
|
|
||||||
else:
|
|
||||||
break
|
|
||||||
open(f"{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}", 'w').writelines(_new_contents)
|
|
||||||
system(f"gpg -qr {str(gpg_id)} -e '{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}'")
|
|
||||||
remove(f"{dirPath.replace(pasture, pasture + '.new')}/{filename[:-4]}")
|
|
||||||
else:
|
|
||||||
print(f"\nError: no entry folder ({pasture}) found\n")
|
|
||||||
move(pasture, f"{pasture}.old")
|
|
||||||
move(f"{pasture}.new", pasture)
|
|
||||||
Executable
+168
@@ -0,0 +1,168 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
from os import listdir, remove, walk
|
||||||
|
from os.path import expanduser, getmtime, join
|
||||||
|
from subprocess import CalledProcessError, PIPE, run
|
||||||
|
from sys import exit as s_exit
|
||||||
|
|
||||||
|
|
||||||
|
# REMOTE
|
||||||
|
|
||||||
|
def remote_list_gen(_client_device_name, _remote_dir): # prints all necessary remote data to stdout
|
||||||
|
# deletions
|
||||||
|
for _file in listdir(expanduser('~/.config/sshyp/deleted')):
|
||||||
|
_file_path, _sep, _device = _file.partition('\x1f')
|
||||||
|
_file_path = _file_path.replace('\x1e', '/')
|
||||||
|
if _device == _client_device_name:
|
||||||
|
print(_file_path)
|
||||||
|
try:
|
||||||
|
remove(f"{expanduser('~/.config/sshyp/deleted/')}{_file}")
|
||||||
|
except FileNotFoundError:
|
||||||
|
pass
|
||||||
|
print('\x1d')
|
||||||
|
# folders
|
||||||
|
for _root, _directories, _files in walk(expanduser('~/.local/share/sshyp')):
|
||||||
|
for _dir in _directories:
|
||||||
|
print(f"{_root.replace(expanduser('~'), '')}/{_dir}")
|
||||||
|
print('\x1d')
|
||||||
|
get_local_data(_remote_dir, 'server') # titles and mod times
|
||||||
|
|
||||||
|
|
||||||
|
# HYBRID
|
||||||
|
|
||||||
|
def delete(_file_path, _target_database): # deletes a file or folder and/or marks it for deletion upon syncing
|
||||||
|
from shutil import rmtree
|
||||||
|
try:
|
||||||
|
if _file_path.endswith('/'):
|
||||||
|
rmtree(f"{expanduser('~/.local/share/sshyp/')}{_file_path}")
|
||||||
|
else:
|
||||||
|
remove(f"{expanduser('~/.local/share/sshyp/')}{_file_path}.gpg")
|
||||||
|
except FileNotFoundError:
|
||||||
|
print(f"location does not exist {_target_database}")
|
||||||
|
if _target_database == 'remotely':
|
||||||
|
for _device_name in listdir(expanduser('~/.config/sshyp/devices')):
|
||||||
|
open(expanduser('~/.config/sshyp/deleted/') + _file_path.replace('/', '\x1e') + '\x1f' + _device_name, 'w')
|
||||||
|
|
||||||
|
|
||||||
|
def get_local_data(_directory, _device): # retrieves and returns titles and mod times from the local device
|
||||||
|
_title_list, _mod_list = [], []
|
||||||
|
for _root, _directories, _files in walk(_directory):
|
||||||
|
for _filename in _files:
|
||||||
|
_title_list.append(join(_root.replace(_directory, '', 1), _filename))
|
||||||
|
_mod_list.append(int(getmtime(join(_root, _filename))))
|
||||||
|
if _device == 'server':
|
||||||
|
for _title in _title_list:
|
||||||
|
print(_title.rstrip())
|
||||||
|
for _time in _mod_list:
|
||||||
|
print(_time)
|
||||||
|
return _title_list, _mod_list
|
||||||
|
|
||||||
|
|
||||||
|
# LOCAL
|
||||||
|
|
||||||
|
def remote_list_fetch(_user_data): # captures and returns all necessary data from the remote server
|
||||||
|
try:
|
||||||
|
_remote_data = run(['ssh', '-i', _user_data[5], '-p', _user_data[2], f"{_user_data[0]}@{_user_data[1]}",
|
||||||
|
f'cd /lib/sshyp; python3 -c \'from sshync import remote_list_gen; remote_list_gen'
|
||||||
|
f'("{_user_data[6]}", "{_user_data[4]}")\''], stdout=PIPE, text=True, check=True
|
||||||
|
).stdout.split('\x1d')
|
||||||
|
except CalledProcessError:
|
||||||
|
print('\n\u001b[38;5;9merror: failed to connect to the remote server\u001b[0m\n')
|
||||||
|
_remote_data = ''
|
||||||
|
s_exit(6)
|
||||||
|
_deletion_database = _remote_data[0].strip().split('\n')
|
||||||
|
_folder_database = _remote_data[1].strip().split('\n')
|
||||||
|
_titles_mods = _remote_data[2].strip().split('\n')
|
||||||
|
return _deletion_database, _folder_database, _titles_mods[:len(_titles_mods)//2], \
|
||||||
|
_titles_mods[len(_titles_mods)//2:]
|
||||||
|
|
||||||
|
|
||||||
|
def deletion_sync(_deletion_database, _silent): # checks for and acts upon files and folders marked for deletion
|
||||||
|
for _file in _deletion_database:
|
||||||
|
if _file != '':
|
||||||
|
if _silent != 1:
|
||||||
|
print(f"\u001b[38;5;208m{_file}\u001b[0m has been sheared, removing...")
|
||||||
|
delete(_file, 'locally')
|
||||||
|
|
||||||
|
|
||||||
|
def folder_sync(_folder_database): # creates matches of remote folders on the local client
|
||||||
|
from pathlib import Path
|
||||||
|
for _folder in _folder_database:
|
||||||
|
if _folder != '' and not Path(f"{expanduser('~')}{_folder}").is_dir():
|
||||||
|
print(f"\u001b[38;5;2m{_folder.replace('/.local/share/sshyp/', '')}/\u001b[0m does not exist locally, "
|
||||||
|
f"creating...")
|
||||||
|
Path(f"{expanduser('~')}{_folder}").mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||||
|
|
||||||
|
|
||||||
|
def sort_titles_mods(_list_1, _list_2): # creates and returns two lists (of titles and mod times) generated by sorting
|
||||||
|
# information from two provided 2D lists
|
||||||
|
_title_list_2_sorted, _mod_list_2_sorted = [], []
|
||||||
|
# title sorting
|
||||||
|
for _title in _list_1[0]:
|
||||||
|
if _title in _list_2[0]:
|
||||||
|
_title_list_2_sorted.append(_title)
|
||||||
|
for _title in _list_2[0]:
|
||||||
|
if _title not in _title_list_2_sorted:
|
||||||
|
_title_list_2_sorted.append(_title)
|
||||||
|
# mod time sorting
|
||||||
|
for _title in _title_list_2_sorted:
|
||||||
|
_mod_list_2_sorted.append(_list_2[1][_list_2[0].index(_title)])
|
||||||
|
return _title_list_2_sorted, _mod_list_2_sorted
|
||||||
|
|
||||||
|
|
||||||
|
def make_profile(_profile_dir, _local_dir, _remote_dir, _identity, _ip, _port, _user): # creates a sshync job profile
|
||||||
|
open(_profile_dir, 'w').write(f"{_user}\n{_ip}\n{_port}\n{_local_dir}\n{_remote_dir}\n{_identity}\n")
|
||||||
|
|
||||||
|
|
||||||
|
def get_profile(_profile_dir): # returns a list of data read from a sshync job profile
|
||||||
|
try:
|
||||||
|
_profile_data = open(_profile_dir).readlines()
|
||||||
|
except (FileNotFoundError, IndexError):
|
||||||
|
print('\n\u001b[38;5;9merror: the profile does not exist or is corrupted\u001b[0m\n')
|
||||||
|
_profile_data = None
|
||||||
|
s_exit(3)
|
||||||
|
_user = _profile_data[0].rstrip()
|
||||||
|
_ip = _profile_data[1].rstrip()
|
||||||
|
_port = _profile_data[2].rstrip()
|
||||||
|
_local_dir = _profile_data[3].rstrip()
|
||||||
|
_remote_dir = _profile_data[4].rstrip()
|
||||||
|
_identity = _profile_data[5].rstrip()
|
||||||
|
_client_device_id = listdir(expanduser('~/.config/sshyp/devices'))[0].rstrip()
|
||||||
|
return _user, _ip, _port, _local_dir, _remote_dir, _identity, _client_device_id
|
||||||
|
|
||||||
|
|
||||||
|
def run_profile(_profile_dir, _silent): # runs a sshync job profile
|
||||||
|
_user_data = get_profile(_profile_dir) # import profile data
|
||||||
|
# fetch remote lists
|
||||||
|
_deletion_database, _folder_database, _remote_titles, _remote_mods = remote_list_fetch(_user_data)
|
||||||
|
_remote_titles_mods = (_remote_titles, _remote_mods)
|
||||||
|
# sync deletions and folders
|
||||||
|
deletion_sync(_deletion_database, _silent)
|
||||||
|
folder_sync(_folder_database)
|
||||||
|
# sort titles and mods
|
||||||
|
_index_local = sort_titles_mods(_remote_titles_mods, get_local_data(_user_data[3], 'client'))
|
||||||
|
_index_remote = sort_titles_mods(_index_local, _remote_titles_mods)
|
||||||
|
# sync new and updated files
|
||||||
|
_i = -1
|
||||||
|
for _title in _index_local[0]:
|
||||||
|
_i += 1
|
||||||
|
if _title in _index_remote[0]:
|
||||||
|
# compare mod times and sync
|
||||||
|
if int(_index_local[1][_i]) > int(_index_remote[1][_i]):
|
||||||
|
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is newer locally, uploading...")
|
||||||
|
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5], _user_data[3] + _title,
|
||||||
|
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||||
|
elif int(_index_local[1][_i]) < int(_index_remote[1][_i]):
|
||||||
|
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is newer remotely, downloading...")
|
||||||
|
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5],
|
||||||
|
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{_title}",
|
||||||
|
f"{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||||
|
else:
|
||||||
|
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is not on remote server, uploading...")
|
||||||
|
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5], _user_data[3] + _title,
|
||||||
|
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||||
|
for _title in _index_remote[0]:
|
||||||
|
if _title not in _index_local[0]:
|
||||||
|
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is not in local directory, downloading...")
|
||||||
|
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5],
|
||||||
|
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{_title}",
|
||||||
|
f"{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||||
Executable
+911
@@ -0,0 +1,911 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
from os import chmod, environ, listdir, remove, uname, walk
|
||||||
|
from os.path import expanduser
|
||||||
|
from pathlib import Path
|
||||||
|
from random import randint
|
||||||
|
from shutil import get_terminal_size, move, rmtree
|
||||||
|
from sshync import delete as offline_delete, run_profile, make_profile, get_profile
|
||||||
|
from subprocess import CalledProcessError, DEVNULL, PIPE, run
|
||||||
|
from sys import argv, exit as s_exit
|
||||||
|
|
||||||
|
|
||||||
|
# UTILITY FUNCTIONS
|
||||||
|
|
||||||
|
def entry_list_gen(_directory=expanduser('~/.local/share/sshyp/')): # generates and prints full entry list
|
||||||
|
from textwrap import fill
|
||||||
|
print('\n\u001b[38;5;0;48;5;15msshyp entries:\u001b[0m\n')
|
||||||
|
_entry_list, _color_alternator = [], 1
|
||||||
|
for _entry in sorted(listdir(_directory)):
|
||||||
|
if Path(f"{_directory}{_entry}").is_file():
|
||||||
|
if _color_alternator == 1:
|
||||||
|
_entry_list.append(f"{_entry.replace('.gpg', '')}")
|
||||||
|
_color_alternator = 2
|
||||||
|
else:
|
||||||
|
_entry_list.append(f"\u001b[38;5;8m{_entry.replace('.gpg', '')}\u001b[0m")
|
||||||
|
_color_alternator = 1
|
||||||
|
_real = len(' '.join(_entry_list)) - (5.5 * len(_entry_list))
|
||||||
|
if _real <= get_terminal_size()[0]:
|
||||||
|
_width = len(' '.join(_entry_list))
|
||||||
|
else:
|
||||||
|
_width = (len(' '.join(_entry_list)) / (_real / get_terminal_size()[0]) - 25)
|
||||||
|
try:
|
||||||
|
print(fill(' '.join(_entry_list), width=_width) + '\n')
|
||||||
|
except ValueError:
|
||||||
|
pass
|
||||||
|
for _root, _dirs, _files in walk(_directory):
|
||||||
|
for _dir in sorted(_dirs):
|
||||||
|
_inner_dir = f"{_root.replace(_directory, '')}/{_dir}"
|
||||||
|
print(f"\u001b[38;5;15;48;5;238m{_inner_dir}/\u001b[0m")
|
||||||
|
_entry_list, _color_alternator = [], 1
|
||||||
|
for _s_root, _s_directories, _s_files in walk(f"{_directory[:-1]}{_inner_dir}"):
|
||||||
|
for _entry in sorted(_s_files):
|
||||||
|
if _color_alternator == 1:
|
||||||
|
_entry_list.append(f"{_entry.replace('.gpg', '')}")
|
||||||
|
_color_alternator = 2
|
||||||
|
else:
|
||||||
|
_entry_list.append(f"\u001b[38;5;8m{_entry.replace('.gpg', '')}\u001b[0m")
|
||||||
|
_color_alternator = 1
|
||||||
|
_real = len(' '.join(_entry_list)) - (5.5 * len(_entry_list))
|
||||||
|
if _real <= get_terminal_size()[0]:
|
||||||
|
_width = len(' '.join(_entry_list))
|
||||||
|
else:
|
||||||
|
_width = (len(' '.join(_entry_list)) / (_real / get_terminal_size()[0]) - 25)
|
||||||
|
try:
|
||||||
|
print(fill(' '.join(_entry_list), width=_width) + '\n')
|
||||||
|
except ValueError:
|
||||||
|
print('\u001b[38;5;9m-empty directory-\u001b[0m\n')
|
||||||
|
|
||||||
|
|
||||||
|
def entry_reader(_decrypted_entry): # displays the contents of an entry in a readable format
|
||||||
|
_entry_lines, _notes_flag = open(_decrypted_entry, 'r').readlines(), 0
|
||||||
|
print()
|
||||||
|
for _num in range(len(_entry_lines)):
|
||||||
|
try:
|
||||||
|
if _num == 0 and _entry_lines[1] != '\n':
|
||||||
|
print(f"\u001b[38;5;15;48;5;238musername:\u001b[0m\n{_entry_lines[1].strip()}\n")
|
||||||
|
elif _num == 1 and _entry_lines[0] != '\n':
|
||||||
|
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0].strip()}\n")
|
||||||
|
elif _num == 2 and _entry_lines[2] != '\n':
|
||||||
|
print(f"\u001b[38;5;15;48;5;238murl:\u001b[0m\n{_entry_lines[_num].strip()}\n")
|
||||||
|
elif _num >= 3 and _entry_lines[_num] != '\n' and _notes_flag != 1:
|
||||||
|
_notes_flag = 1
|
||||||
|
print(f"\u001b[38;5;15;48;5;238mnotes:\u001b[0m\n{_entry_lines[_num].strip()}")
|
||||||
|
elif _num >= 3 and _notes_flag == 1:
|
||||||
|
print(_entry_lines[_num].replace('\n', ''))
|
||||||
|
if _notes_flag == 1:
|
||||||
|
try:
|
||||||
|
_line_test = _entry_lines[_num + 1]
|
||||||
|
except IndexError:
|
||||||
|
print()
|
||||||
|
except IndexError:
|
||||||
|
if _num == 0:
|
||||||
|
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0]}\n")
|
||||||
|
|
||||||
|
|
||||||
|
def entry_name_fetch(_entry_name_location): # fetches and returns entry name from user input or from provided argument
|
||||||
|
if type(_entry_name_location) == str:
|
||||||
|
entry_list_gen()
|
||||||
|
_entry_name = str(input(_entry_name_location))
|
||||||
|
else:
|
||||||
|
_entry_name_split = argument.split(' ')
|
||||||
|
del _entry_name_split[:_entry_name_location]
|
||||||
|
_entry_name = ' '.join(_entry_name_split)
|
||||||
|
if _entry_name.startswith('/'):
|
||||||
|
return _entry_name.replace('/', '', 1)
|
||||||
|
else:
|
||||||
|
return _entry_name.strip()
|
||||||
|
|
||||||
|
|
||||||
|
def string_gen(_complexity, _length): # generates and returns a random string based on input
|
||||||
|
from random import SystemRandom
|
||||||
|
import string
|
||||||
|
if _complexity == 's':
|
||||||
|
_character_pool = string.ascii_letters + string.digits
|
||||||
|
elif _complexity == 'f':
|
||||||
|
_character_pool = string.digits + string.ascii_letters + string.punctuation.replace('/', '').replace('\\', '')\
|
||||||
|
.replace("'", '').replace('"', '').replace('`', '').replace('~', '')
|
||||||
|
else:
|
||||||
|
_character_pool = string.digits + string.ascii_letters + string.punctuation
|
||||||
|
_min_special, _special = round(.2 * _length), 0
|
||||||
|
while True:
|
||||||
|
_gen = ''.join(SystemRandom().choice(_character_pool) for _ in range(_length))
|
||||||
|
for _character in _gen:
|
||||||
|
if not _character.isalpha():
|
||||||
|
_special += 1
|
||||||
|
if _special >= _min_special:
|
||||||
|
break
|
||||||
|
return _gen
|
||||||
|
|
||||||
|
|
||||||
|
def pass_gen(): # prompts the user for necessary information to generate a password and passes it to string_gen
|
||||||
|
_length = 9
|
||||||
|
while True:
|
||||||
|
try:
|
||||||
|
_length = int(input('password length: '))
|
||||||
|
except ValueError:
|
||||||
|
continue
|
||||||
|
else:
|
||||||
|
if _length < 1:
|
||||||
|
continue
|
||||||
|
else:
|
||||||
|
break
|
||||||
|
_complexity = str(input('password complexity - simple (for compatibility) or complex (for security)? (s/C) '))
|
||||||
|
if _complexity != 's' and _complexity != 'S':
|
||||||
|
_complexity = 'c'
|
||||||
|
_gen = string_gen(_complexity.lower(), _length)
|
||||||
|
return _gen
|
||||||
|
|
||||||
|
|
||||||
|
def shm_gen(_tmp_dir=expanduser('~/.config/sshyp/tmp/')): # creates a temporary directory for entry editing
|
||||||
|
_shm_folder_gen = string_gen('f', randint(12, 48))
|
||||||
|
_shm_entry_gen = string_gen('f', randint(12, 48))
|
||||||
|
Path(_tmp_dir + _shm_folder_gen).mkdir(mode=0o700)
|
||||||
|
return _shm_folder_gen, _shm_entry_gen
|
||||||
|
|
||||||
|
|
||||||
|
def encrypt(_entry_dir, _shm_folder, _shm_entry, _gpg_id, _tmp_dir=expanduser('~/.config/sshyp/tmp/')):
|
||||||
|
# encrypts an entry and cleans up the temporary files
|
||||||
|
run(['gpg', '-qr', str(_gpg_id), '-e', f"{_tmp_dir}{_shm_folder}/{_shm_entry}"])
|
||||||
|
move(f"{_tmp_dir}{_shm_folder}/{_shm_entry}.gpg", f"{_entry_dir}.gpg")
|
||||||
|
rmtree(f"{_tmp_dir}{_shm_folder}")
|
||||||
|
|
||||||
|
|
||||||
|
def decrypt(_entry_dir, _shm_folder, _shm_entry, _quick_pass,
|
||||||
|
_tmp_dir=expanduser('~/.config/sshyp/tmp/')): # decrypts an entry to a temporary directory
|
||||||
|
if not isinstance(_quick_pass, bool):
|
||||||
|
_unlock_method = ['gpg', '--pinentry-mode', 'loopback', '--passphrase', _quick_pass, '-qd', '--output']
|
||||||
|
else:
|
||||||
|
_unlock_method = ['gpg', '-qd', '--output']
|
||||||
|
if _shm_folder == 0 and _shm_entry == 0:
|
||||||
|
_output_target = ['/dev/null', expanduser('~/.config/sshyp/lock.gpg')]
|
||||||
|
else:
|
||||||
|
_output_target = [f"{_tmp_dir}{_shm_folder}/{_shm_entry}", f"{_entry_dir}.gpg"]
|
||||||
|
try:
|
||||||
|
run(_unlock_method + _output_target, stderr=DEVNULL, check=True)
|
||||||
|
except CalledProcessError:
|
||||||
|
if not isinstance(_quick_pass, bool):
|
||||||
|
print('\n\u001b[38;5;9merror: quick-unlock failed as a result of an incorrect passphrase, an unreachable '
|
||||||
|
'sshyp server, or an invalid configuration\n\nfalling back to standard unlock\u001b[0m\n')
|
||||||
|
try:
|
||||||
|
run(['gpg', '-qd', '--output'] + _output_target, stderr=DEVNULL, check=True)
|
||||||
|
except CalledProcessError:
|
||||||
|
print('\n\u001b[38;5;9merror: could not decrypt - ensure the correct gpg key is present\u001b[0m\n')
|
||||||
|
s_exit(5)
|
||||||
|
else:
|
||||||
|
print('\n\u001b[38;5;9merror: could not decrypt - ensure the correct gpg key is present\u001b[0m\n')
|
||||||
|
s_exit(5)
|
||||||
|
|
||||||
|
|
||||||
|
def determine_decrypt(_entry_dir, _shm_folder, _shm_entry):
|
||||||
|
if quick_unlock_enabled == 'y':
|
||||||
|
decrypt(_entry_dir, _shm_folder, _shm_entry, whitelist_verify(port, username_ssh, ip, client_device_id))
|
||||||
|
else:
|
||||||
|
decrypt(_entry_dir, _shm_folder, _shm_entry, False)
|
||||||
|
|
||||||
|
|
||||||
|
def optimized_edit(_lines, _edit_data, _edit_line): # ensures an edited entry is optimized for best compatibility
|
||||||
|
while len(_lines) < _edit_line + 1:
|
||||||
|
_lines += ['\n']
|
||||||
|
if _edit_data is not None:
|
||||||
|
_lines[_edit_line] = _edit_data.strip('\n').rstrip() + '\n'
|
||||||
|
for _num in range(len(_lines)):
|
||||||
|
if not _lines[_num].endswith('\n'):
|
||||||
|
_lines[_num] += '\n'
|
||||||
|
for _num in reversed(range(len(_lines))):
|
||||||
|
if _lines[_num] == '\n':
|
||||||
|
_lines = _lines[:-1]
|
||||||
|
elif _lines[_num].endswith('\n'):
|
||||||
|
_lines[_num] = _lines[_num].rstrip()
|
||||||
|
break
|
||||||
|
else:
|
||||||
|
break
|
||||||
|
return _lines
|
||||||
|
|
||||||
|
|
||||||
|
def edit_note(_shm_folder, _shm_entry, _lines): # edits the note attached to an entry
|
||||||
|
_reg_lines = _lines[0:3]
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'w').writelines(_lines[3:])
|
||||||
|
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||||
|
_new_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n").readlines()
|
||||||
|
while len(_reg_lines) < 3:
|
||||||
|
_reg_lines += ['\n']
|
||||||
|
_noted_lines = _reg_lines + _new_notes
|
||||||
|
return _noted_lines
|
||||||
|
|
||||||
|
|
||||||
|
def copy_id_check(_port, _username_ssh, _ip, _client_device_id):
|
||||||
|
# attempts to connect to the user's server via ssh to register the device for syncing
|
||||||
|
try:
|
||||||
|
run(['ssh', '-o', 'ConnectTimeout=3', '-i', expanduser('~/.ssh/sshyp'), '-p', _port, f"{_username_ssh}@{_ip}",
|
||||||
|
f'python3 -c \'from pathlib import Path; Path("/home/{_username_ssh}/.config/sshyp/devices/'
|
||||||
|
f'{_client_device_id}").touch(mode=0o400, exist_ok=True)\''], stderr=DEVNULL, check=True)
|
||||||
|
except CalledProcessError:
|
||||||
|
print('\n\u001b[38;5;9mwarning: ssh connection could not be made - ensure the public key (~/.ssh/sshyp.pub) is '
|
||||||
|
'registered on the remote server and that the entered ip, port, and username are correct\n\nsyncing '
|
||||||
|
'functionality will be disabled until this is addressed\u001b[0m\n')
|
||||||
|
open(expanduser('~/.config/sshyp/ssh-error'), 'w').write('1')
|
||||||
|
return 1
|
||||||
|
open(expanduser('~/.config/sshyp/ssh-error'), 'w').write('0')
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
# ARGUMENT-SPECIFIC FUNCTIONS
|
||||||
|
|
||||||
|
def tweak(): # runs configuration wizard
|
||||||
|
from os import symlink
|
||||||
|
_divider = f"\n{'=' * (get_terminal_size()[0] - int((.5 * get_terminal_size()[0])))}\n\n"
|
||||||
|
|
||||||
|
# config directory creation
|
||||||
|
Path(expanduser('~/.config/sshyp/devices')).mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||||
|
if not Path(f"{expanduser('~/.config/sshyp/tmp')}").exists():
|
||||||
|
if uname()[0] == 'Haiku' or uname()[0] == 'FreeBSD':
|
||||||
|
symlink('/tmp', expanduser('~/.config/sshyp/tmp'))
|
||||||
|
elif Path("/data/data/com.termux").exists():
|
||||||
|
symlink('/data/data/com.termux/files/usr/tmp', expanduser('~/.config/sshyp/tmp'))
|
||||||
|
else:
|
||||||
|
symlink('/dev/shm', expanduser('~/.config/sshyp/tmp'))
|
||||||
|
|
||||||
|
# device type configuration
|
||||||
|
_device_type = input('\nclient or server installation? (C/s) ')
|
||||||
|
if _device_type.lower() == 's':
|
||||||
|
_sshyp_data = ['server']
|
||||||
|
Path(expanduser('~/.config/sshyp/deleted')).mkdir(mode=0o700, exist_ok=True)
|
||||||
|
Path(expanduser('~/.config/sshyp/whitelist')).mkdir(mode=0o700, exist_ok=True)
|
||||||
|
print(f"\n\u001b[4;1mmake sure the ssh service is running and properly configured\u001b[0m")
|
||||||
|
else:
|
||||||
|
_sshyp_data = ['client']
|
||||||
|
Path(expanduser('~/.local/share/sshyp')).mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||||
|
|
||||||
|
# gpg configuration
|
||||||
|
_gpg_gen = input(f"{_divider}sshyp requires the use of a unique gpg key - use an (e)xisting key or (g)enerate a"
|
||||||
|
f" new one? (E/g) ")
|
||||||
|
if _gpg_gen.lower() != 'g':
|
||||||
|
run(['gpg', '-k'])
|
||||||
|
_sshyp_data += [str(input('gpg key id: '))]
|
||||||
|
else:
|
||||||
|
print('\na unique gpg key is being generated for you...')
|
||||||
|
if not Path(expanduser('~/.config/sshyp/gpg-gen')).is_file():
|
||||||
|
open(expanduser('~/.config/sshyp/gpg-gen'), 'w').writelines([
|
||||||
|
'Key-Type: 1\n', 'Key-Length: 4096\n', 'Key-Usage: sign encrypt\n', 'Name-Real: sshyp\n',
|
||||||
|
'Name-Comment: gpg-sshyp\n', 'Name-Email: https://github.com/rwinkhart/sshyp\n', 'Expire-Date: 0'])
|
||||||
|
run(['gpg', '--batch', '--generate-key', expanduser('~/.config/sshyp/gpg-gen')])
|
||||||
|
remove(expanduser('~/.config/sshyp/gpg-gen'))
|
||||||
|
_sshyp_data += [run(['gpg', '-k'], stdout=PIPE, text=True).stdout.split('\n')[-4].strip()]
|
||||||
|
|
||||||
|
# text editor configuration
|
||||||
|
_sshyp_data += [input(f"{_divider}example input: vim\n\npreferred text editor: ")]
|
||||||
|
|
||||||
|
# lock file generation
|
||||||
|
if Path(expanduser('~/.config/sshyp/lock.gpg')).is_file():
|
||||||
|
remove(expanduser('~/.config/sshyp/lock.gpg'))
|
||||||
|
open(expanduser('~/.config/sshyp/lock'), 'w')
|
||||||
|
run(['gpg', '-qr', str(_sshyp_data[1]), '-e', expanduser('~/.config/sshyp/lock')])
|
||||||
|
remove(expanduser('~/.config/sshyp/lock'))
|
||||||
|
|
||||||
|
# ssh key configuration
|
||||||
|
_offline_mode = False
|
||||||
|
_ssh_gen = (input(f"{_divider}make sure the ssh service on the remote server is running and properly "
|
||||||
|
f"configured\n\nsync support requires a unique ssh key - would you like to have this "
|
||||||
|
f"automatically generated? (Y/n/o(ffline)) "))
|
||||||
|
if _ssh_gen.lower() != 'n' and _ssh_gen.lower() != 'o' and _ssh_gen.lower() != 'offline':
|
||||||
|
Path(f"{expanduser('~')}/.ssh").mkdir(mode=0o700, exist_ok=True)
|
||||||
|
run(['ssh-keygen', '-t', 'ed25519', '-f', expanduser('~/.ssh/sshyp')])
|
||||||
|
elif _ssh_gen.lower() == 'n':
|
||||||
|
print(f"\n\u001b[4;1mensure that the key file you are using is located at "
|
||||||
|
f"{expanduser('~/.ssh/sshyp')}\u001b[0m")
|
||||||
|
elif _ssh_gen.lower() == 'o' or _ssh_gen.lower() == 'offline':
|
||||||
|
_offline_mode = True
|
||||||
|
print('\nsshyp has been set to offline mode - to enable syncing, run "sshyp tweak" again')
|
||||||
|
|
||||||
|
if not _offline_mode:
|
||||||
|
# ssh ip+port configuration
|
||||||
|
_ip_port = str(input(f"{_divider}example input: 10.10.10.10:9999\n\nip and ssh port of sshyp server: "))
|
||||||
|
_ip, _sep, _port = _ip_port.partition(':')
|
||||||
|
|
||||||
|
# ssh user configuration
|
||||||
|
_username_ssh = str(input('\nusername of the remote server: '))
|
||||||
|
|
||||||
|
# sshync profile generation
|
||||||
|
make_profile(expanduser('~/.config/sshyp/sshyp.sshync'),
|
||||||
|
expanduser('~/.local/share/sshyp/'), f"/home/{_username_ssh}/.local/share/sshyp/",
|
||||||
|
expanduser('~/.ssh/sshyp'), _ip, _port, _username_ssh)
|
||||||
|
|
||||||
|
# device id configuration
|
||||||
|
for _id in listdir(expanduser('~/.config/sshyp/devices')): # remove existing device id
|
||||||
|
remove(f"{expanduser('~/.config/sshyp/devices/')}{_id}")
|
||||||
|
print(f"{_divider}\u001b[4;1mimportant:\u001b[0m this id \u001b[4;1mmust\u001b[0m be unique amongst your "
|
||||||
|
f"client devices\n\nthis is used to keep track of database syncing and quick-unlock permissions\n")
|
||||||
|
_device_id_prefix = str(input('device id: ')) + '-'
|
||||||
|
_device_id_suffix = string_gen('f', randint(24, 48))
|
||||||
|
_device_id = _device_id_prefix + _device_id_suffix
|
||||||
|
open(f"{expanduser('~/.config/sshyp/devices/')}{_device_id}", 'w')
|
||||||
|
|
||||||
|
# quick-unlock configuration
|
||||||
|
print(f"{_divider}this allows you to use a shorter version of your gpg key password and\n"
|
||||||
|
f"requires a constant connection to your sshyp server to authenticate")
|
||||||
|
_sshyp_data += [input('\nenable quick-unlock? (y/N) ').lower()]
|
||||||
|
if _sshyp_data[3] == 'y':
|
||||||
|
print(f"\nquick-unlock has been enabled client-side - in order for this device to be able to read "
|
||||||
|
f"entries,\nyou must first login to the sshyp server and run:\n\nsshyp whitelist setup "
|
||||||
|
f"(if not already done)\nsshyp whitelist add '{_device_id}'")
|
||||||
|
|
||||||
|
# test server connection and attempt to register device id
|
||||||
|
copy_id_check(_port, _username_ssh, _ip, _device_id)
|
||||||
|
|
||||||
|
elif Path(expanduser('~/.config/sshyp/sshyp.sshync')).is_file():
|
||||||
|
remove(expanduser('~/.config/sshyp/sshyp.sshync'))
|
||||||
|
|
||||||
|
# write main config file (sshyp-data)
|
||||||
|
with open(expanduser('~/.config/sshyp/sshyp-data'), 'w') as _config_file:
|
||||||
|
_lines = 0
|
||||||
|
for _item in _sshyp_data:
|
||||||
|
_lines += 1
|
||||||
|
_config_file.write(_item + '\n')
|
||||||
|
while _lines < 4:
|
||||||
|
_lines += 1
|
||||||
|
_config_file.write('n')
|
||||||
|
print(f"{_divider}configuration complete\n")
|
||||||
|
|
||||||
|
|
||||||
|
def print_info(): # prints help text based on argument
|
||||||
|
if argument_list[1] == 'help' or argument_list[1] == '--help' or argument_list[1] == '-h':
|
||||||
|
print('\n\u001b[1msshyp copyright (c) 2021-2022 randall winkhart\u001b[0m\n')
|
||||||
|
print("this is free software, and you are welcome to redistribute it under certain conditions;\nthis program "
|
||||||
|
"comes with absolutely no warranty;\ntype 'sshyp license' for details")
|
||||||
|
if device_type == 'client':
|
||||||
|
print('\n\u001b[1musage:\u001b[0m sshyp [option [flag] [<entry name>]] | [/<entry name>]\n')
|
||||||
|
print('\u001b[1moptions:\u001b[0m')
|
||||||
|
print('help/--help/-h bring up this menu')
|
||||||
|
print('version/-v display sshyp version info')
|
||||||
|
print('tweak configure sshyp')
|
||||||
|
print('add add an entry')
|
||||||
|
print('gen generate a new password')
|
||||||
|
print('edit edit an existing entry')
|
||||||
|
print('copy copy details of an entry to your clipboard')
|
||||||
|
print('shear/-rm delete an existing entry')
|
||||||
|
print('sync/-s manually sync the entry directory via sshync')
|
||||||
|
print('\n\u001b[1mflags:\u001b[0m')
|
||||||
|
print('add:')
|
||||||
|
print(' password/-p add a password entry')
|
||||||
|
print(' note/-n add a note entry')
|
||||||
|
print(' folder/-f add a new folder for entries')
|
||||||
|
print('edit:')
|
||||||
|
print(' rename/relocate/-r rename or relocate an entry')
|
||||||
|
print(' username/-u change the username of an entry')
|
||||||
|
print(' password/-p change the password of an entry')
|
||||||
|
print(' url/-l change the url attached to an entry')
|
||||||
|
print(' note/-n change the note attached to an entry')
|
||||||
|
print('copy:')
|
||||||
|
print(' username/-u copy the username of an entry to your clipboard')
|
||||||
|
print(' password/-p copy the password of an entry to your clipboard')
|
||||||
|
print(' url/-l copy the url of an entry to your clipboard')
|
||||||
|
print(' note/-n copy the note of an entry to your clipboard')
|
||||||
|
print('gen:')
|
||||||
|
print(' update/-u generate a password for an existing entry')
|
||||||
|
print("\n\u001b[1mtip:\u001b[0m you can quickly read an entry with 'sshyp /<entry name>'\n")
|
||||||
|
else:
|
||||||
|
print('\n\u001b[1musage:\u001b[0m sshyp [option [flag] [<device id>]]\n')
|
||||||
|
print('\u001b[1moptions:\u001b[0m')
|
||||||
|
print('help/--help/-h bring up this menu')
|
||||||
|
print('version/-v display sshyp version info')
|
||||||
|
print('tweak configure sshyp')
|
||||||
|
print('whitelist manage the quick-unlock whitelist')
|
||||||
|
print('\n\u001b[1mflags:\u001b[0m')
|
||||||
|
print('whitelist:')
|
||||||
|
print(' setup set up the quick-unlock whitelist')
|
||||||
|
print(' list/-l view all registered device ids and their quick-unlock whitelist status')
|
||||||
|
print(' add whitelist a device id for quick-unlock')
|
||||||
|
print(' delete/del remove a device id from the quick-unlock whitelist\n')
|
||||||
|
elif argument_list[1] == 'version' or argument_list[1] == '-v':
|
||||||
|
print('\nsshyp is a simple, self-hosted, sftp-synchronized password manager\nfor unix(-like) systems (haiku/'
|
||||||
|
'freebsd/linux/termux)\n\nsshyp is a viable alternative to (and compatible with) pass/password-store\n')
|
||||||
|
print(" .. \u001b[38;5;9m♥♥ ♥♥\u001b[0m ..\n .''.''/()\\ \u001b[38;5;10m"
|
||||||
|
"♥♥♥♥♥♥♥\u001b[0m /()\\''.''.\n * : \u001b[38;5;9m♥♥♥♥♥\u001b[0m : *"
|
||||||
|
"\n `..'..' \u001b[38;5;10m♥♥♥\u001b[0m `..'..'\n // \\\\ "
|
||||||
|
"\u001b[38;5;9m♥\u001b[0m // \\\\")
|
||||||
|
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m')
|
||||||
|
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||||
|
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||||
|
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8msshyp copyright (c) 2021-2022 '
|
||||||
|
'randall winkhart\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||||
|
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||||
|
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||||
|
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mversion 1.3.0'
|
||||||
|
'\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||||
|
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mthe serious shepherd '
|
||||||
|
'update\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||||
|
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||||
|
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||||
|
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m\n')
|
||||||
|
print('see https://github.com/rwinkhart/sshyp for more information\n')
|
||||||
|
elif argument_list[1] == 'license':
|
||||||
|
print('\nThis program is free software: you can redistribute it and/or modify it under the terms\nof version 3 '
|
||||||
|
'(only) of the GNU General Public License as published by the Free Software Foundation.\n\nThis program '
|
||||||
|
'is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;\nwithout even the implied '
|
||||||
|
'warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.\nSee the GNU General Public License for'
|
||||||
|
' more details.\n\nhttps://opensource.org/licenses/GPL-3.0\n')
|
||||||
|
elif argument_list[1] == 'add':
|
||||||
|
print('\n\u001b[1musage:\u001b[0m sshyp add [flag [<entry name>]]\u001b[0m\n')
|
||||||
|
print('\u001b[1mflags:\u001b[0m')
|
||||||
|
print('add:')
|
||||||
|
print(' password/-p add a password entry')
|
||||||
|
print(' note/-n add a note entry')
|
||||||
|
print(' folder/-f add a new folder for entries\n')
|
||||||
|
elif argument_list[1] == 'edit':
|
||||||
|
print('\n\u001b[1musage:\u001b[0m sshyp edit [flag [<entry name>]]\u001b[0m\n')
|
||||||
|
print('\u001b[1mflags:\u001b[0m')
|
||||||
|
print('edit:')
|
||||||
|
print(' rename/relocate/-r rename or relocate an entry')
|
||||||
|
print(' username/-u change the username of an entry')
|
||||||
|
print(' password/-p change the password of an entry')
|
||||||
|
print(' url/-l change the url attached to an entry')
|
||||||
|
print(' note/-n change the note attached to an entry\n')
|
||||||
|
elif argument_list[1] == 'copy':
|
||||||
|
print('\n\u001b[1musage:\u001b[0m sshyp copy [flag [<entry name>]]\u001b[0m\n')
|
||||||
|
print('\u001b[1mflags:\u001b[0m')
|
||||||
|
print('copy:')
|
||||||
|
print(' username/-u copy the username of an entry to your clipboard')
|
||||||
|
print(' password/-p copy the password of an entry to your clipboard')
|
||||||
|
print(' url/-l copy the url of an entry to your clipboard')
|
||||||
|
print(' note/-n copy the note of an entry to your clipboard\n')
|
||||||
|
elif argument_list[1] == 'whitelist':
|
||||||
|
if device_type == 'server':
|
||||||
|
print('\n\u001b[1musage:\u001b[0m sshyp whitelist [flag [<device id>]]\u001b[0m\n')
|
||||||
|
print('\u001b[1mflags:\u001b[0m')
|
||||||
|
print('whitelist:')
|
||||||
|
print(' setup set up the quick-unlock whitelist')
|
||||||
|
print(' list/-l view all registered device ids and their quick-unlock whitelist status')
|
||||||
|
print(' add whitelist a device id for quick-unlock')
|
||||||
|
print(' delete/del remove a device id from the quick-unlock whitelist\n')
|
||||||
|
else:
|
||||||
|
print('\n\u001b[38;5;9merror: argument (whitelist) only available on server\u001b[0m\n')
|
||||||
|
s_exit(0)
|
||||||
|
|
||||||
|
|
||||||
|
def no_arg(): # displays a list of entries and gives an option to select one for viewing
|
||||||
|
print("\nfor a list of usable commands, run 'sshyp help'")
|
||||||
|
_entry_name = entry_name_fetch('entry to read: ')
|
||||||
|
if not Path(f"{directory}{_entry_name}.gpg").exists():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||||
|
s_exit(3)
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
||||||
|
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||||
|
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||||
|
|
||||||
|
|
||||||
|
def read_shortcut(): # shortcut to quickly read an entry
|
||||||
|
if not Path(f"{directory}{argument.replace('/', '', 1)}.gpg").exists():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({argument.replace('/', '', 1)}) does not exist\u001b[0m\n")
|
||||||
|
s_exit(3)
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
determine_decrypt(directory + argument.replace('/', '', 1), _shm_folder, _shm_entry)
|
||||||
|
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||||
|
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||||
|
|
||||||
|
|
||||||
|
def sync(): # calls sshync to sync changes to the user's server
|
||||||
|
print('\nsyncing entries with the server device...\n')
|
||||||
|
# set permissions before uploading
|
||||||
|
for _root, _dirs, _files in walk(expanduser('~/.local/share/sshyp')):
|
||||||
|
for _path in _root.split('\n'):
|
||||||
|
chmod(_path, 0o700)
|
||||||
|
for _file in _files:
|
||||||
|
chmod(_root + '/' + _file, 0o600)
|
||||||
|
run_profile(expanduser('~/.config/sshyp/sshyp.sshync'), silent_sync)
|
||||||
|
|
||||||
|
|
||||||
|
def whitelist_setup(): # takes input from the user to set up quick-unlock password
|
||||||
|
_gpg_password_temp = str(input('\nfull gpg passphrase: '))
|
||||||
|
_half_length = int(len(_gpg_password_temp)/2)
|
||||||
|
try:
|
||||||
|
_short_password_length = int(input(f"\nquick unlock pin length (must be half the length of gpg password or "
|
||||||
|
f"less) ({_half_length}): "))
|
||||||
|
if _short_password_length > _half_length:
|
||||||
|
_short_password_length = _half_length
|
||||||
|
except ValueError:
|
||||||
|
_short_password_length = _half_length
|
||||||
|
_i, _quick_unlock_password, _quick_unlock_password_excluded = 0, '', ''
|
||||||
|
for _char in _gpg_password_temp:
|
||||||
|
if _i % 2 == 1 and _i < _short_password_length*2:
|
||||||
|
_quick_unlock_password += _char
|
||||||
|
else:
|
||||||
|
_quick_unlock_password_excluded += _char
|
||||||
|
_i += 1
|
||||||
|
|
||||||
|
# create assembly key
|
||||||
|
open(expanduser('~/.config/sshyp/gpg-gen'), 'w').writelines([
|
||||||
|
'Key-Type: 1\n', 'Key-Length: 4096\n', 'Key-Usage: sign encrypt\n', 'Name-Real: sshyp\n',
|
||||||
|
'Name-Comment: gpg-sshyp-whitelist\n', 'Name-Email: https://github.com/rwinkhart/sshyp\n', 'Expire-Date: 0'])
|
||||||
|
run(['gpg', '-q', '--pinentry-mode', 'loopback', '--batch', '--generate-key', '--passphrase',
|
||||||
|
_quick_unlock_password, expanduser('~/.config/sshyp/gpg-gen')])
|
||||||
|
remove(expanduser('~/.config/sshyp/gpg-gen'))
|
||||||
|
_gpg_id = run(['gpg', '-k'], stdout=PIPE, text=True).stdout.split('\n')[-4].strip()
|
||||||
|
|
||||||
|
# encrypt excluded with the assembly key
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').write(_quick_unlock_password_excluded)
|
||||||
|
encrypt(expanduser('~/.config/sshyp/excluded'), _shm_folder, _shm_entry, _gpg_id)
|
||||||
|
print(f"\nyour quick-unlock passphrase: {_quick_unlock_password}")
|
||||||
|
|
||||||
|
|
||||||
|
def whitelist_verify(_port, _username_ssh, _ip, _client_device_id):
|
||||||
|
# checks the user's whitelist status and fetches the full gpg key password if possible
|
||||||
|
try:
|
||||||
|
run(['gpg', '--pinentry-mode', 'cancel', '-qd', '--output', '/dev/null',
|
||||||
|
expanduser('~/.config/sshyp/lock.gpg')], stderr=DEVNULL, check=True)
|
||||||
|
return False
|
||||||
|
except CalledProcessError:
|
||||||
|
_i, _full_password = 0, ''
|
||||||
|
_server_whitelist = run(['ssh', '-i', expanduser('~/.ssh/sshyp'), '-p', _port, f"{_username_ssh}@{_ip}",
|
||||||
|
f'python3 -c \'from os import listdir; print(*listdir("/home/{_username_ssh}'
|
||||||
|
f'/.config/sshyp/whitelist"))\''], stdout=PIPE, text=True).stdout.rstrip().split(' ')
|
||||||
|
for _device_id in _server_whitelist:
|
||||||
|
if _device_id == _client_device_id:
|
||||||
|
from getpass import getpass
|
||||||
|
_quick_unlock_password = getpass(prompt='\nquick-unlock passphrase: ')
|
||||||
|
_quick_unlock_password_excluded = \
|
||||||
|
run(['ssh', '-i', expanduser('~/.ssh/sshyp'), '-p', _port, f"{_username_ssh}@{_ip}",
|
||||||
|
f"gpg --pinentry-mode loopback --passphrase '{_quick_unlock_password}' "
|
||||||
|
f"-qd ~/.config/sshyp/excluded.gpg"], stdout=PIPE, text=True).stdout.rstrip()
|
||||||
|
while _i < len(_quick_unlock_password_excluded):
|
||||||
|
try:
|
||||||
|
_full_password += _quick_unlock_password_excluded[_i]
|
||||||
|
except IndexError:
|
||||||
|
pass
|
||||||
|
try:
|
||||||
|
_full_password += _quick_unlock_password[_i]
|
||||||
|
except IndexError:
|
||||||
|
pass
|
||||||
|
_i += 1
|
||||||
|
break
|
||||||
|
return _full_password
|
||||||
|
|
||||||
|
|
||||||
|
def whitelist_list(): # shows the quick-unlock whitelist status of device ids
|
||||||
|
_whitelisted_ids = listdir(expanduser('~/.config/sshyp/whitelist'))
|
||||||
|
_device_ids = listdir(expanduser('~/.config/sshyp/devices'))
|
||||||
|
print('\n\u001b[1mquick-unlock whitelisted device ids:\u001b[0m')
|
||||||
|
for _id in _whitelisted_ids:
|
||||||
|
print(_id)
|
||||||
|
print('\n\u001b[1mother registered device ids:\u001b[0m')
|
||||||
|
for _id in _device_ids:
|
||||||
|
if _id not in _whitelisted_ids:
|
||||||
|
print(_id)
|
||||||
|
print()
|
||||||
|
|
||||||
|
|
||||||
|
def whitelist_manage(): # adds or removes quick-unlock whitelisted device ids
|
||||||
|
if len(argument_list) == 3:
|
||||||
|
whitelist_list()
|
||||||
|
_device_id = input('device id: ')
|
||||||
|
else:
|
||||||
|
_argument_split = argument.split(' ')
|
||||||
|
del _argument_split[:2]
|
||||||
|
_device_id = ' '.join(_argument_split)
|
||||||
|
|
||||||
|
if argument_list[2] == 'add':
|
||||||
|
if _device_id in listdir(expanduser('~/.config/sshyp/devices')):
|
||||||
|
open(expanduser(f"~/.config/sshyp/whitelist/{_device_id}"), 'w').write('')
|
||||||
|
whitelist_list()
|
||||||
|
else:
|
||||||
|
print(f"\n\u001b[38;5;9merror: device id ({_device_id}) is not registered\u001b[0m\n")
|
||||||
|
s_exit(2)
|
||||||
|
|
||||||
|
elif Path(expanduser(f"~/.config/sshyp/whitelist/{_device_id}")).is_file():
|
||||||
|
remove(expanduser(f"~/.config/sshyp/whitelist/{_device_id}"))
|
||||||
|
whitelist_list()
|
||||||
|
|
||||||
|
|
||||||
|
def add_entry(): # adds a new entry
|
||||||
|
_shm_folder, _shm_entry = None, None # sets base-line values to avoid errors
|
||||||
|
if len(argument_list) < 4:
|
||||||
|
_entry_name = entry_name_fetch('name of new entry: ')
|
||||||
|
else:
|
||||||
|
_entry_name = entry_name_fetch(2)
|
||||||
|
if Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) already exists\u001b[0m\n")
|
||||||
|
s_exit(4)
|
||||||
|
if argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||||
|
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(optimized_edit(['', '', '', _notes], None, -1))
|
||||||
|
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||||
|
_username = str(input('username: '))
|
||||||
|
_password = str(input('password: '))
|
||||||
|
_url = str(input('url: '))
|
||||||
|
_add_note = input('add a note to this entry? (y/N) ')
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
if _add_note.lower() == 'y':
|
||||||
|
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||||
|
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||||
|
else:
|
||||||
|
_notes = ''
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w')\
|
||||||
|
.writelines(optimized_edit([_password, _username, _url, _notes], None, -1))
|
||||||
|
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||||
|
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||||
|
encrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg_id)
|
||||||
|
|
||||||
|
|
||||||
|
def add_folder(): # creates a new folder
|
||||||
|
if len(argument_list) < 4:
|
||||||
|
_entry_name = entry_name_fetch('name of new folder: ')
|
||||||
|
else:
|
||||||
|
_entry_name = entry_name_fetch(2)
|
||||||
|
Path(directory + _entry_name).mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||||
|
if ssh_error != 1:
|
||||||
|
run(['ssh', '-i', expanduser('~/.ssh/sshyp'), '-p', port, f"{username_ssh}@{ip}",
|
||||||
|
f'python3 -c \'from pathlib import Path; Path("{directory_ssh}{_entry_name}")'
|
||||||
|
f'.mkdir(mode=0o700, parents=True, exist_ok=True)\''])
|
||||||
|
|
||||||
|
|
||||||
|
def rename(): # renames an entry or folder
|
||||||
|
from shutil import copy
|
||||||
|
if argument == 'edit rename' or argument == 'edit relocate' or argument == 'edit -r':
|
||||||
|
_entry_name = entry_name_fetch('entry/folder to rename/relocate: ')
|
||||||
|
else:
|
||||||
|
_entry_name = entry_name_fetch(2)
|
||||||
|
if not Path(f"{directory}{_entry_name}.gpg").is_file() and not Path(f"{directory}{_entry_name}").is_dir():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||||
|
s_exit(3)
|
||||||
|
_new_name = entry_name_fetch('new name: ')
|
||||||
|
if Path(f"{directory}{_new_name}.gpg").is_file() or Path(f"{directory}{_new_name}").is_dir():
|
||||||
|
print(f"\n\u001b[38;5;9merror: ({_new_name}) already exists\u001b[0m\n")
|
||||||
|
s_exit(4)
|
||||||
|
if _entry_name.endswith('/'):
|
||||||
|
if ssh_error != 1:
|
||||||
|
Path(f"{directory}{_new_name}").mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||||
|
run(['ssh', '-i', expanduser('~/.ssh/sshyp'), '-p', port, f"{username_ssh}@{ip}",
|
||||||
|
f'python3 -c \'from pathlib import Path; Path("{directory_ssh}{_new_name}")'
|
||||||
|
f'.mkdir(mode=0o700, parents=True, exist_ok=True)\''])
|
||||||
|
else:
|
||||||
|
move(f"{directory}{_entry_name}", f"{directory}{_new_name}")
|
||||||
|
else:
|
||||||
|
if ssh_error != 1:
|
||||||
|
copy(f"{directory}{_entry_name}.gpg", f"{directory}{_new_name}.gpg")
|
||||||
|
else:
|
||||||
|
move(f"{directory}{_entry_name}.gpg", f"{directory}{_new_name}.gpg")
|
||||||
|
if ssh_error != 1:
|
||||||
|
run(['ssh', '-i', expanduser('~/.ssh/sshyp'), '-p', port, f"{username_ssh}@{ip}",
|
||||||
|
f'cd /lib/sshyp; python3 -c \'from sshync import delete; delete("{_entry_name}", "remotely")\''])
|
||||||
|
|
||||||
|
|
||||||
|
def edit(): # edits the contents of an entry
|
||||||
|
_shm_folder, _shm_entry, _detail, _edit_line = None, None, None, None # sets values to avoid PEP8 warnings
|
||||||
|
if len(argument_list) < 4:
|
||||||
|
_entry_name = entry_name_fetch('entry to edit: ')
|
||||||
|
else:
|
||||||
|
_entry_name = entry_name_fetch(2)
|
||||||
|
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||||
|
s_exit(3)
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
||||||
|
if argument_list[2] == 'username' or argument_list[2] == '-u':
|
||||||
|
_detail, _edit_line = str(input('username: ')), 1
|
||||||
|
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||||
|
_detail, _edit_line = str(input('password: ')), 0
|
||||||
|
elif argument_list[2] == 'url' or argument_list[2] == '-l':
|
||||||
|
_detail, _edit_line = str(input('url: ')), 2
|
||||||
|
if argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||||
|
_edit_line = 2
|
||||||
|
_new_lines = optimized_edit(edit_note(_shm_folder, _shm_entry,
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines()), None, -1)
|
||||||
|
else:
|
||||||
|
_new_lines = optimized_edit(open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), _detail, _edit_line)
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_new_lines)
|
||||||
|
remove(f"{directory}{_entry_name}.gpg")
|
||||||
|
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||||
|
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||||
|
encrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg_id)
|
||||||
|
|
||||||
|
|
||||||
|
def gen(): # generates a password for a new or an existing entry
|
||||||
|
_username, _url, _notes = None, None, None # sets base-line values to avoid errors
|
||||||
|
if argument == 'gen update' or argument == 'gen -u' or argument == 'gen':
|
||||||
|
_entry_name = entry_name_fetch('name of entry: ')
|
||||||
|
elif argument_list[2] == 'update' or argument_list[2] == '-u':
|
||||||
|
_entry_name = entry_name_fetch(2)
|
||||||
|
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||||
|
s_exit(3)
|
||||||
|
else:
|
||||||
|
_entry_name = entry_name_fetch(1)
|
||||||
|
if len(argument_list) == 2 or (not argument_list[2] == 'update' and not argument_list[2] == '-u'):
|
||||||
|
if Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) already exists\u001b[0m\n")
|
||||||
|
s_exit(4)
|
||||||
|
_username = str(input('username: '))
|
||||||
|
_password = pass_gen()
|
||||||
|
_url = str(input('url: '))
|
||||||
|
_add_note = input('add a note to this entry? (y/N) ')
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
if _add_note.lower() == 'y':
|
||||||
|
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||||
|
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||||
|
else:
|
||||||
|
_notes = ''
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w')\
|
||||||
|
.writelines(optimized_edit([_password, _username, _url, _notes], None, -1))
|
||||||
|
else:
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
||||||
|
_new_lines = optimized_edit(open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), pass_gen(), 0)
|
||||||
|
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_new_lines)
|
||||||
|
remove(f"{directory}{_entry_name}.gpg")
|
||||||
|
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||||
|
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||||
|
encrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg_id)
|
||||||
|
|
||||||
|
|
||||||
|
def copy_data(): # copies a specified field of an entry to the clipboard
|
||||||
|
from subprocess import Popen
|
||||||
|
if len(argument_list) < 4:
|
||||||
|
_entry_name = entry_name_fetch('entry to copy: ')
|
||||||
|
else:
|
||||||
|
_entry_name = entry_name_fetch(2)
|
||||||
|
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||||
|
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||||
|
s_exit(3)
|
||||||
|
_shm_folder, _shm_entry = shm_gen()
|
||||||
|
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry)
|
||||||
|
_copy_line, _index = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), 0
|
||||||
|
if argument_list[2] == 'username' or argument_list[2] == '-u':
|
||||||
|
_index = 1
|
||||||
|
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||||
|
_index = 0
|
||||||
|
elif argument_list[2] == 'url' or argument_list[2] == '-l':
|
||||||
|
_index = 2
|
||||||
|
elif argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||||
|
_index = 3
|
||||||
|
if 'WAYLAND_DISPLAY' in environ: # Wayland clipboard detection
|
||||||
|
run(['wl-copy', _copy_line[_index].rstrip()])
|
||||||
|
Popen('sleep 30; wl-copy -c', shell=True)
|
||||||
|
elif uname()[0] == 'Haiku': # Haiku clipboard detection
|
||||||
|
run(['clipboard', '-c', _copy_line[_index].rstrip()])
|
||||||
|
Popen('sleep 30; clipboard -r', shell=True)
|
||||||
|
elif Path("/data/data/com.termux").exists(): # Termux (Android) clipboard detection
|
||||||
|
run(['termux-clipboard-set', _copy_line[_index].rstrip()])
|
||||||
|
Popen("sleep 30; termux-clipboard-set ''", shell=True)
|
||||||
|
else: # X11 clipboard detection
|
||||||
|
run(['xclip', '-sel', 'c'], stdin=Popen(['echo', '-n', _copy_line[_index].rstrip()], stdout=PIPE).stdout)
|
||||||
|
Popen("sleep 30; echo -n '' | xclip -sel c", shell=True)
|
||||||
|
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||||
|
|
||||||
|
|
||||||
|
def remove_data(): # deletes an entry from the server and flags it for local deletion on sync
|
||||||
|
if argument == 'shear' or argument == '-rm':
|
||||||
|
_entry_name = entry_name_fetch('entry/folder to shear: ')
|
||||||
|
else:
|
||||||
|
_entry_name = entry_name_fetch(1)
|
||||||
|
determine_decrypt(expanduser('~/.config/sshyp/lock.gpg'), 0, 0)
|
||||||
|
if ssh_error != 1:
|
||||||
|
run(['ssh', '-i', expanduser('~/.ssh/sshyp'), '-p', port, f"{username_ssh}@{ip}",
|
||||||
|
f'cd /lib/sshyp; python3 -c \'from sshync import delete; delete("{_entry_name}", "remotely")\''])
|
||||||
|
else:
|
||||||
|
offline_delete(_entry_name, 'locally')
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
try:
|
||||||
|
silent_sync, ssh_error = 0, 0
|
||||||
|
# retrieve typed argument
|
||||||
|
argument_list = argv
|
||||||
|
argument = ' '.join(argument_list[1:])
|
||||||
|
|
||||||
|
# import saved userdata
|
||||||
|
device_type = ''
|
||||||
|
if argument != 'tweak':
|
||||||
|
tmp_dir = expanduser('~/.config/sshyp/tmp/')
|
||||||
|
try:
|
||||||
|
sshyp_data = open(expanduser('~/.config/sshyp/sshyp-data')).readlines()
|
||||||
|
device_type = sshyp_data[0].rstrip()
|
||||||
|
if device_type == 'client':
|
||||||
|
directory = expanduser('~/.local/share/sshyp/')
|
||||||
|
gpg_id = sshyp_data[1].rstrip()
|
||||||
|
editor = sshyp_data[2].rstrip()
|
||||||
|
quick_unlock_enabled = sshyp_data[3].rstrip()
|
||||||
|
if Path(expanduser('~/.config/sshyp/sshyp.sshync')).is_file():
|
||||||
|
ssh_info = get_profile(expanduser('~/.config/sshyp/sshyp.sshync'))
|
||||||
|
username_ssh = ssh_info[0].rstrip()
|
||||||
|
ip = ssh_info[1].rstrip()
|
||||||
|
port = ssh_info[2].rstrip()
|
||||||
|
directory_ssh = str(ssh_info[4].rstrip())
|
||||||
|
client_device_id = listdir(expanduser('~/.config/sshyp/devices'))[0].rstrip()
|
||||||
|
ssh_error = int(open(expanduser('~/.config/sshyp/ssh-error')).read().rstrip())
|
||||||
|
if ssh_error != 0:
|
||||||
|
ssh_error = copy_id_check(port, username_ssh, ip, client_device_id)
|
||||||
|
else:
|
||||||
|
ssh_error = 1
|
||||||
|
elif len(argument_list) <= 1 or (argument_list[1] != "help" and argument_list[1] != "--help" and
|
||||||
|
argument_list[1] != "-h" and argument_list[1] != "license" and
|
||||||
|
argument_list[1] != "version" and argument_list[1] != "-v" and
|
||||||
|
argument_list[1] != "whitelist"):
|
||||||
|
print(f"\n\u001b[38;5;9merror: invalid server argument - run 'sshyp help' to "
|
||||||
|
f"list usable commands\u001b[0m\n")
|
||||||
|
s_exit(1)
|
||||||
|
except (FileNotFoundError, IndexError):
|
||||||
|
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||||
|
print("not all necessary configuration files are present - please run 'sshyp tweak'")
|
||||||
|
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||||
|
s_exit(2)
|
||||||
|
else:
|
||||||
|
tweak()
|
||||||
|
s_exit(0)
|
||||||
|
|
||||||
|
# run function based on arguments
|
||||||
|
if argument.startswith('/'):
|
||||||
|
read_shortcut()
|
||||||
|
elif argument == '':
|
||||||
|
no_arg()
|
||||||
|
elif argument == 'help' or argument == '--help' or argument == '-h' or argument == 'license' or argument \
|
||||||
|
== 'version' or argument == '-v':
|
||||||
|
print_info()
|
||||||
|
elif argument_list[1] == 'whitelist':
|
||||||
|
if device_type == 'server':
|
||||||
|
if len(argument_list) == 2:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[2] == 'list' or argument_list[2] == '-l':
|
||||||
|
whitelist_list()
|
||||||
|
elif argument_list[2] == 'add' or argument_list[2] == 'delete' or argument_list[2] == 'del':
|
||||||
|
whitelist_manage()
|
||||||
|
elif argument_list[2] == 'setup':
|
||||||
|
whitelist_setup()
|
||||||
|
else:
|
||||||
|
print_info()
|
||||||
|
else:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[1] == 'add':
|
||||||
|
if len(argument_list) == 2:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[2] == 'note' or argument_list[2] == '-n' or argument_list[2] == 'password' or \
|
||||||
|
argument_list[2] == '-p':
|
||||||
|
add_entry()
|
||||||
|
elif argument_list[2] == 'folder' or argument_list[2] == '-f':
|
||||||
|
add_folder()
|
||||||
|
else:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[1] == 'edit':
|
||||||
|
if len(argument_list) == 2:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[2] == 'rename' or argument_list[2] == 'relocate' or argument_list[2] == '-r':
|
||||||
|
silent_sync = 1
|
||||||
|
rename()
|
||||||
|
elif argument_list[2] == 'username' or argument_list[2] == '-u' or argument_list[2] == 'password' or \
|
||||||
|
argument_list[2] == '-p' or argument_list[2] == 'url' or argument_list[2] == '-l' or \
|
||||||
|
argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||||
|
edit()
|
||||||
|
else:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[1] == 'gen':
|
||||||
|
gen()
|
||||||
|
elif argument_list[1] == 'copy':
|
||||||
|
if len(argument_list) == 2:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[2] == 'username' or argument_list[2] == '-u' or argument_list[2] == 'password' or \
|
||||||
|
argument_list[2] == '-p' or argument_list[2] == 'url' or argument_list[2] == '-l' or \
|
||||||
|
argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||||
|
try:
|
||||||
|
copy_data()
|
||||||
|
except IndexError:
|
||||||
|
print(f"\n\u001b[38;5;9merror: field does not exist in entry\u001b[0m\n")
|
||||||
|
s_exit(3)
|
||||||
|
else:
|
||||||
|
print_info()
|
||||||
|
elif argument_list[1] == 'shear' or argument_list[1] == '-rm':
|
||||||
|
remove_data()
|
||||||
|
elif argument_list[1] != 'sync' and argument_list[1] != '-s':
|
||||||
|
print(f"\n\u001b[38;5;9merror: invalid argument - run 'sshyp help' to list usable commands\u001b[0m\n")
|
||||||
|
s_exit(1)
|
||||||
|
|
||||||
|
# sync if any changes were made
|
||||||
|
if len(argument_list) > 1 and ssh_error == 0 \
|
||||||
|
and ((argument_list[1] == 'sync' or argument_list[1] == '-s' or argument_list[1] == 'gen' or
|
||||||
|
argument_list[1] == 'shear' or argument_list[1] == '-rm') or
|
||||||
|
((argument_list[1] == 'add' or argument_list[1] == 'edit') and len(argument_list) > 2)):
|
||||||
|
sync()
|
||||||
|
|
||||||
|
except KeyboardInterrupt:
|
||||||
|
print('\n')
|
||||||
+192
-149
@@ -1,39 +1,80 @@
|
|||||||
#!/bin/bash
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
# This script packages sshyp (from source) for various UNIX(-like) environments.
|
version=$(sed -n '1{p;q}' share/doc/sshyp/changelog | cut -c8-)
|
||||||
# Dependencies (Arch Linux): dpkg (packaging for Debian/Termux), freebsd-pkg (packaging for FreeBSD)
|
if [ -z "$2" ]; then
|
||||||
# Dependencies (Fedora) (can only package for self): rpmdevtools
|
revision=1
|
||||||
# NOTE It is recommended to instead use the latest officially packaged and tagged release.
|
else
|
||||||
|
revision="$2"
|
||||||
echo -e '\nOptions (please enter the number only):'
|
|
||||||
echo -e '\nPackage Formats:\n\n1. Haiku\n2. Debian&Ubuntu Linux\n3. Fedora Linux\n4. FreeBSD\n5. Termux\n6. Generic (used for PKGBUILD/APKBUILD)'
|
|
||||||
echo -e '\nBuild Scripts:\n\n7. Arch Linux (PKGBUILD)'
|
|
||||||
echo -e '\nOther:\n\n8. All (generates all distribution packages (excluding Haiku and Fedora, as these must be packaged on their respective distributions) and build scripts)\n'
|
|
||||||
read -n 1 -r -p "Distribution: " distro
|
|
||||||
|
|
||||||
echo -e '\n\nThe value entered in this field will only affect the version reported to the package manager. The latest source is used regardless.\n'
|
|
||||||
read -r -p "Version number: " version
|
|
||||||
|
|
||||||
echo -e '\nThe value entered in this field will only affect the revision number for build scripts.\n'
|
|
||||||
read -r -p "Revision number: " revision
|
|
||||||
|
|
||||||
if [ "$distro" == "7" ] || [ "$distro" == "8" ]; then
|
|
||||||
echo -e '\nOptions (please enter the number only):'
|
|
||||||
echo -e '\n1. GitHub Release Tag\n2. Local\n'
|
|
||||||
read -r -p "Source (for build scripts): " source
|
|
||||||
|
|
||||||
if [ "$source" == "1" ]; then
|
|
||||||
source='https://github.com/rwinkhart/sshyp/releases/download/v$pkgver/sshyp-$pkgver.tar.xz'
|
|
||||||
else
|
|
||||||
source=local://sshyp-"$version".tar.xz
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
mkdir -p packages
|
_create_generic() {
|
||||||
|
echo -e '\npackaging as generic...\n'
|
||||||
|
mkdir -p output/generictemp/usr/{bin,lib/sshyp,share/{man/man1,bash-completion/completions}}
|
||||||
|
cp -r lib/. output/generictemp/usr/lib/sshyp/
|
||||||
|
ln -s /usr/lib/sshyp/sshyp.py output/generictemp/usr/bin/sshyp
|
||||||
|
cp -r share output/generictemp/usr/
|
||||||
|
cp extra/sshyp-completion.bash output/generictemp/usr/share/bash-completion/completions/sshyp
|
||||||
|
cp extra/manpage output/generictemp/usr/share/man/man1/sshyp.1
|
||||||
|
gzip output/generictemp/usr/share/man/man1/sshyp.1
|
||||||
|
tar -C output/generictemp -cvJf output/sshyp-"$version".tar.xz usr/
|
||||||
|
rm -rf output/generictemp
|
||||||
|
sha512="$(sha512sum output/sshyp-"$version".tar.xz | awk '{print $1;}')"
|
||||||
|
echo -e "\nsha512 sum:\n$sha512"
|
||||||
|
echo -e "\ngeneric packaging complete\n"
|
||||||
|
} &&
|
||||||
|
|
||||||
if [ "$distro" == "1" ]; then
|
_create_pkgbuild() {
|
||||||
echo -e '\nPackaging for Haiku...\n'
|
source='https://github.com/rwinkhart/sshyp/releases/download/v$pkgver/sshyp-$pkgver.tar.xz'
|
||||||
mkdir -p packages/haikutemp/documentation/{man/man1,packages/sshyp}
|
echo -e '\ngenerating PKGBUILD...'
|
||||||
|
echo "# Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||||
|
pkgname=sshyp
|
||||||
|
pkgver="$version"
|
||||||
|
pkgrel="$revision"
|
||||||
|
pkgdesc='A light-weight, self-hosted, synchronized password manager'
|
||||||
|
url='https://github.com/rwinkhart/sshyp'
|
||||||
|
arch=('any')
|
||||||
|
license=('GPL-3.0-only')
|
||||||
|
depends=(python gnupg openssh xclip wl-clipboard)
|
||||||
|
optdepends=('bash-completion: bash completion support')
|
||||||
|
source=(\""$source"\")
|
||||||
|
sha512sums=('"$sha512"')
|
||||||
|
|
||||||
|
package() {
|
||||||
|
tar xf sshyp-"\"\$pkgver\"".tar.xz -C "\"\${pkgdir}\""
|
||||||
|
}
|
||||||
|
" > output/PKGBUILD
|
||||||
|
echo -e "\nPKGBUILD generated\n"
|
||||||
|
} &&
|
||||||
|
|
||||||
|
_create_apkbuild() {
|
||||||
|
echo -e '\ngenerating APKBUILD...'
|
||||||
|
echo "# Maintainer: Randall Winkhart <idgr@tutanota.com>
|
||||||
|
pkgname=sshyp
|
||||||
|
pkgver="$version"
|
||||||
|
pkgrel="$((revision-1))"
|
||||||
|
pkgdesc='A light-weight, self-hosted, synchronized password manager'
|
||||||
|
options=!check
|
||||||
|
url='https://github.com/rwinkhart/sshyp'
|
||||||
|
arch='noarch'
|
||||||
|
license='GPL-3.0-only'
|
||||||
|
depends='python3 gnupg openssh xclip wl-clipboard'
|
||||||
|
source=\""$source"\"
|
||||||
|
|
||||||
|
package() {
|
||||||
|
mkdir -p "\"\$pkgdir\""
|
||||||
|
cp -r "\"\$srcdir/usr/"\" "\"\$pkgdir\""
|
||||||
|
}
|
||||||
|
|
||||||
|
sha512sums=\"
|
||||||
|
"$sha512' 'sshyp-\"\$pkgver\".tar.xz"
|
||||||
|
\"
|
||||||
|
" > output/APKBUILD
|
||||||
|
echo -e "\nAPKBUILD generated\n"
|
||||||
|
} &&
|
||||||
|
|
||||||
|
_create_hpkg() {
|
||||||
|
echo -e '\npackaging for Haiku...\n'
|
||||||
|
mkdir -p output/haikutemp/{bin,lib/sshyp,documentation/{packages/sshyp,man/man1},data/bash-completion/completions}
|
||||||
echo "name sshyp
|
echo "name sshyp
|
||||||
version "$version"-"$revision"
|
version "$version"-"$revision"
|
||||||
architecture any
|
architecture any
|
||||||
@@ -54,131 +95,121 @@ provides {
|
|||||||
requires {
|
requires {
|
||||||
gnupg
|
gnupg
|
||||||
openssh
|
openssh
|
||||||
python3
|
python310
|
||||||
nano
|
|
||||||
}
|
}
|
||||||
urls {
|
urls {
|
||||||
\"https://github.com/rwinkhart/sshyp\"
|
\"https://github.com/rwinkhart/sshyp\"
|
||||||
}
|
}
|
||||||
" > packages/haikutemp/.PackageInfo
|
" > output/haikutemp/.PackageInfo
|
||||||
cp -r bin packages/haikutemp/
|
cp -r lib/. output/haikutemp/lib/sshyp/
|
||||||
cp -r share/doc/sshyp/ packages/haikutemp/documentation/packages/
|
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshync.py
|
||||||
cp -r share/licenses/sshyp/ packages/haikutemp/documentation/packages/
|
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshyp.py
|
||||||
cp extra/manpage packages/haikutemp/documentation/man/man1/sshyp.1
|
ln -s /system/lib/sshyp/sshyp.py output/haikutemp/bin/sshyp
|
||||||
gzip packages/haikutemp/documentation/man/man1/sshyp.1
|
cp -r share/doc/sshyp/. output/haikutemp/documentation/packages/sshyp/
|
||||||
cd packages/haikutemp
|
cp -r share/licenses/sshyp/. output/haikutemp/documentation/packages/sshyp/
|
||||||
|
cp extra/sshyp-completion.bash output/haikutemp/data/bash-completion/completions/sshyp
|
||||||
|
cp extra/manpage output/haikutemp/documentation/man/man1/sshyp.1
|
||||||
|
gzip output/haikutemp/documentation/man/man1/sshyp.1
|
||||||
|
cd output/haikutemp
|
||||||
package create -b sshyp-"$version"-"$revision"_all.hpkg
|
package create -b sshyp-"$version"-"$revision"_all.hpkg
|
||||||
package add sshyp-"$version"-"$revision"_all.hpkg bin documentation
|
package add sshyp-"$version"-"$revision"_all.hpkg bin lib documentation data
|
||||||
cd ../..
|
cd ../..
|
||||||
mv packages/haikutemp/sshyp-"$version"-"$revision"_all.hpkg packages/
|
mv output/haikutemp/sshyp-"$version"-"$revision"_all.hpkg output/
|
||||||
rm -rf packages/haikutemp
|
rm -rf output/haikutemp
|
||||||
echo -e "\nHaiku packaging complete.\n"
|
echo -e "\nHaiku packaging complete\n"
|
||||||
fi
|
} &&
|
||||||
|
|
||||||
if [ "$distro" == "2" ] || [ "$distro" == "8" ]; then
|
_create_deb() {
|
||||||
echo -e '\nPackaging for Debian...\n'
|
echo -e '\npackaging for Debian/Ubuntu...\n'
|
||||||
mkdir -p packages/debiantemp/sshyp_"$version"-"$revision"_all/{DEBIAN,usr/share/man/man1}
|
mkdir -p output/debiantemp/sshyp_"$version"-"$revision"_all/{DEBIAN,usr/{lib/sshyp,bin,share/{bash-completion/completions,man/man1}}}
|
||||||
echo "Package: sshyp
|
echo "Package: sshyp
|
||||||
Version: $version
|
Version: $version
|
||||||
Section: utils
|
Section: utils
|
||||||
Architecture: all
|
Architecture: all
|
||||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||||
Description: A light-weight, self-hosted, synchronized password manager
|
Description: A light-weight, self-hosted, synchronized password manager
|
||||||
Depends: python3, gnupg, openssh-client, nano, xclip, wl-clipboard
|
Depends: python3, gnupg, openssh-client, xclip, wl-clipboard
|
||||||
|
Suggests: bash-completion
|
||||||
Priority: optional
|
Priority: optional
|
||||||
Installed-Size: 185
|
Installed-Size: 14584
|
||||||
" > packages/debiantemp/sshyp_"$version"-"$revision"_all/DEBIAN/control
|
" > output/debiantemp/sshyp_"$version"-"$revision"_all/DEBIAN/control
|
||||||
cp -r bin packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/
|
cp -r lib/. output/debiantemp/sshyp_"$version"-"$revision"_all/usr/lib/sshyp/
|
||||||
cp -r share packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/
|
ln -s /usr/lib/sshyp/sshyp.py output/debiantemp/sshyp_"$version"-"$revision"_all/usr/bin/sshyp
|
||||||
cp extra/manpage packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
cp -r share output/debiantemp/sshyp_"$version"-"$revision"_all/usr/
|
||||||
gzip packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
cp extra/sshyp-completion.bash output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/bash-completion/completions/sshyp
|
||||||
dpkg-deb --build --root-owner-group packages/debiantemp/sshyp_"$version"-"$revision"_all/
|
cp extra/manpage output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||||
mv packages/debiantemp/sshyp_"$version"-"$revision"_all.deb packages/
|
gzip output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||||
rm -rf packages/debiantemp
|
dpkg-deb --build --root-owner-group output/debiantemp/sshyp_"$version"-"$revision"_all/
|
||||||
echo -e "\nDebian packaging complete.\n"
|
mv output/debiantemp/sshyp_"$version"-"$revision"_all.deb output/
|
||||||
fi
|
rm -rf output/debiantemp
|
||||||
|
echo -e "\nDebian/Ubuntu packaging complete\n"
|
||||||
|
} &&
|
||||||
|
|
||||||
if [ "$distro" == "5" ] || [ "$distro" == "8" ]; then
|
_create_termux() {
|
||||||
echo -e '\nPackaging for Termux...\n'
|
echo -e '\npackaging for Termux...\n'
|
||||||
mkdir -p packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/{data,DEBIAN}
|
mkdir -p output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/{DEBIAN,data/data/com.termux/files/usr/{lib/sshyp,bin,share/{bash-completion/completions,man/man1}}}
|
||||||
mkdir -p packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1
|
|
||||||
echo "Package: sshyp
|
echo "Package: sshyp
|
||||||
Version: $version
|
Version: $version
|
||||||
Section: utils
|
Section: utils
|
||||||
Architecture: all
|
Architecture: all
|
||||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||||
Description: A light-weight, self-hosted, synchronized password manager
|
Description: A light-weight, self-hosted, synchronized password manager
|
||||||
Depends: python, gnupg, openssh, nano, termux-api, termux-am
|
Depends: python, gnupg, openssh, termux-api, termux-am
|
||||||
|
Suggests: bash-completion
|
||||||
Priority: optional
|
Priority: optional
|
||||||
Installed-Size: 185
|
Installed-Size: 14584
|
||||||
" > packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/DEBIAN/control
|
" > output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/DEBIAN/control
|
||||||
cp -r bin packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
|
cp -r lib/. output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/lib/sshyp/
|
||||||
cp -r share packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
|
ln -s /data/data/com.termux/files/usr/lib/sshyp/sshyp.py output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/bin/sshyp
|
||||||
cp extra/manpage packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
cp -r share output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
|
||||||
gzip packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
cp extra/sshyp-completion.bash output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/bash-completion/completions/sshyp
|
||||||
dpkg-deb --build --root-owner-group packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/
|
cp extra/manpage output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||||
mv packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux.deb packages/
|
gzip output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||||
rm -rf packages/termuxtemp
|
dpkg-deb --build --root-owner-group output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/
|
||||||
echo -e "\nTermux packaging complete.\n"
|
mv output/termuxtemp/sshyp_"$version"-"$revision"_all_termux.deb output/
|
||||||
fi
|
rm -rf output/termuxtemp
|
||||||
|
echo -e "\nTermux packaging complete\n"
|
||||||
|
} &&
|
||||||
|
|
||||||
if [ "$distro" == "3" ] || [ "$distro" == "4" ] || [ "$distro" == "6" ] || [ "$distro" == "7" ] || [ "$distro" == "8" ]; then
|
_create_rpm() {
|
||||||
echo -e '\nPackaging as generic...\n'
|
echo -e '\npackaging for Fedora...\n'
|
||||||
mkdir -p packages/archtemp/usr/share/man/man1
|
|
||||||
cp -r bin packages/archtemp/usr/
|
|
||||||
cp -r share packages/archtemp/usr/
|
|
||||||
cp extra/manpage packages/archtemp/usr/share/man/man1/sshyp.1
|
|
||||||
gzip packages/archtemp/usr/share/man/man1/sshyp.1
|
|
||||||
tar -C packages/archtemp -cvf packages/sshyp-"$version".tar.xz usr/
|
|
||||||
rm -rf packages/archtemp
|
|
||||||
sha512="$(sha512sum packages/sshyp-"$version".tar.xz | awk '{print $1;}')"
|
|
||||||
echo -e "\nsha512 sum:\n$sha512"
|
|
||||||
echo -e "\nGeneric packaging complete.\n"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ "$distro" == "3" ]; then
|
|
||||||
echo -e '\nPackaging for Fedora...\n'
|
|
||||||
rm -rf ~/rpmbuild
|
rm -rf ~/rpmbuild
|
||||||
rpmdev-setuptree
|
rpmdev-setuptree
|
||||||
cp packages/sshyp-"$version".tar.xz ~/rpmbuild/SOURCES
|
cp output/sshyp-"$version".tar.xz ~/rpmbuild/SOURCES
|
||||||
echo "Name: sshyp
|
echo "Name: sshyp
|
||||||
Version: "$version"
|
Version: "$version"
|
||||||
Release: "$revision"
|
Release: "$revision"
|
||||||
Summary: A light-weight, self-hosted, synchronized password manager
|
Summary: A light-weight, self-hosted, synchronized password manager
|
||||||
BuildArch: noarch
|
BuildArch: noarch
|
||||||
|
License: GPL-3.0-only
|
||||||
License: GPL3
|
|
||||||
URL: https://github.com/rwinkhart/sshyp
|
URL: https://github.com/rwinkhart/sshyp
|
||||||
Source0: sshyp-"$version".tar.xz
|
Source0: sshyp-"$version".tar.xz
|
||||||
|
Requires: python gnupg openssh-clients wl-clipboard
|
||||||
Requires: python gnupg openssh nano wl-clipboard
|
Recommends: bash-completion
|
||||||
|
|
||||||
%description
|
%description
|
||||||
sshyp is a password-store compatible CLI password manager available for UNIX(-like) systems - its primary goal is to make syncing passwords and notes across devices as easy as possible via CLI.
|
sshyp is a password-store compatible CLI password manager available for UNIX(-like) systems - its primary goal is to make syncing passwords and notes across devices as easy as possible via CLI.
|
||||||
|
|
||||||
%install
|
%install
|
||||||
tar xf %{_sourcedir}/sshyp-"$version".tar.xz -C %{_sourcedir}
|
tar xf %{_sourcedir}/sshyp-"$version".tar.xz -C %{_sourcedir}
|
||||||
cp -r %{_sourcedir}/usr %{buildroot}
|
cp -r %{_sourcedir}/usr %{buildroot}
|
||||||
|
|
||||||
%files
|
%files
|
||||||
/usr/bin/sshyp
|
/usr/bin/sshyp
|
||||||
/usr/bin/sshync.py
|
/usr/lib/sshyp/sshyp.py
|
||||||
/usr/bin/sshypRemote.py
|
/usr/lib/sshyp/sshync.py
|
||||||
|
/usr/share/bash-completion/completions/sshyp
|
||||||
%license /usr/share/licenses/sshyp/license
|
%license /usr/share/licenses/sshyp/license
|
||||||
%doc /usr/share/doc/sshyp/changelog
|
%doc
|
||||||
%doc /usr/share/man/man1/sshyp.1.gz
|
/usr/share/doc/sshyp/changelog
|
||||||
|
/usr/share/man/man1/sshyp.1.gz
|
||||||
" > ~/rpmbuild/SPECS/sshyp.spec
|
" > ~/rpmbuild/SPECS/sshyp.spec
|
||||||
rpmbuild -bb ~/rpmbuild/SPECS/sshyp.spec
|
rpmbuild -bb ~/rpmbuild/SPECS/sshyp.spec
|
||||||
mv ~/rpmbuild/RPMS/noarch/* packages/
|
mv ~/rpmbuild/RPMS/noarch/* output/
|
||||||
rm -rf ~/rpmbuild
|
rm -rf ~/rpmbuild
|
||||||
echo -e "\nFedora packaging complete.\n"
|
echo -e "\nFedora packaging complete\n"
|
||||||
fi
|
} &&
|
||||||
|
|
||||||
if [ "$distro" == "4" ] || [ "$distro" == "8" ]; then
|
_create_freebsd_pkg() {
|
||||||
echo -e '\nPackaging for FreeBSD...\n'
|
echo -e '\npackaging for FreeBSD...'
|
||||||
mkdir -p packages/FreeBSDtemp/bin
|
mkdir -p output/freebsdtemp/usr/{lib/sshyp,bin,share/{bash-completion/completions,man/man1}}
|
||||||
tar xf packages/sshyp-"$version".tar.xz -C packages/FreeBSDtemp
|
|
||||||
ln -s /usr/local/bin/python3 packages/FreeBSDtemp/bin/python3
|
|
||||||
echo "name: sshyp
|
echo "name: sshyp
|
||||||
version: \""$version"\"
|
version: \""$version"\"
|
||||||
abi = \"FreeBSD:13:*\";
|
abi = \"FreeBSD:13:*\";
|
||||||
@@ -196,9 +227,6 @@ prefix: /
|
|||||||
\"gnupg\" : {
|
\"gnupg\" : {
|
||||||
\"origin\" : \"security/gnupg\"
|
\"origin\" : \"security/gnupg\"
|
||||||
},
|
},
|
||||||
\"nano\" : {
|
|
||||||
\"origin\" : \"editors/nano\"
|
|
||||||
},
|
|
||||||
\"xclip\" : {
|
\"xclip\" : {
|
||||||
\"origin\" : \"x11/xclip\"
|
\"origin\" : \"x11/xclip\"
|
||||||
},
|
},
|
||||||
@@ -206,41 +234,56 @@ prefix: /
|
|||||||
\"origin\" : \"x11/wl-clipboard\"
|
\"origin\" : \"x11/wl-clipboard\"
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
" > packages/FreeBSDtemp/+MANIFEST
|
" > output/freebsdtemp/+MANIFEST
|
||||||
echo "/bin/python3
|
echo "/usr/bin/sshyp
|
||||||
/usr/bin/sshync.py
|
/usr/lib/sshyp/sshync.py
|
||||||
/usr/bin/sshyp
|
/usr/lib/sshyp/sshyp.py
|
||||||
/usr/bin/sshypRemote.py
|
/usr/share/bash-completion/completions/sshyp
|
||||||
/usr/share/doc/sshyp/changelog
|
/usr/share/doc/sshyp/changelog
|
||||||
/usr/share/licenses/sshyp/license
|
/usr/share/licenses/sshyp/license
|
||||||
/usr/share/man/man1/sshyp.1.gz
|
/usr/share/man/man1/sshyp.1.gz
|
||||||
" > packages/FreeBSDtemp/plist
|
" > output/freebsdtemp/plist
|
||||||
pkg create -m packages/FreeBSDtemp/ -r packages/FreeBSDtemp/ -p packages/FreeBSDtemp/plist -o packages/
|
cp -r lib/. output/freebsdtemp/usr/lib/sshyp/
|
||||||
rm -rf packages/FreeBSDtemp
|
ln -s /usr/lib/sshyp/sshyp.py output/freebsdtemp/usr/bin/sshyp
|
||||||
echo -e "\nFreeBSD packaging complete.\n"
|
cp -r share output/freebsdtemp/usr/
|
||||||
fi
|
cp extra/sshyp-completion.bash output/freebsdtemp/usr/share/bash-completion/completions/sshyp
|
||||||
|
cp extra/manpage output/freebsdtemp/usr/share/man/man1/sshyp.1
|
||||||
|
gzip output/freebsdtemp/usr/share/man/man1/sshyp.1
|
||||||
|
pkg create -m output/freebsdtemp/ -r output/freebsdtemp/ -p output/freebsdtemp/plist -o output/
|
||||||
|
rm -rf output/freebsdtemp
|
||||||
|
echo -e "\nFreeBSD packaging complete\n"
|
||||||
|
} &&
|
||||||
|
|
||||||
if [ "$distro" == "7" ] || [ "$distro" == "8" ]; then
|
if [ "$1" == "generic" ]; then # build scripts
|
||||||
echo -e '\nGenerating PKGBUILD...'
|
_create_generic
|
||||||
echo "# Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
elif [ "$1" == "pkgbuild" ]; then
|
||||||
|
_create_generic
|
||||||
pkgname=sshyp
|
_create_pkgbuild
|
||||||
pkgver="$version"
|
elif [ "$1" == "apkbuild" ]; then
|
||||||
pkgrel="$revision"
|
_create_generic
|
||||||
pkgdesc='A light-weight, self-hosted, synchronized password manager'
|
_create_apkbuild
|
||||||
url='https://github.com/rwinkhart/sshyp'
|
elif [ "$1" == "haiku" ]; then # distribution packages
|
||||||
arch=('any')
|
_create_hpkg
|
||||||
license=('GPL3')
|
elif [ "$1" == "debian" ]; then
|
||||||
depends=(python gnupg openssh nano xclip wl-clipboard)
|
_create_deb
|
||||||
|
elif [ "$1" == "termux" ]; then
|
||||||
source=(\""$source"\")
|
_create_termux
|
||||||
sha512sums=('"$sha512"')
|
elif [ "$1" == "fedora" ]; then
|
||||||
|
_create_generic
|
||||||
package() {
|
_create_rpm
|
||||||
|
elif [ "$1" == "freebsd" ]; then
|
||||||
tar xf sshyp-"\"\$pkgver\"".tar.xz -C "\"\${pkgdir}\""
|
_create_freebsd_pkg
|
||||||
|
elif [ "$1" == "buildable-arch" ]; then
|
||||||
}
|
_create_generic
|
||||||
" > packages/PKGBUILD
|
_create_pkgbuild
|
||||||
echo -e "\nPKGBUILD generated.\n"
|
_create_apkbuild
|
||||||
|
if [[ $(pacman -Q dpkg) == "dpkg"* ]]; then
|
||||||
|
_create_deb
|
||||||
|
_create_termux
|
||||||
|
fi
|
||||||
|
if [[ "$(pacman -Q freebsd-pkg)" == "freebsd-pkg"* ]]; then
|
||||||
|
_create_freebsd_pkg
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo -e '\nusage: package.sh [target] <revision>\n\ntargets:\n mainline: pkgbuild apkbuild haiku fedora debian\n experimental: freebsd termux\n other: buildable-arch\n'
|
||||||
fi
|
fi
|
||||||
|
|||||||
+35
-44
@@ -1,59 +1,50 @@
|
|||||||
sshyp v1.0.1
|
sshyp v1.3.0
|
||||||
|
|
||||||
The Polished Trotters Update - Patch 1
|
the serious shepherd update
|
||||||
|
|
||||||
This is a hotfix for the Haiku decryption bug.
|
this release ties up many of sshyp's loose ends where there was
|
||||||
|
room for major performance, compatibility, and security improvements
|
||||||
|
|
||||||
Changes:
|
compatibility-breaking changes:
|
||||||
|
|
||||||
- subprocess.Popen has been replaced with subprocess.run where applicable
|
- due to a near full re-write of the syncing functionality, all clients and servers
|
||||||
- stdout is no longer captured with any subprocess.Popen or subprocess.run usages
|
must be updated to this release (v1.3.0 is not backwards compatible with any prior release)
|
||||||
^ this fixes decryption on Haiku
|
- it is recommended to either delete the contents of ~/.config/sshyp/deleted (on the server-side)
|
||||||
|
or sync all of your clients before updating
|
||||||
|
^ old entries in this folder will throw errors with v1.3.0
|
||||||
|
|
||||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
user-facing features:
|
||||||
|
|
||||||
sshyp v1.0.0
|
|
||||||
|
|
||||||
The Polished Trotters Update
|
- none - all changes were under-the-hood - the user experience should be
|
||||||
|
exactly the same as v1.2.0 - just faster, less buggy, and more secure
|
||||||
|
|
||||||
This release brings 'sshyp' in line with the original goals of the project.
|
major fixes/optimizations:
|
||||||
As such, it is being crowned "v1.0.0", and is considered a stable base for future expansions.
|
|
||||||
|
|
||||||
Features:
|
- a near full re-write of the syncing functionality
|
||||||
|
^ all syncing logic has been moved into sshync.py (from sshyp.py and sshypRemote.py)
|
||||||
|
^ in my setup, a dry, local "sshyp sync" went from 2.00+ seconds (v1.2.0) to 0.36 seconds (v1.3.0)
|
||||||
|
^ the performance improvements are even greater when syncing from outside your local network
|
||||||
|
- the following character sequences will no longer break the syncing logic: "@", "^&*", and "*&^"
|
||||||
|
^ ASCII separator characters 29-31 are now used, instead
|
||||||
|
- os.system has been replaced with subprocess.run in all cases, shell=True is no longer used with subprocess.run
|
||||||
|
^ this protects against shell escape attacks and potentially makes sshyp more compatible with some environments
|
||||||
|
- replaced shell commands with python built-in library functions where applicable
|
||||||
|
^ this brings speed and compatibility improvements
|
||||||
|
- sshyp should no longer incorrectly assume an X11 environment when Wayland is in use
|
||||||
|
^ this fixes clipboard support in some Wayland environments, such as Sway (Plasma/Gnome/Phosh were unaffected)
|
||||||
|
- sshyp now uses the default pinentry on Haiku thanks to haikuports/haikuports#7457
|
||||||
|
^ this brings the Haiku port in-line with the other sshyp packages in terms of security
|
||||||
|
- "python3" is now called over ssh, rather than "python"
|
||||||
|
^ some environments do not have a "python" symlink, or it links to "python2" - changing this increases compatibility
|
||||||
|
- fixed an issue from v1.2.0 where renaming threw an error if not in offline mode
|
||||||
|
|
||||||
- sshyp has been modified to run on Haiku, an open-source re-implementation of BeOS
|
other notable changes:
|
||||||
^ new package formats have been added for Haiku, FreeBSD, and Fedora Linux
|
|
||||||
- the entry format has been changed to support entries created in pass/password-store
|
|
||||||
^ this change requires existing entry libraries to be converted - see the sshyp v1.0.0 release page on GitHub for a conversion script
|
|
||||||
- majorly overhauled visual experience for sshyp
|
|
||||||
^ this includes a new entry list, a new entry readout, colored output, ascii art, and more!
|
|
||||||
- entries can now optionally be passed as arguments, directly
|
|
||||||
^ as opposed to the user being prompted for an entry name after running a command
|
|
||||||
|
|
||||||
Changes:
|
- quick-unlock password input is now hidden while the user is typing
|
||||||
|
^ user input is now invisible to prevent snooping
|
||||||
- corrected outdated licensing and copyright information
|
- lots of smaller optimizations not listed here
|
||||||
- 'if __name__=="__main__":' convention is now used
|
|
||||||
- help screens have been overhauled
|
|
||||||
- improved password generator to guarantee more secure results
|
|
||||||
- fixed errors when trying to sync with a multi-word entry on the server
|
|
||||||
- sshync now uses 'scp' (via the sftp protocol), rather than 'sftp'
|
|
||||||
- rename function now properly allows for renaming folders
|
|
||||||
- renaming an entry/folder will now properly delete the old entry/folder from the server
|
|
||||||
- entry previews at the time of entry creation/editing no longer require entering the gpg password more times than necessary
|
|
||||||
- entries will no longer be overwritten if attempting to create a new entry that uses an already existing name
|
|
||||||
- the clipboard now automatically clears after 30 seconds
|
|
||||||
- sshyp server no longer needs to create copies of its libraries in ~/
|
|
||||||
- added more and improved existing exceptions
|
|
||||||
- the lock file is now decrypted to /dev/null
|
|
||||||
- ...and lots of minor (under the hood) changes!
|
|
||||||
|
|
||||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||||
|
|
||||||
The full history of changes to "sshyp" can be found on the following page:
|
The full history of changes to "sshyp" can be found on the following page:
|
||||||
https://raw.githubusercontent.com/rwinkhart/sshyp/main/extra/changelog-total
|
https://raw.githubusercontent.com/rwinkhart/sshyp/main/extra/changelog-total
|
||||||
|
|
||||||
Legend:
|
|
||||||
|
|
||||||
- = feature/change implemented and pushed upstream
|
|
||||||
^ = note regarding the above feature/change
|
|
||||||
|
|||||||
Executable → Regular
+3
-4
@@ -2,9 +2,8 @@
|
|||||||
Copyright (C) 2022 Randall Winkhart idgr@tutanota.com
|
Copyright (C) 2022 Randall Winkhart idgr@tutanota.com
|
||||||
|
|
||||||
This program is free software: you can redistribute it and/or modify
|
This program is free software: you can redistribute it and/or modify
|
||||||
it under the terms of the GNU General Public License as published by
|
it under the terms of version 3 (only) of the GNU General Public License
|
||||||
the Free Software Foundation, either version 3 of the License, or
|
as published by the Free Software Foundation.
|
||||||
(at your option) any later version.
|
|
||||||
|
|
||||||
This program is distributed in the hope that it will be useful,
|
This program is distributed in the hope that it will be useful,
|
||||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
@@ -12,4 +11,4 @@
|
|||||||
GNU General Public License for more details.
|
GNU General Public License for more details.
|
||||||
|
|
||||||
You should have received a copy of the GNU General Public License
|
You should have received a copy of the GNU General Public License
|
||||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||||
|
|||||||
Reference in New Issue
Block a user