mirror of
https://github.com/rwinkhart/sshyp.git
synced 2026-09-03 07:37:16 -04:00
Compare commits
399
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3a6655e977 | ||
|
|
9d1f0a065b | ||
|
|
8298966d8f | ||
|
|
d4d9fb88fd | ||
|
|
2beeb1dc38 | ||
|
|
86ad4e5cad | ||
|
|
e55c812a06 | ||
|
|
a0351d19d3 | ||
|
|
90c15bcda8 | ||
|
|
cb754c5ba7 | ||
|
|
9979de26d0 | ||
|
|
4207ecb555 | ||
|
|
8bcfd3fcd8 | ||
|
|
78588f686e | ||
|
|
4753bb4c37 | ||
|
|
81ccdf71ea | ||
|
|
67eb1a44ca | ||
|
|
8af7de10a7 | ||
|
|
3108a072dd | ||
|
|
65be0eaf6f | ||
|
|
bb34025c31 | ||
|
|
278231fe40 | ||
|
|
7356777e50 | ||
|
|
5a33eb26f0 | ||
|
|
d796c48ede | ||
|
|
b1fd934b96 | ||
|
|
9848d38a0b | ||
|
|
2ab409e95e | ||
|
|
64d46f1746 | ||
|
|
e9c787cfe3 | ||
|
|
c200b5bbec | ||
|
|
b6593e609b | ||
|
|
32b0c39fb6 | ||
|
|
6b8e24b0b2 | ||
|
|
2d47f42414 | ||
|
|
a773056202 | ||
|
|
097aca8c43 | ||
|
|
275b07e53f | ||
|
|
46d539f386 | ||
|
|
0adf00d81e | ||
|
|
46b212988f | ||
|
|
3e8772786a | ||
|
|
3a01157cb3 | ||
|
|
079a1412ae | ||
|
|
359edcd46c | ||
|
|
60c2920f3c | ||
|
|
a3cd6a1f17 | ||
|
|
8c2b7df1da | ||
|
|
994eaee49b | ||
|
|
8f0eb1134a | ||
|
|
c95643ca89 | ||
|
|
35ea8bf7d7 | ||
|
|
60431b623c | ||
|
|
185ae4ebff | ||
|
|
1e290a1f26 | ||
|
|
71157633df | ||
|
|
03487348ea | ||
|
|
2d20ddbb97 | ||
|
|
21287ca57f | ||
|
|
612f288904 | ||
|
|
0fbe084ff7 | ||
|
|
fdf90e043a | ||
|
|
b89158d0bb | ||
|
|
dede7cf8ac | ||
|
|
6d3ba2714b | ||
|
|
09991a2a30 | ||
|
|
c5884024de | ||
|
|
1e2166ddaf | ||
|
|
86487b8ae5 | ||
|
|
fa05312d49 | ||
|
|
71d942ffae | ||
|
|
cc1a099363 | ||
|
|
d6342faf84 | ||
|
|
c7cae5303a | ||
|
|
1d80cb08ce | ||
|
|
8163aee868 | ||
|
|
7c061f561f | ||
|
|
339d20bc3e | ||
|
|
434f5f85cd | ||
|
|
22d9605781 | ||
|
|
d644f8df01 | ||
|
|
551789636d | ||
|
|
9ab175a8d8 | ||
|
|
e5a4d80e3b | ||
|
|
0920dcf004 | ||
|
|
e18b3b4d0a | ||
|
|
ffccc88a1d | ||
|
|
e1ec834e5c | ||
|
|
018d0c511d | ||
|
|
55b94fc4cc | ||
|
|
3f9c4e2c8d | ||
|
|
166ac50f42 | ||
|
|
df1c6482a8 | ||
|
|
38c6ef3d1b | ||
|
|
7bea6093b8 | ||
|
|
f9ca6f8e94 | ||
|
|
75d8eb7b7d | ||
|
|
39316d04a2 | ||
|
|
3e9a4c0403 | ||
|
|
3bc07b48ef | ||
|
|
5234e8c048 | ||
|
|
b7c3535955 | ||
|
|
1f52c45c43 | ||
|
|
7723baa69e | ||
|
|
b680cc96d6 | ||
|
|
f750fe1e4d | ||
|
|
b96db3ad92 | ||
|
|
224fc1fc6d | ||
|
|
0bd2e45dba | ||
|
|
6410843911 | ||
|
|
3dda6d8428 | ||
|
|
4f31af5eff | ||
|
|
bfb830c5e5 | ||
|
|
790121e7ea | ||
|
|
4168b800f8 | ||
|
|
801d515697 | ||
|
|
379970d53b | ||
|
|
4abb3ed718 | ||
|
|
6690fd15c9 | ||
|
|
1582e73a98 | ||
|
|
dfe1703e62 | ||
|
|
7a76130b26 | ||
|
|
98dcbf57c6 | ||
|
|
a5946d558a | ||
|
|
30fb5ed041 | ||
|
|
fb1f5b92c3 | ||
|
|
61b2186b0a | ||
|
|
2113b93481 | ||
|
|
2030d90114 | ||
|
|
75071601e6 | ||
|
|
9a0a261d55 | ||
|
|
4ca2d89464 | ||
|
|
f90ec5c900 | ||
|
|
fa0a4fe0b8 | ||
|
|
c85a9d2ccd | ||
|
|
43351fd66f | ||
|
|
096bdb0773 | ||
|
|
330396c5f1 | ||
|
|
8576f63479 | ||
|
|
393f241538 | ||
|
|
c557d5bfee | ||
|
|
acca7d888c | ||
|
|
2f3b3c67ba | ||
|
|
88d2402e88 | ||
|
|
928aacc64a | ||
|
|
094bdcb418 | ||
|
|
419ff51e75 | ||
|
|
2111a0454e | ||
|
|
5d902f0324 | ||
|
|
505ffdb489 | ||
|
|
5cab1ad091 | ||
|
|
2e2404636b | ||
|
|
6cb5bd405f | ||
|
|
c93965c9a5 | ||
|
|
d685e07d32 | ||
|
|
192f58fef5 | ||
|
|
106f22f757 | ||
|
|
ae414dadda | ||
|
|
c9e99732a2 | ||
|
|
fc37368447 | ||
|
|
ca2bc98735 | ||
|
|
f44391612d | ||
|
|
8c0e9eb6df | ||
|
|
c03e818560 | ||
|
|
0b653000ef | ||
|
|
9f89dce42b | ||
|
|
e7b2e19039 | ||
|
|
80b6b4abd2 | ||
|
|
758e9f331c | ||
|
|
ba14c0e74b | ||
|
|
1991672618 | ||
|
|
9b600dabbf | ||
|
|
e42641079d | ||
|
|
7c6cbaec35 | ||
|
|
cb441933db | ||
|
|
dad1a34575 | ||
|
|
3a30812de5 | ||
|
|
e1930f9457 | ||
|
|
05df3dd903 | ||
|
|
5c1195f42d | ||
|
|
30aa3e2438 | ||
|
|
a8ea1eb444 | ||
|
|
8e053f25b8 | ||
|
|
a175a270e0 | ||
|
|
d116582144 | ||
|
|
f760b5420c | ||
|
|
6498a076f2 | ||
|
|
f4a0c52ca8 | ||
|
|
ffafbd2b91 | ||
|
|
d7bf7da177 | ||
|
|
13d466bb21 | ||
|
|
7aa9ea63e2 | ||
|
|
208bd8707b | ||
|
|
fb398333a6 | ||
|
|
b369f9a530 | ||
|
|
747f83819d | ||
|
|
2f1e693991 | ||
|
|
dd811cbe35 | ||
|
|
87dee4f197 | ||
|
|
bf86d72472 | ||
|
|
a3722e3c29 | ||
|
|
1f4d5b0591 | ||
|
|
e21faa8bbb | ||
|
|
309a471e77 | ||
|
|
968a7322f8 | ||
|
|
75e152ebfe | ||
|
|
15204fb0e9 | ||
|
|
5977367f28 | ||
|
|
96eb80226f | ||
|
|
9ede33d3d8 | ||
|
|
4093c36d48 | ||
|
|
947754f87c | ||
|
|
84bfefb7b1 | ||
|
|
7ac5cd723e | ||
|
|
68aa5eee04 | ||
|
|
f869e3b45d | ||
|
|
551f1e8f50 | ||
|
|
1687d9e1e2 | ||
|
|
930595ecad | ||
|
|
2d00da0e18 | ||
|
|
c84d52fb8d | ||
|
|
88fd9e77a9 | ||
|
|
4258ad85ab | ||
|
|
337e68d088 | ||
|
|
fb8c5be284 | ||
|
|
0293d273a7 | ||
|
|
40a43ed86d | ||
|
|
18c78743ca | ||
|
|
2f5080fec0 | ||
|
|
99e0d5f666 | ||
|
|
be19e271c5 | ||
|
|
20d2de338f | ||
|
|
e830d8486b | ||
|
|
5fc74ac2b3 | ||
|
|
24acd1cb87 | ||
|
|
0079934354 | ||
|
|
399e291902 | ||
|
|
66a026e327 | ||
|
|
b5f4e776e5 | ||
|
|
0056f60af1 | ||
|
|
41aa093685 | ||
|
|
30034be36f | ||
|
|
a43530d34f | ||
|
|
7d14c49490 | ||
|
|
462ba05833 | ||
|
|
e89bf06d9a | ||
|
|
d33d07894f | ||
|
|
cade83a0f0 | ||
|
|
100edd07ea | ||
|
|
d19651819a | ||
|
|
d951284bcd | ||
|
|
3c9b80ec80 | ||
|
|
0f3d9854b7 | ||
|
|
0c52149c40 | ||
|
|
f838af0b4e | ||
|
|
72f126d21d | ||
|
|
2385f669f8 | ||
|
|
b8896a6b58 | ||
|
|
51ec2143e3 | ||
|
|
4c1989287a | ||
|
|
daba737ca6 | ||
|
|
8cac27c6f6 | ||
|
|
19d37dfdb6 | ||
|
|
87a56a80bd | ||
|
|
5aaa284cbf | ||
|
|
a6aa0561b4 | ||
|
|
b08456e873 | ||
|
|
ef828b88a0 | ||
|
|
bde243c644 | ||
|
|
894f406fd2 | ||
|
|
00b935f1bb | ||
|
|
49608cb839 | ||
|
|
a417478aa0 | ||
|
|
344c74b728 | ||
|
|
fc0e4bb4a5 | ||
|
|
37867cb673 | ||
|
|
86aa7da038 | ||
|
|
9231257af8 | ||
|
|
102f22143f | ||
|
|
3dd12b4d6d | ||
|
|
a0b5dad073 | ||
|
|
2ba19f9a39 | ||
|
|
8af71ceb1a | ||
|
|
81c9b35c75 | ||
|
|
eeabc18f18 | ||
|
|
73128665fb | ||
|
|
607a4709f6 | ||
|
|
c643e861d9 | ||
|
|
23e7e375ae | ||
|
|
b8743d5fe2 | ||
|
|
e95aa85453 | ||
|
|
caf130568e | ||
|
|
f65adc17f3 | ||
|
|
fc2f42a1aa | ||
|
|
8403f4af98 | ||
|
|
4b24df0e97 | ||
|
|
ca007f55ac | ||
|
|
7afcfdb43d | ||
|
|
5178377827 | ||
|
|
ff9241368e | ||
|
|
6014de98dd | ||
|
|
6e7e42a69e | ||
|
|
0314bf36af | ||
|
|
93ac4ef824 | ||
|
|
65d10551f6 | ||
|
|
f6ddf2ad37 | ||
|
|
7f00570249 | ||
|
|
3d7f08e43e | ||
|
|
d82c9b5e02 | ||
|
|
9133a73553 | ||
|
|
ad039d6322 | ||
|
|
caa5fad0bc | ||
|
|
68ded52e8c | ||
|
|
85c59b302d | ||
|
|
954dd30361 | ||
|
|
65d1885311 | ||
|
|
5a7b45c3ac | ||
|
|
e5638255a8 | ||
|
|
2e32911470 | ||
|
|
4973d18034 | ||
|
|
6e13a6ebb3 | ||
|
|
dfbdc16079 | ||
|
|
3c4bf0115f | ||
|
|
762211bae0 | ||
|
|
d9adcac8ec | ||
|
|
1d9000ab16 | ||
|
|
bdea49268d | ||
|
|
187ea39861 | ||
|
|
ee8e7fc8a5 | ||
|
|
8a4ae469fa | ||
|
|
4330617060 | ||
|
|
54397dcd13 | ||
|
|
0e7595489b | ||
|
|
cd378aadc2 | ||
|
|
d26c2a5e08 | ||
|
|
b24bcdd413 | ||
|
|
b0fa1f99c9 | ||
|
|
2825b43659 | ||
|
|
49721cd39a | ||
|
|
715d58fb62 | ||
|
|
73307e2b3c | ||
|
|
ab739e3920 | ||
|
|
0253872c8d | ||
|
|
2d2b0aa0ec | ||
|
|
532784d817 | ||
|
|
6d1bf9f96c | ||
|
|
67a7c2e382 | ||
|
|
9f229e7ae7 | ||
|
|
e3b0d2dbe7 | ||
|
|
ce4e32c8f4 | ||
|
|
0fb339a2ab | ||
|
|
51ac1a49fd | ||
|
|
87576338fd | ||
|
|
6116de41b1 | ||
|
|
a218e77e41 | ||
|
|
e00fd64c66 | ||
|
|
e2f45c7cac | ||
|
|
700d5701fd | ||
|
|
ac6f6f279f | ||
|
|
019aa58411 | ||
|
|
398ac8a04a | ||
|
|
d63c663dd0 | ||
|
|
078d6026e0 | ||
|
|
76c4fff520 | ||
|
|
2ba2dd57e4 | ||
|
|
e64ef1103d | ||
|
|
d3971af85b | ||
|
|
7840f47b9f | ||
|
|
21785ce380 | ||
|
|
c716073525 | ||
|
|
c64a4fedb1 | ||
|
|
81263ac375 | ||
|
|
ec079f996a | ||
|
|
edad359330 | ||
|
|
649c405d49 | ||
|
|
0f382af9c8 | ||
|
|
b7e129e0dd | ||
|
|
dc63176263 | ||
|
|
5e5e6ea905 | ||
|
|
6b4eeabfc0 | ||
|
|
2600eae464 | ||
|
|
3152201ead | ||
|
|
2b31d00f32 | ||
|
|
61c7543cfa | ||
|
|
246c84ff1f | ||
|
|
23ad878a71 | ||
|
|
8ff7705577 | ||
|
|
b0213eca8e | ||
|
|
9efeca546a | ||
|
|
b21a60ca88 | ||
|
|
9095cf9e74 | ||
|
|
f15b90d32a | ||
|
|
29cc47c8d9 | ||
|
|
f7ee816c62 | ||
|
|
aee22ba779 | ||
|
|
83ef92da63 | ||
|
|
27eab28fc9 | ||
|
|
8a4b5d72d1 | ||
|
|
801177d386 |
@@ -0,0 +1,72 @@
|
||||
# For most projects, this workflow file will not need changing; you simply need
|
||||
# to commit it to your repository.
|
||||
#
|
||||
# You may wish to alter this file to override the set of languages analyzed,
|
||||
# or to provide custom queries or build logic.
|
||||
#
|
||||
# ******** NOTE ********
|
||||
# We have attempted to detect the languages in your repository. Please check
|
||||
# the `language` matrix defined below to confirm you have the correct set of
|
||||
# supported CodeQL languages.
|
||||
#
|
||||
name: "CodeQL"
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ "main" ]
|
||||
pull_request:
|
||||
# The branches below must be a subset of the branches above
|
||||
branches: [ "main" ]
|
||||
schedule:
|
||||
- cron: '34 22 * * 5'
|
||||
|
||||
jobs:
|
||||
analyze:
|
||||
name: Analyze
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
security-events: write
|
||||
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
language: [ 'python' ]
|
||||
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
|
||||
# Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v3
|
||||
|
||||
# Initializes the CodeQL tools for scanning.
|
||||
- name: Initialize CodeQL
|
||||
uses: github/codeql-action/init@v2
|
||||
with:
|
||||
languages: ${{ matrix.language }}
|
||||
# If you wish to specify custom queries, you can do so here or in a config file.
|
||||
# By default, queries listed here will override any specified in a config file.
|
||||
# Prefix the list here with "+" to use these queries and those in the config file.
|
||||
|
||||
# Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
|
||||
# queries: security-extended,security-and-quality
|
||||
|
||||
|
||||
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
|
||||
# If this step fails, then you should remove it and run the build manually (see below)
|
||||
- name: Autobuild
|
||||
uses: github/codeql-action/autobuild@v2
|
||||
|
||||
# ℹ️ Command-line programs to run using the OS shell.
|
||||
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
|
||||
|
||||
# If the Autobuild fails above, remove it and uncomment the following three lines.
|
||||
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.
|
||||
|
||||
# - run: |
|
||||
# echo "Run, Build Application using script"
|
||||
# ./location_of_script_within_repo/buildscript.sh
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@v2
|
||||
@@ -1,22 +0,0 @@
|
||||
# Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
|
||||
pkgname=sshyp
|
||||
pkgver=2021.11.05.fr1
|
||||
pkgrel=1
|
||||
pkgdesc='A self-hosted, synchronized password manager'
|
||||
url='https://github.com/rwinkhart/sshyp'
|
||||
arch=('x86_64' 'aarch64')
|
||||
license=('GPL3')
|
||||
depends=( python gnupg openssh nano xclip wl-clipboard)
|
||||
|
||||
source_x86_64=('https://github.com/rwinkhart/sshyp/releases/download/v2021.11.05.fr1/sshyp-2021.11.05.fr1.tar.xz')
|
||||
source_aarch64=('https://github.com/rwinkhart/sshyp/releases/download/v2021.11.05.fr1/sshyp-2021.11.05.fr1.tar.xz')
|
||||
sha512sums_x86_64=('dcc2fe2e751120ffed86cad5f170bdf6ba4ef96df4c4cc784496289c7fda1ccef5ded030ce20f4ea6571a0def5bc185037b39f0958958a1aadb1ead63291b879')
|
||||
sha512sums_aarch64=('dcc2fe2e751120ffed86cad5f170bdf6ba4ef96df4c4cc784496289c7fda1ccef5ded030ce20f4ea6571a0def5bc185037b39f0958958a1aadb1ead63291b879')
|
||||
|
||||
package() {
|
||||
|
||||
tar xf sshyp-"$pkgver".tar.xz -C "${pkgdir}"
|
||||
chown -R "$USER" ${pkgdir}/var/lib/sshyp
|
||||
|
||||
}
|
||||
@@ -1,8 +1,18 @@
|
||||
# sshyp
|
||||
A very simple self-hosted, synchronized password manager. Alternative to GNU pass.
|
||||

|
||||
|
||||
"sshyp" stands for "sshync passwords", or "ssh sync passwords".
|
||||
"sshync" is the custom syncing backend (based on sftp) used by "sshyp".
|
||||
[](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml)
|
||||
|
||||
pronounced as: 'sheep', 'shēp'
|
||||
|
||||
sshyp is a very simple self-hosted, synchronized password manager for UNIX(-like) systems (currently Haiku/FreeBSD/Linux).
|
||||
|
||||
sshyp is compatible with entries created by pass/password-store, as its original goal was to be like pass/password-store, but far more user-friendly to synchronize with a self-hosted server.
|
||||
|
||||
sshyp is (as of writing) the only password-store compatible CLI password manager available for Haiku.
|
||||
|
||||
sshyp makes use of a custom sftp wrapper, called sshync (ssh+sync), to reliably sync user entries with a local or remote server.
|
||||
|
||||
The name "sshyp" is a combination of its syncing library, "sshync", and "passwords".
|
||||
|
||||
# WARNING
|
||||
It is your responsibility to assess the security and stability of "sshyp" before using it and ensure it meets your needs.
|
||||
@@ -16,45 +26,55 @@ What sshyp can do:
|
||||
|
||||
- securely manage a collection of encrypted passwords and notes via CLI
|
||||
- generate new, secure passwords to the user's choice in length and complexity
|
||||
- securely sync said passwords and notes seamlessly between multiple POSIX compliant Unix devices
|
||||
|
||||
What sshyp will do:
|
||||
|
||||
- everything it already does, but also in a GUI for Linux/Android
|
||||
- have a distinct retro theme
|
||||
- receive many usability enhancements
|
||||
- securely sync said passwords and notes seamlessly between devices (or just manage them offline)
|
||||
- utilize [extensions](https://github.com/rwinkhart/sshyp-labs) to interact with your entries is additional ways (such as generating TOTP keys or managing your entries in a GUI)
|
||||
- everything above with entries created by pass/password-store!
|
||||
- everything above on Haiku, FreeBSD, Linux, and Termux (an Android terminal emulator)!
|
||||
|
||||
What sshyp definitely won't do:
|
||||
|
||||
- 2FA/MFA (for security purposes, this should not be handled by your password manager)
|
||||
- Windows support (I don't use Windows and I have no interest in developing for it)
|
||||
- Non-UNIX(-like) support, e.g. Windows (I'd be happy to link to third-party ports, if someone were to make them)
|
||||
|
||||
# Installation
|
||||
Arch Linux (x86_64, aarch64)
|
||||
Please see the [installation guide](https://github.com/rwinkhart/sshyp/wiki/Installation) in the sshyp wiki for directions specific to your distribution/OS.
|
||||
|
||||
Note: currently unavailable in the AUR (the older version, "rpass", will remain available until sshyp is stable)
|
||||
Pre-built packages exist for Haiku, FreeBSD, Alpine Linux, Arch Linux, Debian/Ubuntu Linux, Fedora Linux, and Termux. These can be downloaded from the releases page.
|
||||
|
||||
sshyp releases will be available in the Arch User Repository as 'sshyp'.
|
||||
Requests for additional distribution/OS support can be filed as issues.
|
||||
|
||||
Install with your preferred AUR helper or use:
|
||||
Extensions are available in the [sshyp-labs](https://github.com/rwinkhart/sshyp-labs) repository.
|
||||
|
||||
Bash completions can be enabled by installing your distribution's "bash-completion" package and restarting your terminal.
|
||||
|
||||
# Building
|
||||
Since sshyp is written entirely in Python, it doesn't need to be compiled. It does, however, need to be packaged for installation.
|
||||
|
||||
A packaging script is included in the root directory of the repo in order to package sshyp for your distribution. To package sshyp from source, simply run:
|
||||
|
||||
```
|
||||
git clone https://aur.archlinux.org/sshyp.git
|
||||
git clone https://github.com/rwinkhart/sshyp.git
|
||||
cd sshyp
|
||||
makepkg -si
|
||||
./package.sh [target] <revision>
|
||||
```
|
||||
|
||||
Packaging for other distributions coming soon.
|
||||
The packaging script has been tested on Arch Linux with "dpkg" as a dependency for Debian/Ubuntu and Termux packaging and "freebsd-pkg" as a dependency for FreeBSD packaging.
|
||||
|
||||
Haiku and Fedora packaging must be done on their own respective distributions.
|
||||
|
||||
The AUR version and the packages attatched to the release tags were already packaged using this script.
|
||||
|
||||
Currently, the script can create packages for Haiku, FreeBSD, Alpine Linux (APKBUILD), Arch Linux (PKGBUILD), Debian/Ubuntu Linux, Fedora Linux, Termux, and generic.
|
||||
|
||||
# Usage
|
||||
Upon initial installation, be sure to run:
|
||||
Upon initial installation (on both the server and client devices), be sure to run:
|
||||
|
||||
```
|
||||
sshyp config
|
||||
sshyp tweak
|
||||
```
|
||||
|
||||
This command will allow you to configure the settings necessary for sshyp to function.
|
||||
As of right now, sshyp is rapidly changing, and as such, it is a good idea to run "sshyp config" after each update.
|
||||
This command will allow you to configure the settings necessary for sshyp to function. To ensure configuration compatibility, it is a good idea to run 'sshyp tweak' after each major update.
|
||||
|
||||
Please note that decrypting and reading entries is disabled on server devices for security reasons. Only devices configured as clients can use the gpg key to decrypt entries.
|
||||
|
||||
All available options can be found with:
|
||||
|
||||
@@ -62,21 +82,20 @@ All available options can be found with:
|
||||
sshyp --help
|
||||
```
|
||||
|
||||
Or alternatively, in the manpage:
|
||||
|
||||
```
|
||||
man sshyp
|
||||
```
|
||||
|
||||
# Roadmap
|
||||
Short-term Goals:
|
||||
|
||||
- re-write bad, leftover "rpass" code
|
||||
- create new file list w/color and w/o file extensions
|
||||
- create a man page
|
||||
- overhaul argument system
|
||||
- fix lots of bugs!
|
||||
- make lots of optimizations!
|
||||
|
||||
Medium-term Goals:
|
||||
|
||||
- create minimal GUI apps (Linux x86_64, Linux aarch64, Android aarch64)
|
||||
- auto-completion on tab for CLI version
|
||||
- create minimal GUI app (Linux x86_64, Linux aarch64) - being done as an [extension](https://github.com/rwinkhart/sshyp-labs)
|
||||
- significant optimizations
|
||||
- vaious bug fixes
|
||||
|
||||
Long-term Goals:
|
||||
|
||||
- a fun surprise
|
||||
- seize the thrones, shear the humans
|
||||
|
||||
-216
@@ -1,216 +0,0 @@
|
||||
#!/usr/bin/python3
|
||||
|
||||
# Main Targets:
|
||||
# TODO Make it so that when a new folder is created in sshyp, it is automatically created on the remote server
|
||||
# TODO Replace references to sshyp directory with a changeable variable
|
||||
# TODO Clean everything up and move sshync to a separate package
|
||||
# TODO Add dry run support
|
||||
# TODO use partition command instead of split for separating paths
|
||||
# TODO use classes!
|
||||
|
||||
# sshync 2021.11.05.unreleased5
|
||||
# sshync was created to solve a problem with rpass/sshyp, and as such, sshync will be bundled with sshyp until it is
|
||||
# polished enough for a standalone release
|
||||
|
||||
# sshync is a wrapper around sftp that allows easy remote directory synchronization via Python
|
||||
# openssh (on POSIX compliant Unix) is required
|
||||
|
||||
# sshync will always overwrite the older files with the newer files, regardless of all other conditions
|
||||
# ^the age is determined by the date and time of the last modification to the files
|
||||
|
||||
# syncing via sshync is always done recursively
|
||||
|
||||
# external modules
|
||||
|
||||
from os import walk
|
||||
from os import system as term
|
||||
from os.path import getmtime
|
||||
from os.path import join as path_join
|
||||
|
||||
|
||||
# internal modules
|
||||
|
||||
|
||||
# recursively scans a local directory for all files and saves file paths and mod times to lists
|
||||
def get_file_paths_mod(directory, name_database, time_database):
|
||||
file_paths = []
|
||||
temp_mod_times = []
|
||||
mod_times = []
|
||||
for root, directories, files in walk(directory):
|
||||
for filename in files:
|
||||
filepath = path_join(root, filename)
|
||||
file_paths.append(filepath)
|
||||
temp_mod_times.append(str(getmtime(filepath)))
|
||||
for time in temp_mod_times:
|
||||
mod_times.append(round(float(time), 2))
|
||||
open(name_database, 'w').write(str(file_paths))
|
||||
open(time_database, 'w').write(str(mod_times))
|
||||
return file_paths, mod_times
|
||||
|
||||
|
||||
# recursively scans a remote directory for all files and saves file paths and mod times to lists
|
||||
def get_file_paths_mod_remote(profile_dir):
|
||||
# import profile data
|
||||
profile_data = get_profile(profile_dir)
|
||||
user = profile_data[0].replace('\n', '')
|
||||
ip = profile_data[1].replace('\n', '')
|
||||
port = profile_data[2].replace('\n', '')
|
||||
remote_dir = profile_data[4].replace('\n', '')
|
||||
identity = profile_data[5].replace('\n', '')
|
||||
term("ssh -i " + "'" + identity + "'" + " -p " + port + " " + user + "@" + ip + " \"python -c \'import sshync; "
|
||||
"sshync.get_file_paths_mod(" +
|
||||
"\"'\"" + remote_dir + "/\"'\", " + "\"'\"/var/lib/sshyp/sshyncdatabase_names\"'\", " +
|
||||
"\"'\"/var/lib/sshyp/sshyncdatabase_times\"'\")\'\"")
|
||||
term(
|
||||
'sftp -P ' + port + ' ' + user + '@' + ip + ':/var/lib/sshyp/sshyncdatabase_names ' +
|
||||
'/var/lib/sshyp/sshyncdatabase_names')
|
||||
term(
|
||||
'sftp -P ' + port + ' ' + user + '@' + ip + ':/var/lib/sshyp/sshyncdatabase_times ' +
|
||||
'/var/lib/sshyp/sshyncdatabase_times')
|
||||
remote_mod_names = (open('/var/lib/sshyp/sshyncdatabase_names').read()).replace('[', '').replace(']', '').replace(
|
||||
' ', '').replace("'", '').split(',')
|
||||
remote_mod_times = (open('/var/lib/sshyp/sshyncdatabase_times').read()).replace('[', '').replace(']', '').replace(
|
||||
' ', '').replace("'", '').split(',')
|
||||
return remote_mod_names, remote_mod_times
|
||||
|
||||
|
||||
# regular profiles check the mod time of every individual file in the directory, making them slow but versatile
|
||||
def make_profile(profile_dir, local_dir, remote_dir, identity, ip, port, user):
|
||||
open(profile_dir, 'w').write(user + '\n' + ip + '\n' + port + '\n' + local_dir + '\n' + remote_dir + '\n' + identity
|
||||
+ '\n')
|
||||
|
||||
|
||||
# returns the settings for a specified profile
|
||||
def get_profile(profile_dir):
|
||||
try:
|
||||
profile_data = open(profile_dir).readlines()
|
||||
except (FileNotFoundError, IndexError):
|
||||
profile_data = 0
|
||||
return profile_data
|
||||
|
||||
|
||||
# sorts name lists so that local and remote are in the same order
|
||||
def name_sort(local_names, remote_names):
|
||||
remote_names_new = []
|
||||
for ele in local_names:
|
||||
if ele in remote_names:
|
||||
remote_names_new.append(ele)
|
||||
for ele in remote_names:
|
||||
if ele not in remote_names_new:
|
||||
remote_names_new.append(ele)
|
||||
return remote_names_new
|
||||
|
||||
|
||||
# sorts time lists to compensate for name list re-ordering
|
||||
def time_sort(old_names, new_names, old_times):
|
||||
remote_mod_times_new = []
|
||||
new_pos = -1
|
||||
for title in new_names:
|
||||
new_pos += 1
|
||||
if title in old_names:
|
||||
old_pos = old_names.index(title)
|
||||
try:
|
||||
remote_mod_times_new.append(old_times[old_pos])
|
||||
except IndexError:
|
||||
pass
|
||||
return remote_mod_times_new
|
||||
|
||||
|
||||
getter_loop_count = -1
|
||||
|
||||
|
||||
def loop_getter(split_remote_dir):
|
||||
global getter_loop_count
|
||||
getter_loop_count += 1
|
||||
new_var = split_remote_dir[getter_loop_count] + '/'
|
||||
return new_var
|
||||
|
||||
|
||||
def run_profile(profile_dir):
|
||||
# import profile data
|
||||
profile_data = get_profile(profile_dir)
|
||||
user = profile_data[0].replace('\n', '')
|
||||
ip = profile_data[1].replace('\n', '')
|
||||
port = profile_data[2].replace('\n', '')
|
||||
local_dir = profile_data[3].replace('\n', '')
|
||||
remote_dir = profile_data[4].replace('\n', '')
|
||||
identity = profile_data[5].replace('\n', '')
|
||||
# get file modification times
|
||||
local_mod_names, local_mod_times = get_file_paths_mod(local_dir + '/', '/var/lib/sshyp/sshyncdatabase_names',
|
||||
'/var/lib/sshyp/sshyncdatabase_times')
|
||||
remote_mod_times = []
|
||||
remote_mod_names, remote_mod_times_temp = get_file_paths_mod_remote('/var/lib/sshyp/sshyp.sshync')
|
||||
try:
|
||||
for time in remote_mod_times_temp: # remove quotes from remote_mod_times
|
||||
remote_mod_times.append(float(time))
|
||||
except ValueError:
|
||||
pass
|
||||
lmod_short = []
|
||||
rmod_short = []
|
||||
matching_names = []
|
||||
matching_times_local = []
|
||||
matching_times_remote = []
|
||||
for lmod in local_mod_names:
|
||||
lmod_short.append(lmod.replace(local_dir, ''))
|
||||
for rmod in remote_mod_names:
|
||||
rmod_short.append(rmod.replace(remote_dir, ''))
|
||||
rmod_short_old = rmod_short
|
||||
rmod_short = name_sort(lmod_short, rmod_short)
|
||||
remote_mod_times = time_sort(rmod_short_old, rmod_short, remote_mod_times)
|
||||
i = -1
|
||||
for lshort in lmod_short:
|
||||
i += 1
|
||||
if lshort in rmod_short:
|
||||
matching_names.append(lshort)
|
||||
matching_times_local.append(local_mod_times[i])
|
||||
else:
|
||||
print('Uploading ' + lshort)
|
||||
lshort_split = lshort.replace('/', '', 1).split('/')
|
||||
|
||||
c = -1
|
||||
for _ in lshort_split:
|
||||
c += 1
|
||||
|
||||
global getter_loop_count
|
||||
getter_loop_count = -1
|
||||
q = ''
|
||||
for _ in range(c):
|
||||
q += loop_getter(lshort_split)
|
||||
|
||||
term('sftp -p -i ' + "'" + identity + "' " + '-P ' + port + ' ' + user + '@' + ip + ':' + remote_dir + q +
|
||||
" <<< $'put " + local_dir + lshort.replace('/', '', 1) + "'")
|
||||
i = -1
|
||||
for rshort in rmod_short:
|
||||
i += 1
|
||||
if rshort in lmod_short:
|
||||
matching_times_remote.append(float(remote_mod_times[i]))
|
||||
else:
|
||||
print('Downloading ' + rshort)
|
||||
term('sftp -p -i ' + "'" + identity + "' " + '-P ' + port + ' ' + user + '@' + ip + ':' + remote_dir +
|
||||
rshort.replace('/', '', 1) + ' ' + local_dir + rshort.replace('/', '', 1))
|
||||
i = -1
|
||||
for ltime in matching_times_local:
|
||||
i += 1
|
||||
ltime = int(ltime)
|
||||
if ltime == int(matching_times_remote[i]):
|
||||
print('Local ' + matching_names[i] + ' is up to date, not syncing.')
|
||||
elif ltime > int(matching_times_remote[i]):
|
||||
print('Local ' + matching_names[i] + ' is newer, uploading.')
|
||||
matching_names_split = matching_names[i].replace('/', '', 1).split('/')
|
||||
|
||||
c = -1
|
||||
for _ in matching_names_split:
|
||||
c += 1
|
||||
|
||||
getter_loop_count = -1
|
||||
q = ''
|
||||
for _ in range(c):
|
||||
q += loop_getter(matching_names_split)
|
||||
|
||||
term('sftp -p -i ' + "'" + identity + "' " + '-P ' + port + ' ' + user + '@' + ip + ':' + remote_dir + q +
|
||||
" <<< $'put " + local_dir + matching_names[i].replace('/', '', 1) + "'")
|
||||
|
||||
elif ltime < int(matching_times_remote[i]):
|
||||
print('Local ' + matching_names[i] + ' is older, downloading.')
|
||||
term('sftp -p -i ' + "'" + identity + "' " + '-P ' + port + ' ' + user + '@' + ip + ':' + remote_dir +
|
||||
matching_names[i].replace('/', '', 1) + ' ' + local_dir + matching_names[i].replace('/', '', 1))
|
||||
@@ -1,814 +0,0 @@
|
||||
#!/usr/bin/python3
|
||||
|
||||
# external modules
|
||||
|
||||
from os import system as term
|
||||
from os import remove
|
||||
from os import environ
|
||||
from shutil import move
|
||||
from shutil import rmtree
|
||||
from shutil import copy
|
||||
from sys import argv
|
||||
from re import search
|
||||
from re import escape
|
||||
import random
|
||||
import string
|
||||
import sshync
|
||||
|
||||
|
||||
# internal modules
|
||||
|
||||
def clear():
|
||||
print('\n' * 100)
|
||||
|
||||
|
||||
def string_found(string1, string2):
|
||||
if search(r"\b" + escape(string1) + r"\b", string2):
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
def replace_line(file_name, line_num, text):
|
||||
xlines = open(file_name, 'r').readlines()
|
||||
xlines[line_num] = text
|
||||
open(file_name, 'w').writelines(xlines)
|
||||
|
||||
|
||||
def edit_note():
|
||||
lines = open('/dev/shm/' + shmfolder + '/' + shmentry).readlines()
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines(lines[0:3])
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry + '-n', 'w').writelines(lines[4:-2])
|
||||
term('nano /dev/shm/' + shmfolder + '/' + shmentry + '-n')
|
||||
edit_notes = open('/dev/shm/' + shmfolder + '/' + shmentry + '-n').read()
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'a').write('\n' + edit_notes + '\n\n')
|
||||
|
||||
|
||||
def shmgen():
|
||||
shmfoldergen = ''.join(random.SystemRandom().choice(string.ascii_letters + string.digits)
|
||||
for _ in range(random.randint(10, 30)))
|
||||
shmentrygen = ''.join(random.SystemRandom().choice(string.ascii_letters + string.digits)
|
||||
for _ in range(random.randint(10, 30)))
|
||||
term('mkdir -p /dev/shm/' + shmfoldergen)
|
||||
return shmfoldergen, shmentrygen
|
||||
|
||||
|
||||
def encrypt():
|
||||
term('gpg -r ' + str(gpgid) + ' -e ' + "'" + '/dev/shm/' + shmfolder + '/' + shmentry + "'")
|
||||
move('/dev/shm/' + shmfolder + '/' + shmentry + '.gpg', directory + entryname.replace('/', '', 1) + '.gpg')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
|
||||
|
||||
def encryptfolder():
|
||||
term('gpg -r ' + str(gpgid) + ' -e ' + "'" + '/dev/shm/' + shmfolder + '/' + shmentry + "'")
|
||||
move('/dev/shm/' + shmfolder + '/' + shmentry + '.gpg', directory + folder + '/' + folderentry + '.gpg')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
|
||||
|
||||
# argument - filter the argument to usable text
|
||||
|
||||
argument = str(argv).replace('[', '', 1).replace(']', '', 1).replace(',', '').replace("'", '') \
|
||||
.replace(' ', '', 1).replace('/usr/bin/', '', 1).replace('sshyp', '', 1)
|
||||
|
||||
# help
|
||||
|
||||
if argument == 'help' or argument == '--help' or argument == '-h':
|
||||
print('\nsshyp Copyright (C) 2021 Randall Winkhart')
|
||||
print("This program comes with ABSOLUTELY NO WARRANTY; for details type `sshyp show w'.\nThis is free software, "
|
||||
"and you are welcome to redistribute it under certain conditions; type `sshyp show c' for details.")
|
||||
print('\nUSAGE: sshyp [/<entry name>] [OPTION] [FLAG]\n')
|
||||
print('Options: ')
|
||||
print('help/--help/-h bring up this menu')
|
||||
print('version/-v display sshyp version info')
|
||||
print('config configure sshyp')
|
||||
print('add add an entry')
|
||||
print('gen generate a new password')
|
||||
print('edit edit an existing entry')
|
||||
print('copy copy details of an entry to your clipboard')
|
||||
print('remove/-rm delete an existing entry')
|
||||
print('sync/-s manually sync the entry directory via rsync\n')
|
||||
print('Flags:')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' note/-n change the note attached to an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the URL of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard')
|
||||
print('gen:')
|
||||
print(' update/-u generate a password for an existing entry\n')
|
||||
print("Tip: You can quickly read an entry with 'sshyp /<entry name>'!")
|
||||
print("When specifying entry names, do not include the file extension! '.gpg' is assumed!\n")
|
||||
|
||||
# version info
|
||||
|
||||
if argument == 'version' or argument == '-v':
|
||||
print('\n////////////////////////////////////////////////////////')
|
||||
print('/ /')
|
||||
print('/ sshyp Copyright (C) 2021 Randall Winkhart /')
|
||||
print('/ /')
|
||||
print('/ Version 2021.11.05.fr1 /')
|
||||
print('/ The sshync Update /')
|
||||
print('/ /')
|
||||
print('////////////////////////////////////////////////////////\n')
|
||||
|
||||
# licensing info
|
||||
|
||||
if argument == 'show w':
|
||||
clear()
|
||||
print('This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;')
|
||||
print('without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.')
|
||||
print('See the GNU General Public License for more details.')
|
||||
print('\nhttps://opensource.org/licenses/GPL-3.0\n')
|
||||
|
||||
if argument == 'show c':
|
||||
clear()
|
||||
print('This program is free software: you can redistribute it and/or modify it under the terms of the GNU General')
|
||||
print('Public License as published by the Free Software Foundation, either version 3 of the License,')
|
||||
print('or (at your option) any later version.\n')
|
||||
|
||||
# config
|
||||
|
||||
if argument == 'config':
|
||||
try:
|
||||
print()
|
||||
devicetype = str(input('Will this be a client or a server device? (C/s) '))
|
||||
if devicetype == 's' or devicetype == 'S':
|
||||
open("/var/lib/sshyp/sshyp-device", 'w').write(devicetype)
|
||||
print('\nMake sure the ssh service is running and properly configured.\n')
|
||||
copy('/usr/bin/sshync.py', '/home/' + environ.get('USER') + '/')
|
||||
term('mkdir -p /home/' + environ.get('USER') + '/.password-pasture')
|
||||
print('Configuration complete!\n')
|
||||
else:
|
||||
devicetype = 'c'
|
||||
gpgid = ''
|
||||
print()
|
||||
gpgpresent = str(input(
|
||||
'sshyp requires the use of a unique gpg key. Do you already have one you are willing to use? (y/N) '))
|
||||
if gpgpresent == 'y' or gpgpresent == 'Y':
|
||||
print()
|
||||
gpgid = str(input('Please input the ID of your gpg key: '))
|
||||
open("/var/lib/sshyp/sshyp-gpg", 'w').write(gpgid + '\n')
|
||||
else:
|
||||
print()
|
||||
gpggen = str(
|
||||
input('Would you like to generate one now? Note that if you choose not to do this, you will have '
|
||||
'to re-run "sshyp config" to specify a gpg key when you acquire one (Y/n) '))
|
||||
if gpggen == 'n' or gpggen == 'N':
|
||||
exit()
|
||||
else:
|
||||
term('gpg --full-generate-key')
|
||||
print()
|
||||
gpgid = str(input('Please input the ID of your gpg key: '))
|
||||
open("/var/lib/sshyp/sshyp-gpg", 'w').write(gpgid + '\n')
|
||||
try:
|
||||
open('/var/lib/sshyp/lock', 'x').write('locked')
|
||||
except FileExistsError:
|
||||
pass
|
||||
term('gpg -r ' + str(gpgid) + ' -e ' + '/var/lib/sshyp/lock')
|
||||
remove('/var/lib/sshyp/lock')
|
||||
print('\nMake sure the ssh service on the remote server is running and properly configured.\n')
|
||||
sshgen = str(input('rsync support requires a unique ssh key. Would you like to have this '
|
||||
'automatically generated? (Y/n) '))
|
||||
if sshgen != 'n' and sshgen != 'N':
|
||||
term('ssh-keygen -t ed25519 -f ~/.ssh/sshyp')
|
||||
print('\nExample input: 10.10.10.10:9999\n')
|
||||
ip_port = str(input('What is the IP and ssh port of the remote server? '))
|
||||
print()
|
||||
ip, sep, port = ip_port.partition(':')
|
||||
usernamessh = str(input('What is the username of the remote server? '))
|
||||
print('\nDefault directory: ' + '/home/' + usernamessh + '/.password-pasture/\n')
|
||||
directoryssh = ('/home/' + usernamessh + '/.password-pasture/')
|
||||
open("/var/lib/sshyp/sshyp-device", 'w').write(devicetype)
|
||||
sshync.make_profile('/var/lib/sshyp/sshyp.sshync', '/home/' + environ.get('USER') + '/.password-pasture/',
|
||||
directoryssh, '/home/' + environ.get('USER') + '/.ssh/sshyp', ip, port, usernamessh)
|
||||
print('Configuration complete!\n')
|
||||
except KeyboardInterrupt:
|
||||
print('\n\nConfiguration cancelled.\n')
|
||||
exit()
|
||||
|
||||
# startup help
|
||||
|
||||
if argument == '':
|
||||
clear()
|
||||
print("Use 'help', '--help', or '-h' to see a list of commands.\n")
|
||||
print('sshyp is currently early software with very little polish\n')
|
||||
|
||||
# import userdata
|
||||
|
||||
devicetype = 'c'
|
||||
try:
|
||||
devicetype = open('/var/lib/sshyp/sshyp-device').read().strip()
|
||||
gpgid = open('/var/lib/sshyp/sshyp-gpg').read().strip()
|
||||
sshinfo = sshync.get_profile('/var/lib/sshyp/sshyp.sshync')
|
||||
usernamessh = sshinfo[0].replace('\n', '')
|
||||
ip = sshinfo[1].replace('\n', '')
|
||||
port = sshinfo[2].replace('\n', '')
|
||||
directory = str(sshinfo[3].replace('\n', ''))
|
||||
directoryssh = sshinfo[4].replace('\n', '')
|
||||
term('mkdir -p ' + directory)
|
||||
except FileNotFoundError:
|
||||
if devicetype != 's' and devicetype != 'S':
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print("Not all necessary configuration files are present. Please run 'sshyp config'!")
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
devicetype, sshinfo, directory, directoryssh, ip, port, usernamessh = [0, 0, 0, 0, 0, 0, 0]
|
||||
exit()
|
||||
|
||||
# no argument
|
||||
|
||||
if argument == '':
|
||||
try:
|
||||
print()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
readentry = str(input('Entry to read: '))
|
||||
clear()
|
||||
term('gpg -d ' + directory + "'" + readentry.replace('/', '', 1) + "'" + '.gpg')
|
||||
print()
|
||||
except KeyboardInterrupt:
|
||||
print('\n\nSelection cancelled.\n')
|
||||
exit()
|
||||
|
||||
# read shortcut
|
||||
|
||||
if argument.startswith('/'):
|
||||
if argument.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = argument.replace('/', '', 1).partition('/')
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d ' + directory + "'" + argument.replace('/', '', 1) + '.gpg' + "'")
|
||||
|
||||
# add
|
||||
|
||||
if argument == 'add':
|
||||
print('\nUSAGE: sshyp add [FLAG]')
|
||||
print('Flags:')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries\n')
|
||||
|
||||
if argument == 'add note' or argument == 'add -n':
|
||||
try:
|
||||
clear()
|
||||
entryname = str(input('Name of note: '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, notes = (0, 0)
|
||||
print('\n\nEntry add cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
term('nano /dev/shm/' + shmfolder + '/' + shmentry + '-n')
|
||||
notes = open('/dev/shm/' + shmfolder + '/' + shmentry + '-n', 'r').read()
|
||||
try:
|
||||
if entryname.startswith('/'): # check if user input contains slashes
|
||||
if entryname.replace('/', '', 1).__contains__('/'): # create folder and entry if there are two slashes
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines('\n\n\n\n' + notes + '\n\n')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else: # create entry if there is only one slash
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines('\n\n\n\n' + notes + '\n\n')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else: # create entry if there are no slashes
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines('\n\n\n\n' + notes + '\n\n')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The folder you requested to access does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'add password' or argument == 'add -p':
|
||||
try:
|
||||
clear()
|
||||
entryname = str(input('Name of service: '))
|
||||
username = str(input('Username: '))
|
||||
password = str(input('Password: '))
|
||||
url = str(input('URL: '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, username, password, url, notes = (0, 0, 0, 0, 0)
|
||||
print('\n\nEntry add cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
add_note = input('Add a note to this entry? (y/N) ')
|
||||
if add_note == 'y' or add_note == 'Y':
|
||||
term('nano /dev/shm/' + shmfolder + '/' + shmentry + '-n')
|
||||
notes = open('/dev/shm/' + shmfolder + '/' + shmentry + '-n', 'r').read()
|
||||
else:
|
||||
notes = ''
|
||||
try:
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines(username + '\n' + password + '\n' + url
|
||||
+ '\n\n' + notes + '\n\n')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines(username + '\n' + password + '\n' + url
|
||||
+ '\n\n' + notes + '\n\n')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else:
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines(username + '\n' + password + '\n' + url
|
||||
+ '\n\n' + notes + '\n\n')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The folder you requested to access does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'add folder' or argument == 'add -f':
|
||||
newfolder = str(input('Name of new folder: '))
|
||||
term('mkdir ' + "'" + directory + newfolder + "'")
|
||||
|
||||
# edit
|
||||
|
||||
if argument == 'edit':
|
||||
print('\nUSAGE: sshyp edit [FLAG]')
|
||||
print('Flags:')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print(' note/-n change the note attached to an entry\n')
|
||||
|
||||
if argument == 'edit rename' or argument == 'edit relocate' or argument == 'edit -r':
|
||||
try:
|
||||
clear()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
entryname = str(input('What file would you like to edit? '))
|
||||
newname = str(input('New Name: '))
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
move(directory + folder + '/' + folderentry + '.gpg', directory + '/' + newname + '.gpg')
|
||||
else:
|
||||
move(directory + entryname.replace('/', '', 1) + '.gpg',
|
||||
directory + newname.replace('/', '', 1) + '.gpg')
|
||||
else:
|
||||
move(directory + entryname + '.gpg', directory + newname + '.gpg')
|
||||
except KeyboardInterrupt:
|
||||
print('\n\nEdit cancelled.\n')
|
||||
exit()
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
exit()
|
||||
|
||||
if argument == 'edit username' or argument == 'edit -u':
|
||||
try:
|
||||
clear()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
entryname = str(input('What file would you like to edit? '))
|
||||
username = str(input('New Username: '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, username = (0, 0)
|
||||
print('\n\nEdit cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
folder + '/' + folderentry + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 0, username + '\n')
|
||||
remove(directory + folder + '/' + folderentry + '.gpg')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
entryname.replace('/', '', 1) + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 0, username + '\n')
|
||||
remove(directory + entryname.replace('/', '', 1) + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + entryname + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 0, username + '\n')
|
||||
remove(directory + entryname + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'edit password' or argument == 'edit -p':
|
||||
try:
|
||||
clear()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
entryname = str(input('What file would you like to edit? '))
|
||||
password = str(input('New Password: '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, password = (0, 0)
|
||||
print('\n\nEdit cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
folder + '/' + folderentry + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 1, password + '\n')
|
||||
remove(directory + folder + '/' + folderentry + '.gpg')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
entryname.replace('/', '', 1) + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 1, password + '\n')
|
||||
remove(directory + entryname.replace('/', '', 1) + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + entryname + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 1, password + '\n')
|
||||
remove(directory + entryname + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'edit url' or argument == 'edit -l':
|
||||
try:
|
||||
clear()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
entryname = str(input('What file would you like to edit? '))
|
||||
url = str(input('New URL: '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, url = (0, 0)
|
||||
print('\n\nEdit cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
folder + '/' + folderentry + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 2, url + '\n')
|
||||
remove(directory + folder + '/' + folderentry + '.gpg')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
entryname.replace('/', '', 1) + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 2, url + '\n')
|
||||
remove(directory + entryname.replace('/', '', 1) + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + entryname + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 2, url + '\n')
|
||||
remove(directory + entryname + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'edit note' or argument == 'edit -n':
|
||||
try:
|
||||
clear()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
entryname = str(input('What file would you like to edit? '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, notes = (0, 0)
|
||||
print('\n\nEdit cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
folder + '/' + folderentry + '.gpg')
|
||||
edit_note()
|
||||
remove(directory + folder + '/' + folderentry + '.gpg')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
entryname.replace('/', '', 1) + '.gpg')
|
||||
edit_note()
|
||||
remove(directory + entryname.replace('/', '', 1) + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + entryname + '.gpg')
|
||||
edit_note()
|
||||
remove(directory + entryname + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
# copy
|
||||
|
||||
if argument == 'copy':
|
||||
print('\nUSAGE: sshyp copy [FLAG]')
|
||||
print('Flags:')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the URL of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard\n')
|
||||
|
||||
if argument == 'copy username' or argument == 'copy -u':
|
||||
try:
|
||||
print()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
readentry = str(input('Entry to copy: '))
|
||||
except KeyboardInterrupt:
|
||||
readentry = 0
|
||||
print('\n\nCopy cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + readentry + '.gpg')
|
||||
copyline = open('/dev/shm/' + shmfolder + '/' + shmentry, 'r').readlines()
|
||||
if environ.get('WAYLAND_DISPLAY') == 'wayland-0':
|
||||
term('wl-copy ' + "'" + copyline[0].replace('\n', '') + "'")
|
||||
else:
|
||||
term('echo -n ' + "'" + copyline[0].replace('\n', '') + "'" + ' | xclip -sel c')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'copy password' or argument == 'copy -p':
|
||||
try:
|
||||
print()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
readentry = str(input('Entry to copy: '))
|
||||
except KeyboardInterrupt:
|
||||
readentry = 0
|
||||
print('\n\nCopy cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + readentry + '.gpg')
|
||||
copyline = open('/dev/shm/' + shmfolder + '/' + shmentry, 'r').readlines()
|
||||
if environ.get('WAYLAND_DISPLAY') == 'wayland-0':
|
||||
term('wl-copy ' + "'" + copyline[1].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
else:
|
||||
term('echo -n ' + "'" + copyline[1].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'copy url' or argument == 'copy -l':
|
||||
try:
|
||||
print()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
readentry = str(input('Entry to copy: '))
|
||||
except KeyboardInterrupt:
|
||||
readentry = 0
|
||||
print('\n\nCopy cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + readentry + '.gpg')
|
||||
copyline = open('/dev/shm/' + shmfolder + '/' + shmentry, 'r').readlines()
|
||||
if environ.get('WAYLAND_DISPLAY') == 'wayland-0':
|
||||
term('wl-copy ' + "'" + copyline[2].replace('\n', '') + "'")
|
||||
else:
|
||||
term('echo -n ' + "'" + copyline[2].replace('\n', '') + "'" + ' | xclip -sel c')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'copy note' or argument == 'copy -n':
|
||||
try:
|
||||
print()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
readentry = str(input('Entry to copy: '))
|
||||
except KeyboardInterrupt:
|
||||
readentry = 0
|
||||
print('\n\nCopy cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + readentry + '.gpg')
|
||||
copyline = open('/dev/shm/' + shmfolder + '/' + shmentry, 'r').readlines()
|
||||
if environ.get('WAYLAND_DISPLAY') == 'wayland-0':
|
||||
term('wl-copy ' + "'" + copyline[4].replace('\n', '') + "'")
|
||||
else:
|
||||
term('echo -n ' + "'" + copyline[4].replace('\n', '') + "'" + ' | xclip -sel c')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
# gen
|
||||
|
||||
if argument == 'gen':
|
||||
try:
|
||||
clear()
|
||||
entryname = str(input('Name of service: '))
|
||||
username = str(input('Username: '))
|
||||
passlength = int(input('How many characters should be in the password? '))
|
||||
passtype = str(input('Should the password be simple (for compatibility) or complex (for security)? (s/C) '))
|
||||
if passtype != 's':
|
||||
passtype = string.ascii_letters + string.digits + string.punctuation
|
||||
if passtype == 's':
|
||||
passtype = string.ascii_letters + string.digits
|
||||
passgen = ''.join(random.SystemRandom().choice(passtype) for _ in range(passlength))
|
||||
url = str(input('URL: '))
|
||||
notes = str(input('Additional notes: '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, username, passgen, url, notes = (0, 0, 0, 0, 0)
|
||||
print('\n\nEntry generation cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines(username + '\n' + passgen + '\n' + url
|
||||
+ '\n' + notes + '\n\n')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines(username + '\n' + passgen + '\n' + url
|
||||
+ '\n' + notes + '\n\n')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else:
|
||||
open('/dev/shm/' + shmfolder + '/' + shmentry, 'w').writelines(username + '\n' + passgen + '\n' + url
|
||||
+ '\n' + notes + '\n\n')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The folder you requested to access does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
if argument == 'gen update' or argument == 'gen -u':
|
||||
try:
|
||||
clear()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
entryname = str(input('Which password would you like to re-generate? '))
|
||||
passlength = int(input('How many characters should be in the password? '))
|
||||
passtype = str(input('Should the password be simple (for compatibility) or complex (for security)? (s/C) '))
|
||||
except KeyboardInterrupt:
|
||||
entryname, passlength, passtype = (0, 0, 0)
|
||||
print('\n\nEntry generation cancelled.\n')
|
||||
exit()
|
||||
shmfolder, shmentry = shmgen()
|
||||
try:
|
||||
if passtype != 's':
|
||||
passtype = string.ascii_letters + string.digits + string.punctuation
|
||||
if passtype == 's':
|
||||
passtype = string.ascii_letters + string.digits
|
||||
passgen = ''.join(random.SystemRandom().choice(passtype) for _ in range(passlength))
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
folder, sep, folderentry = entryname.replace('/', '', 1).partition('/')
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
folder + '/' + folderentry + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 1, passgen + '\n')
|
||||
remove(directory + folder + '/' + folderentry.replace('/', '', 1) + '.gpg')
|
||||
encryptfolder()
|
||||
term('gpg -d ' + directory + folder + '/' + "'" + folderentry + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory +
|
||||
entryname.replace('/', '', 1) + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 1, passgen + '\n')
|
||||
remove(directory + entryname.replace('/', '', 1) + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname.replace('/', '', 1) + '.gpg' + "'")
|
||||
else:
|
||||
term('gpg -d --output /dev/shm/' + shmfolder + '/' + shmentry + ' ' + directory + entryname + '.gpg')
|
||||
replace_line('/dev/shm/' + shmfolder + '/' + shmentry, 1, passgen + '\n')
|
||||
remove(directory + entryname + '.gpg')
|
||||
encrypt()
|
||||
term('gpg -d ' + directory + "'" + entryname + '.gpg' + "'")
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to edit does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
rmtree('/dev/shm/' + shmfolder)
|
||||
exit()
|
||||
|
||||
# remove
|
||||
|
||||
if argument == 'remove' or argument == '-rm':
|
||||
clear()
|
||||
term('cd ' + directory + '; ls -1 *')
|
||||
print()
|
||||
try:
|
||||
entryname = str(input('What would you like to delete? '))
|
||||
try:
|
||||
term('gpg -d --output /dev/shm/sshyp.lock /var/lib/sshyp/lock.gpg')
|
||||
unlocker = open('/dev/shm/sshyp.lock', 'r').readlines()
|
||||
remove('/dev/shm/sshyp.lock')
|
||||
except FileNotFoundError:
|
||||
print('\nAccess denied.\n')
|
||||
exit()
|
||||
if entryname.startswith('/'):
|
||||
if entryname.replace('/', '', 1).__contains__('/'):
|
||||
if devicetype == 'c':
|
||||
term('ssh -p ' + port + ' ' + usernamessh + '@' + ip + ' "' + ' rm -rf ' + "'" + directoryssh +
|
||||
entryname.replace('/', '', 1) + '.gpg' + "'" + '"')
|
||||
remove(directory + entryname.replace('/', '', 1) + '.gpg')
|
||||
else:
|
||||
if devicetype == 'c':
|
||||
term('ssh -p ' + port + ' ' + usernamessh + '@' + ip + ' "' + ' rm -rf ' + "'" + directoryssh +
|
||||
entryname.replace('/', '', 1) + "'" + '"')
|
||||
rmtree(directory + entryname.replace('/', '', 1))
|
||||
else:
|
||||
if devicetype == 'c':
|
||||
term('ssh -p ' + port + ' ' + usernamessh + '@' + ip + ' "' + ' rm -rf ' + "'" + directoryssh +
|
||||
entryname + '.gpg' + "'" + '"')
|
||||
remove(directory + entryname + '.gpg')
|
||||
except KeyboardInterrupt:
|
||||
print('\n\nDeletion cancelled.\n')
|
||||
exit()
|
||||
except FileNotFoundError:
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print('The file you requested to delete does not exist!')
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
exit()
|
||||
|
||||
if argument.__contains__('-rm') or string_found('remove', argument) or string_found('add', argument) or \
|
||||
string_found('edit', argument) or string_found('gen', argument) or string_found('copy', argument) or \
|
||||
string_found('/', argument) or argument == 'sync' or argument == '-s' or argument == '' or argument == 'help' \
|
||||
or argument == '--help' or argument == '-h' or argument == 'version' or argument == '-v' or argument == \
|
||||
'config' or argument == 'show w' or argument == 'show c':
|
||||
pass
|
||||
else:
|
||||
print('\n!!!!!!!!!!!!!!!')
|
||||
print('Argument error!')
|
||||
print('!!!!!!!!!!!!!!!')
|
||||
print("\nUse 'help', '--help', or '-h' to see a list of commands.\n")
|
||||
|
||||
# permissions - applied pre-sync to ensure permissions are correct before upload
|
||||
|
||||
term('find ' + directory + ' -type d -exec chmod -R 700 {} +')
|
||||
term('find ' + directory + ' -type f -exec chmod -R 600 {} +')
|
||||
|
||||
# rsync - ran at end of program to ensure all files are properly synced
|
||||
if devicetype == 'c':
|
||||
if argument.__contains__('-rm') or string_found('remove', argument) or string_found('add', argument) or \
|
||||
string_found('edit', argument) or string_found('gen', argument) or argument == 'sync' or argument == '-s':
|
||||
print('Syncing entries with other device(s)...\n')
|
||||
sshync.run_profile('/var/lib/sshyp/sshyp.sshync')
|
||||
Executable → Regular
+1011
-2
File diff suppressed because it is too large
Load Diff
+132
@@ -0,0 +1,132 @@
|
||||
.TH sshyp 1 "06 November 2022" "v1.2.0" "sshyp man page"
|
||||
.SH NAME
|
||||
sshyp \- A very simple self-hosted, synchronized password manager for UNIX(-like) systems. Alternative to (and compatible with) pass/password-store.
|
||||
.SH SYNOPSIS
|
||||
Client Usage: sshyp [option [flag] [<entry name>]] | [/<entry name>]
|
||||
|
||||
Server Usage: sshyp [option [flag] [<device id>]]
|
||||
.SH DESCRIPTION
|
||||
sshyp is a lightweight password and note management program written in Python. sshyp is used via CLI and is self-hosted with a client-server model. sshyp expects that you have access to a personal server with a properly configured ssh server, ideally accepting remote connections.
|
||||
.SH EXAMPLES (CLIENT)
|
||||
Setting up sshyp for the first time or altering its configuration (also recommended after major updates):
|
||||
sshyp tweak
|
||||
|
||||
Viewing the entry database:
|
||||
sshyp
|
||||
|
||||
Reading an existing entry saved as ~/.local/share/sshyp/development/github.gpg:
|
||||
sshyp /development/github
|
||||
|
||||
Copying the password of an existing entry saved as ~/.local/share/sshyp/financial/bank.gpg:
|
||||
sshyp copy -p /financial/bank
|
||||
|
||||
Editing the username of an existing entry saved as ~/.local/share/sshyp/game.gpg:
|
||||
sshyp edit -u game
|
||||
|
||||
Making a new entry saved as ~/.local/share/sshyp/school/university.gpg using the built-in password generator:
|
||||
sshyp gen /school/university
|
||||
|
||||
Creating a note-only entry saved as ~/.local/share/sshyp/notes/testNote.gpg:
|
||||
sshyp add -n /notes/testNote
|
||||
|
||||
Manually syncing entries with the server:
|
||||
sshyp sync
|
||||
|
||||
Removing an existing folder saved as ~/.local/share/sshyp/social:
|
||||
sshyp shear social/
|
||||
.SH EXAMPLES (SERVER)
|
||||
Setting up the quick-unlock whitelist:
|
||||
sshyp whitelist setup
|
||||
|
||||
Checking the quick-unlock whitelist status of all registered client devices:
|
||||
sshyp whitelist list
|
||||
|
||||
Adding a device with the id "laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_" to the quick-unlock whitelist:
|
||||
sshyp whitelist add 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_'
|
||||
|
||||
Removing a device with the id "laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_" from the quick-unlock whitelist:
|
||||
sshyp whitelist del 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_'
|
||||
.SH OPTIONS (CLIENT)
|
||||
help/--help/-h bring up the help menu
|
||||
version/-v display sshyp version info
|
||||
tweak configure sshyp
|
||||
add add an entry
|
||||
gen generate a new password
|
||||
edit edit an existing entry
|
||||
copy copy details of an entry to your clipboard
|
||||
shear/-rm delete an existing entry
|
||||
sync/-s manually sync the entry directory via sshync
|
||||
.SH FLAGS (CLIENT)
|
||||
add:
|
||||
password/-p add a password entry
|
||||
note/-n add a note entry
|
||||
folder/-f add a new folder for entries
|
||||
|
||||
edit:
|
||||
rename/relocate/-r rename or relocate an entry
|
||||
username/-u change the username of an entry
|
||||
password/-p change the password of an entry
|
||||
note/-n change the note attached to an entry
|
||||
url/-l change the url attached to an entry
|
||||
|
||||
copy:
|
||||
username/-u copy the username of an entry to your clipboard
|
||||
password/-p copy the password of an entry to your clipboard
|
||||
url/-l copy the URL of an entry to your clipboard
|
||||
note/-n copy the note of an entry to your clipboard
|
||||
|
||||
gen:
|
||||
update/-u generate a password for an existing entry
|
||||
.SH OPTIONS (SERVER)
|
||||
help/--help/-h bring up this menu
|
||||
version/-v display sshyp version info
|
||||
tweak configure sshyp
|
||||
whitelist manage the quick-unlock whitelist
|
||||
.SH FLAGS (SERVER)
|
||||
whitelist:
|
||||
setup set up the quick-unlock whitelist
|
||||
list/-l view all registered device ids and their quick-unlock whitelist status
|
||||
add whitelist a device id for quick-unlock
|
||||
delete/del remove a device id from the quick-unlock whitelist
|
||||
.SH LIMITATIONS
|
||||
The following characters/character sequences are not supported in entry/folder titles:
|
||||
|
||||
@ ^&* *&^
|
||||
.SH SETUP
|
||||
sshyp operates on a client-server model, and thus requires you to have access to your own server (whether it be a physical home server or a cloud rental) with remote access via SSH.
|
||||
|
||||
The sshyp package includes modes for operating on both client and server devices, so only one package is necessary.
|
||||
|
||||
Server setup:
|
||||
Configure an OpenSSH server (if sshyp was installed from the Debian package, openssh-server and openssh-sftp-server must be installed manually - if sshyp was installed from the Fedora package, openssh-server must be installed manually)
|
||||
Allow remote access to the SSH server w/public key authentication (disabling password-only authentication recommended)
|
||||
Install sshyp
|
||||
Run "sshyp tweak" and set the device type as server
|
||||
Optionally, run "sshyp whitelist setup" and configure quick-unlock
|
||||
Done!
|
||||
|
||||
Client setup:
|
||||
Install sshyp
|
||||
Run "sshyp tweak" and follow the prompts
|
||||
Copy the generated public SSH key (located at ~/.ssh/sshyp.pub) to the server using preferred method (manually adding to authorized_keys, ssh-copy-id, etc.)
|
||||
If you already have entries on the server, sync them using "sshyp sync"
|
||||
Optionally, Bash completions can be enabled by installing your distribution's "bash-completion" package and restarting your terminal
|
||||
Done!
|
||||
|
||||
Please note that the server setup intentionally does not allow the reading of entries (it does not allow adding a gpg decryption key). For security purposes, only clients can read entries.
|
||||
.SH EXIT CODES
|
||||
0 - no error
|
||||
|
||||
1 - argument error
|
||||
|
||||
2 - configuration error
|
||||
|
||||
3 - data not found error
|
||||
|
||||
4 - data already exists error
|
||||
|
||||
5 - decryption/encryption error
|
||||
|
||||
6 - server data retrieval error
|
||||
.SH AUTHOR
|
||||
Randall Winkhart (https://github.com/rwinkhart)
|
||||
Executable
+50
@@ -0,0 +1,50 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
_path_gen() {
|
||||
local sshyp_path="$HOME/.local/share/sshyp"
|
||||
local sshyp_path_length="$(("${#sshyp_path}" + 1))"
|
||||
readarray -t full_paths < <(find "$sshyp_path" -type f -exec ls {} \;)
|
||||
for path in "${full_paths[@]}"; do
|
||||
trimmed_path=$(echo ${path%????} | cut -c"$sshyp_path_length"-)
|
||||
trimmed_path=$(echo ${trimmed_path// /\\ })
|
||||
trimmed_paths+=("$trimmed_path")
|
||||
done
|
||||
} &&
|
||||
|
||||
# from this point, this completions script was partially generated by
|
||||
# completely (https://github.com/dannyben/completely)
|
||||
|
||||
_sshyp_completions() {
|
||||
if [ "${#COMP_WORDS[@]}" -gt "4" ]; then
|
||||
return
|
||||
fi
|
||||
local cur=${COMP_WORDS[COMP_CWORD]}
|
||||
local compline="${COMP_WORDS[@]:1:$COMP_CWORD-1}"
|
||||
|
||||
case "$compline" in
|
||||
'add password'* | 'add -p'* | 'add note'* | 'add -n'* | 'add folder'*| 'add -f'* | 'edit relocate'* | 'edit -r'* | 'edit username'* | 'edit -u'* | 'edit password'* | 'edit -p'* | 'edit url'* | 'edit -l'* | 'edit note'* | 'edit -n'* | 'copy username'* | 'copy -u'* | 'copy password'* | 'copy -p'* | 'copy note'* | 'copy -n'* | 'copy url'* | 'copy -l'* | 'gen update'* | 'gen -u'*)
|
||||
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "$(printf "'%s' " "${trimmed_paths[@]}")" -- "$cur" )
|
||||
;;
|
||||
|
||||
'edit'*)
|
||||
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "relocate username password note url" -- "$cur" )
|
||||
;;
|
||||
|
||||
'copy'*)
|
||||
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "username password url note" -- "$cur" )
|
||||
;;
|
||||
|
||||
'add'*)
|
||||
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "password note folder" -- "$cur" )
|
||||
;;
|
||||
|
||||
'gen'*)
|
||||
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "update" -- "$cur" )
|
||||
;;
|
||||
*)
|
||||
while read; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "help version tweak add gen edit copy shear sync $(printf "'%s' " "${trimmed_paths[@]}")" -- "$cur" )
|
||||
;;
|
||||
|
||||
esac
|
||||
} &&
|
||||
_path_gen && complete -F _sshyp_completions sshyp
|
||||
Executable
+104
@@ -0,0 +1,104 @@
|
||||
#!/usr/bin/env python3
|
||||
|
||||
# external modules
|
||||
|
||||
from os import path, system, walk
|
||||
from os.path import expanduser, getmtime, join
|
||||
from sys import exit as s_exit
|
||||
|
||||
|
||||
# utility functions
|
||||
|
||||
def get_titles_mods(_directory, _destination, _user_data): # fetches and returns lists of titles and their mod times
|
||||
from pathlib import Path
|
||||
_title_list, _mod_list = [], []
|
||||
Path(path.expanduser('~/.config/sshync')).mkdir(0o700, parents=True, exist_ok=True) # create config directory
|
||||
# local fetching
|
||||
if _destination == 'l':
|
||||
open(expanduser('~/.config/sshync/database'), 'w').write('') # blanks out database file
|
||||
for _root, _directories, _files in walk(_directory):
|
||||
for _filename in _files:
|
||||
_title_list.append(join(_root.replace(_directory, '', 1), _filename))
|
||||
_mod_list.append(int(getmtime(join(_root, _filename))))
|
||||
for _title in _title_list:
|
||||
open(expanduser('~/.config/sshync/database'), 'a').write(str(_title) + '\n')
|
||||
open(expanduser('~/.config/sshync/database'), 'a').write('^&*\n')
|
||||
for _mod in _mod_list:
|
||||
open(expanduser('~/.config/sshync/database'), 'a').write(str(_mod) + '\n')
|
||||
# remote fetching
|
||||
if _destination == 'r':
|
||||
system(f"ssh -i '{_user_data[5]}' -p {_user_data[2]} {_user_data[0]}@{_user_data[1]} \"cd /lib/sshyp; python -c"
|
||||
f" 'import sshync; sshync.get_titles_mods(\"'\"{_user_data[4]}\"'\", \"'\"l\"'\", \"'\"{_user_data}"
|
||||
f"\"'\")'\"")
|
||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' {_user_data[0]}@{_user_data[1]}:"
|
||||
f"'/home/{_user_data[0]}/.config/sshync/database' '{expanduser('~/.config/sshync/')}'")
|
||||
_titles, _sep, _mods = '*&^'.join(open(expanduser('~/.config/sshync/database')).readlines()).replace('\n', '')\
|
||||
.partition('^&*')
|
||||
_title_list, _mod_list = _titles.split('*&^')[:-1], _mods.split('*&^')[1:]
|
||||
return _title_list, _mod_list
|
||||
|
||||
|
||||
def sort_titles_mods(_list_1, _list_2): # creates and returns two lists (of titles and mod times) generated by sorting
|
||||
# information from two different, provided lists
|
||||
_title_list_2_sorted, _mod_list_2_sorted = [], []
|
||||
# title sorting
|
||||
for _title in _list_1[0]:
|
||||
if _title in _list_2[0]:
|
||||
_title_list_2_sorted.append(_title)
|
||||
for _title in _list_2[0]:
|
||||
if _title not in _title_list_2_sorted:
|
||||
_title_list_2_sorted.append(_title)
|
||||
# mod time sorting
|
||||
for _title in _title_list_2_sorted:
|
||||
_mod_list_2_sorted.append(_list_2[1][_list_2[0].index(_title)])
|
||||
return _title_list_2_sorted, _mod_list_2_sorted
|
||||
|
||||
|
||||
def make_profile(_profile_dir, _local_dir, _remote_dir, _identity, _ip, _port, _user): # creates a sshync job profile
|
||||
open(_profile_dir, 'w').write(f"{_user}\n{_ip}\n{_port}\n{_local_dir}\n{_remote_dir}\n{_identity}\n")
|
||||
|
||||
|
||||
def get_profile(_profile_dir): # returns a list of data read from a sshync job profile
|
||||
try:
|
||||
_profile_data = open(_profile_dir).readlines()
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\n\u001b[38;5;9merror: the profile does not exist or is corrupted.\u001b[0m\n')
|
||||
_profile_data = None
|
||||
s_exit(3)
|
||||
# extract data from profile
|
||||
_user = _profile_data[0].rstrip()
|
||||
_ip = _profile_data[1].rstrip()
|
||||
_port = _profile_data[2].rstrip()
|
||||
_local_dir = _profile_data[3].rstrip()
|
||||
_remote_dir = _profile_data[4].rstrip()
|
||||
_identity = _profile_data[5].rstrip()
|
||||
return _user, _ip, _port, _local_dir, _remote_dir, _identity
|
||||
|
||||
|
||||
def run_profile(_profile_dir): # runs a sshync job profile
|
||||
_user_data = get_profile(_profile_dir)
|
||||
_remote_titles_mods_saver = get_titles_mods(_user_data[4], 'r', _user_data) # saved to prevent re-walking directory
|
||||
_index_l = sort_titles_mods(_remote_titles_mods_saver, get_titles_mods(_user_data[3], 'l', _user_data))
|
||||
_index_r = sort_titles_mods(_index_l, _remote_titles_mods_saver)
|
||||
_i = -1
|
||||
for _title in _index_l[0]:
|
||||
_i += 1
|
||||
if _title in _index_r[0]:
|
||||
# compare mod times and sync
|
||||
if int(_index_l[1][_i]) > int(_index_r[1][_i]):
|
||||
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is newer locally, uploading...")
|
||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[3]}{_title}' "
|
||||
f"'{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
||||
elif int(_index_l[1][_i]) < int(_index_r[1][_i]):
|
||||
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is newer remotely, downloading...")
|
||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[0]}@{_user_data[1]}:"
|
||||
f"{_user_data[4]}{_title}' '{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
||||
else:
|
||||
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is not on remote server, uploading...")
|
||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[3]}{_title}' "
|
||||
f"'{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
||||
for _title in _index_r[0]:
|
||||
if _title not in _index_l[0]:
|
||||
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is not in local directory, downloading...")
|
||||
system(f"scp -pqs -P {_user_data[2]} -i '{_user_data[5]}' '{_user_data[0]}@{_user_data[1]}:"
|
||||
f"{_user_data[4]}{_title}' '{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}'")
|
||||
Executable
+966
@@ -0,0 +1,966 @@
|
||||
#!/usr/bin/env python3
|
||||
|
||||
# external modules
|
||||
|
||||
from os import environ, listdir, path, remove, system, uname, walk
|
||||
from pathlib import Path
|
||||
from random import randint, SystemRandom
|
||||
from shutil import get_terminal_size, move, rmtree
|
||||
import sshync
|
||||
from subprocess import CalledProcessError, Popen, PIPE, run
|
||||
from sys import argv, exit as s_exit
|
||||
|
||||
|
||||
# BELOW - utility functions
|
||||
|
||||
def entry_list_gen(_directory=path.expanduser('~/.local/share/sshyp/')): # generates and prints full entry list
|
||||
from textwrap import fill
|
||||
print('\n\u001b[38;5;0;48;5;15msshyp entries:\u001b[0m\n')
|
||||
_entry_list, _color_alternator = [], 1
|
||||
for _entry in sorted(listdir(_directory)):
|
||||
if Path(f"{_directory}{_entry}").is_file():
|
||||
if _color_alternator == 1:
|
||||
_entry_list.append(f"{_entry.replace('.gpg', '')}")
|
||||
_color_alternator = 2
|
||||
else:
|
||||
_entry_list.append(f"\u001b[38;5;8m{_entry.replace('.gpg', '')}\u001b[0m")
|
||||
_color_alternator = 1
|
||||
_real = len(' '.join(_entry_list)) - (5.5 * len(_entry_list))
|
||||
if _real <= get_terminal_size()[0]:
|
||||
_width = len(' '.join(_entry_list))
|
||||
else:
|
||||
_width = (len(' '.join(_entry_list)) / (_real / get_terminal_size()[0]) - 25)
|
||||
try:
|
||||
print(fill(' '.join(_entry_list), width=_width) + '\n')
|
||||
except ValueError:
|
||||
pass
|
||||
for _root, _directories, _files in walk(_directory):
|
||||
for _dir in sorted(_directories):
|
||||
_inner_dir = f"{_root.replace(_directory, '')}/{_dir}"
|
||||
print(f"\u001b[38;5;15;48;5;238m{_inner_dir}/\u001b[0m")
|
||||
_entry_list, _color_alternator = [], 1
|
||||
for _s_root, _s_directories, _s_files in walk(f"{_directory[:-1]}{_inner_dir}"):
|
||||
for _entry in sorted(_s_files):
|
||||
if _color_alternator == 1:
|
||||
_entry_list.append(f"{_entry.replace('.gpg', '')}")
|
||||
_color_alternator = 2
|
||||
else:
|
||||
_entry_list.append(f"\u001b[38;5;8m{_entry.replace('.gpg', '')}\u001b[0m")
|
||||
_color_alternator = 1
|
||||
_real = len(' '.join(_entry_list)) - (5.5 * len(_entry_list))
|
||||
if _real <= get_terminal_size()[0]:
|
||||
_width = len(' '.join(_entry_list))
|
||||
else:
|
||||
_width = (len(' '.join(_entry_list)) / (_real / get_terminal_size()[0]) - 25)
|
||||
try:
|
||||
print(fill(' '.join(_entry_list), width=_width) + '\n')
|
||||
except ValueError:
|
||||
print('\u001b[38;5;9m-empty directory-\u001b[0m\n')
|
||||
|
||||
|
||||
def entry_reader(_decrypted_entry): # displays the contents of an entry in a readable format
|
||||
_entry_lines, _notes_flag = open(_decrypted_entry, 'r').readlines(), 0
|
||||
print()
|
||||
for _num in range(len(_entry_lines)):
|
||||
try:
|
||||
if _num == 0 and _entry_lines[1] != '\n':
|
||||
print(f"\u001b[38;5;15;48;5;238musername:\u001b[0m\n{_entry_lines[1].strip()}\n")
|
||||
elif _num == 1 and _entry_lines[0] != '\n':
|
||||
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0].strip()}\n")
|
||||
elif _num == 2 and _entry_lines[2] != '\n':
|
||||
print(f"\u001b[38;5;15;48;5;238murl:\u001b[0m\n{_entry_lines[_num].strip()}\n")
|
||||
elif _num >= 3 and _entry_lines[_num] != '\n' and _notes_flag != 1:
|
||||
_notes_flag = 1
|
||||
print(f"\u001b[38;5;15;48;5;238mnotes:\u001b[0m\n{_entry_lines[_num].strip()}")
|
||||
elif _num >= 3 and _notes_flag == 1:
|
||||
print(_entry_lines[_num].replace('\n', ''))
|
||||
if _notes_flag == 1:
|
||||
try:
|
||||
_line_test = _entry_lines[_num + 1]
|
||||
except IndexError:
|
||||
print()
|
||||
except IndexError:
|
||||
if _num == 0:
|
||||
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0]}\n")
|
||||
|
||||
|
||||
def entry_name_fetch(_entry_name_location): # fetches and returns entry name from user input or from provided argument
|
||||
if type(_entry_name_location) == str:
|
||||
entry_list_gen()
|
||||
_entry_name = str(input(_entry_name_location))
|
||||
else:
|
||||
_entry_name_split = argument.split(' ')
|
||||
del _entry_name_split[:_entry_name_location]
|
||||
_entry_name = ' '.join(_entry_name_split)
|
||||
if _entry_name.startswith('/'):
|
||||
return _entry_name.replace('/', '', 1)
|
||||
else:
|
||||
return _entry_name
|
||||
|
||||
|
||||
def string_gen(_complexity, _length): # generates and returns a random string based on input
|
||||
import string
|
||||
if _complexity == 's':
|
||||
_character_pool = string.ascii_letters + string.digits
|
||||
elif _complexity == 'f':
|
||||
_character_pool = string.digits + string.ascii_letters + string.punctuation.replace('/', '').replace('\\', '')\
|
||||
.replace("'", '').replace('"', '').replace('`', '').replace('~', '')
|
||||
else:
|
||||
_character_pool = string.digits + string.ascii_letters + string.punctuation
|
||||
_min_special, _special = round(.2 * _length), 0
|
||||
while True:
|
||||
_gen = ''.join(SystemRandom().choice(_character_pool) for _ in range(_length))
|
||||
for _character in _gen:
|
||||
if not _character.isalpha():
|
||||
_special += 1
|
||||
if _special >= _min_special:
|
||||
break
|
||||
return _gen
|
||||
|
||||
|
||||
def pass_gen(): # prompts the user for necessary information to generate a password and passes it to string_gen
|
||||
try:
|
||||
_length = int(input('password length: '))
|
||||
except ValueError:
|
||||
print(f"\n\u001b[38;5;9merror: a non-integer value was input for password length\u001b[0m\n")
|
||||
_gen = pass_gen()
|
||||
return _gen
|
||||
_complexity = str(input('password complexity - simple (for compatibility) or complex (for security)? (s/C) '))
|
||||
if _complexity != 's' and _complexity != 'S':
|
||||
_complexity = 'c'
|
||||
_gen = string_gen(_complexity.lower(), _length)
|
||||
return _gen
|
||||
|
||||
|
||||
def shm_gen(_tmp_dir=path.expanduser('~/.config/sshyp/tmp/')): # creates a temporary directory for entry editing
|
||||
_shm_folder_gen = string_gen('f', randint(12, 48))
|
||||
_shm_entry_gen = string_gen('f', randint(12, 48))
|
||||
Path(_tmp_dir + _shm_folder_gen).mkdir(0o700)
|
||||
return _shm_folder_gen, _shm_entry_gen
|
||||
|
||||
|
||||
def encrypt(_entry_dir, _shm_folder, _shm_entry, _gpg_com, _gpg_id, _tmp_dir=path.expanduser('~/.config/sshyp/tmp/')):
|
||||
# encrypts an entry and cleans up the temporary files
|
||||
system(f"{_gpg_com} -qr {str(_gpg_id)} -e '{_tmp_dir}{_shm_folder}/{_shm_entry}'")
|
||||
move(f"{_tmp_dir}{_shm_folder}/{_shm_entry}.gpg", f"{_entry_dir}.gpg")
|
||||
rmtree(f"{_tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def decrypt(_entry_dir, _shm_folder, _shm_entry, _gpg_com, _quick_pass,
|
||||
_tmp_dir=path.expanduser('~/.config/sshyp/tmp/')): # decrypts an entry to a temporary directory
|
||||
if not isinstance(_quick_pass, bool):
|
||||
_unlock_method = f"gpg --pinentry-mode loopback --passphrase '{_quick_pass}' -qd --output "
|
||||
else:
|
||||
_unlock_method = f"{_gpg_com} -qd --output "
|
||||
if _shm_folder == 0 and _shm_entry == 0:
|
||||
_output_target = f"/dev/null {path.expanduser('~/.config/sshyp/lock.gpg')}"
|
||||
else:
|
||||
_output_target = f"'{_tmp_dir}{_shm_folder}/{_shm_entry}' '{_entry_dir}.gpg'"
|
||||
try:
|
||||
run(_unlock_method + _output_target, shell=True, stderr=PIPE, check=True, close_fds=True)
|
||||
except CalledProcessError:
|
||||
if not isinstance(_quick_pass, bool):
|
||||
print('\n\u001b[38;5;9merror: quick-unlock failed as a result of an incorrect passphrase, an unreachable '
|
||||
'sshyp server, or an invalid configuration\n\nfalling back to standard unlock\u001b[0m\n')
|
||||
try:
|
||||
run(f"{_gpg_com} -qd --output {_output_target}", shell=True, stderr=PIPE, check=True,
|
||||
close_fds=True)
|
||||
except CalledProcessError:
|
||||
print('\n\u001b[38;5;9merror: could not decrypt - ensure the correct gpg key is present\u001b[0m\n')
|
||||
s_exit(5)
|
||||
else:
|
||||
print('\n\u001b[38;5;9merror: could not decrypt - ensure the correct gpg key is present\u001b[0m\n')
|
||||
s_exit(5)
|
||||
|
||||
|
||||
def determine_decrypt(_entry_dir, _shm_folder, _shm_entry, _gpg_com):
|
||||
if quick_unlock_enabled == 'y':
|
||||
decrypt(_entry_dir, _shm_folder, _shm_entry, _gpg_com, whitelist_verify(port, username_ssh, ip,
|
||||
client_device_id))
|
||||
else:
|
||||
decrypt(_entry_dir, _shm_folder, _shm_entry, _gpg_com, False)
|
||||
|
||||
|
||||
def optimized_edit(_lines, _edit_data, _edit_line): # ensures an edited entry is optimized for best compatibility
|
||||
while len(_lines) < _edit_line + 1:
|
||||
_lines += ['\n']
|
||||
if _edit_data is not None:
|
||||
_lines[_edit_line] = _edit_data.strip('\n').rstrip() + '\n'
|
||||
for _num in range(len(_lines)):
|
||||
if not _lines[_num].endswith('\n'):
|
||||
_lines[_num] += '\n'
|
||||
for _num in reversed(range(len(_lines))):
|
||||
if _lines[_num] == '\n':
|
||||
_lines = _lines[:-1]
|
||||
elif _lines[_num].endswith('\n'):
|
||||
_lines[_num] = _lines[_num].rstrip()
|
||||
break
|
||||
else:
|
||||
break
|
||||
return _lines
|
||||
|
||||
|
||||
def edit_note(_shm_folder, _shm_entry, _lines): # edits the note attached to an entry
|
||||
_reg_lines = _lines[0:3]
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'w').writelines(_lines[3:])
|
||||
system(f"{editor} '{tmp_dir}{_shm_folder}/{_shm_entry}-n'")
|
||||
_new_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n").readlines()
|
||||
while len(_reg_lines) < 3:
|
||||
_reg_lines += ['\n']
|
||||
_noted_lines = _reg_lines + _new_notes
|
||||
return _noted_lines
|
||||
|
||||
|
||||
def copy_id_check(_port, _username_ssh, _ip, _client_device_id):
|
||||
# attempts to connect to the user's server via ssh to register the device for syncing
|
||||
_command = f"ssh -o ConnectTimeout=3 -i '{path.expanduser('~/.ssh/sshyp')}' -p {_port} {_username_ssh}@{_ip} " \
|
||||
f"\"touch '/home/{_username_ssh}/.config/sshyp/devices/{_client_device_id}'\""
|
||||
try:
|
||||
run(_command, shell=True, stderr=PIPE, check=True, close_fds=True)
|
||||
except CalledProcessError:
|
||||
print('\n\u001b[38;5;9mwarning: ssh connection could not be made - ensure the public key (~/.ssh/sshyp.pub) is '
|
||||
'registered on the remote server and that the entered ip, port, and username are correct\n\nsyncing '
|
||||
'functionality will be disabled until this is addressed\u001b[0m\n')
|
||||
open(path.expanduser('~/.config/sshyp/ssh-error'), 'w').write('1')
|
||||
return 1
|
||||
open(path.expanduser('~/.config/sshyp/ssh-error'), 'w').write('0')
|
||||
return 0
|
||||
|
||||
# BELOW - argument-specific functions
|
||||
|
||||
|
||||
def tweak(): # runs configuration wizard
|
||||
_divider = f"\n{'=' * (get_terminal_size()[0] - int((.5 * get_terminal_size()[0])))}\n\n"
|
||||
|
||||
# config directory creation
|
||||
Path(path.expanduser('~/.config/sshyp/devices')).mkdir(0o700, parents=True, exist_ok=True)
|
||||
if not Path(f"{path.expanduser('~/.config/sshyp/tmp')}").exists():
|
||||
if uname()[0] == 'Haiku' or uname()[0] == 'FreeBSD':
|
||||
system(f"ln -s /tmp {path.expanduser('~/.config/sshyp/tmp')}")
|
||||
elif Path("/data/data/com.termux").exists():
|
||||
system(f"ln -s '/data/data/com.termux/files/usr/tmp' {path.expanduser('~/.config/sshyp/tmp')}")
|
||||
else:
|
||||
system(f"ln -s /dev/shm {path.expanduser('~/.config/sshyp/tmp')}")
|
||||
|
||||
# device type configuration
|
||||
_device_type = input('\nclient or server installation? (C/s) ')
|
||||
if _device_type.lower() == 's':
|
||||
_sshyp_data = ['server']
|
||||
Path(path.expanduser('~/.config/sshyp/deleted')).mkdir(0o700, exist_ok=True)
|
||||
Path(path.expanduser('~/.config/sshyp/whitelist')).mkdir(0o700, exist_ok=True)
|
||||
print(f"\n\u001b[4;1mmake sure the ssh service is running and properly configured\u001b[0m")
|
||||
else:
|
||||
_sshyp_data = ['client']
|
||||
Path(path.expanduser('~/.local/share/sshyp')).mkdir(0o700, parents=True, exist_ok=True)
|
||||
|
||||
# gpg configuration
|
||||
_gpg_gen = input(f"{_divider}sshyp requires the use of a unique gpg key - use an (e)xisting key or (g)enerate a"
|
||||
f" new one? (E/g) ")
|
||||
if _gpg_gen.lower() != 'g':
|
||||
system(f"{gpg} -k")
|
||||
_sshyp_data += [str(input('gpg key id: '))]
|
||||
else:
|
||||
print('\na unique gpg key is being generated for you...')
|
||||
if not Path(path.expanduser('~/.config/sshyp/gpg-gen')).is_file():
|
||||
open(path.expanduser('~/.config/sshyp/gpg-gen'), 'w').writelines([
|
||||
'Key-Type: 1\n', 'Key-Length: 4096\n', 'Key-Usage: sign encrypt\n', 'Name-Real: sshyp\n',
|
||||
'Name-Comment: gpg-sshyp\n', 'Name-Email: https://github.com/rwinkhart/sshyp\n', 'Expire-Date: 0'])
|
||||
if uname()[0] == 'Haiku':
|
||||
run(gpg + ' --batch --generate-key --passphrase ' + "'" +
|
||||
input('\ngpg passphrase: ') + "'" + " '" +
|
||||
path.expanduser('~/.config/sshyp/gpg-gen') + "'", shell=True)
|
||||
else:
|
||||
run(f"{gpg} --batch --generate-key '{path.expanduser('~/.config/sshyp/gpg-gen')}'", shell=True)
|
||||
remove(path.expanduser('~/.config/sshyp/gpg-gen'))
|
||||
_sshyp_data += [run(f"{gpg} -k", shell=True, stdout=PIPE, text=True).stdout.split('\n')[-4].strip()]
|
||||
|
||||
# text editor configuration
|
||||
_sshyp_data += [input(f"{_divider}example input: vim\n\npreferred text editor: ")]
|
||||
|
||||
# lock file generation
|
||||
if Path(path.expanduser('~/.config/sshyp/lock.gpg')).is_file():
|
||||
remove(path.expanduser('~/.config/sshyp/lock.gpg'))
|
||||
open(path.expanduser('~/.config/sshyp/lock'), 'w')
|
||||
system(f"{gpg} -qr {str(_sshyp_data[1])} -e {path.expanduser('~/.config/sshyp/lock')}")
|
||||
remove(path.expanduser('~/.config/sshyp/lock'))
|
||||
|
||||
# ssh key configuration
|
||||
_offline_mode = False
|
||||
_ssh_gen = (input(f"{_divider}make sure the ssh service on the remote server is running and properly "
|
||||
f"configured\n\nsync support requires a unique ssh key - would you like to have this "
|
||||
f"automatically generated? (Y/n/o(ffline)) "))
|
||||
if _ssh_gen.lower() != 'n' and _ssh_gen.lower() != 'o' and _ssh_gen.lower() != 'offline':
|
||||
if uname()[0] == 'Haiku':
|
||||
Path(f"{path.expanduser('~')}/.ssh").mkdir(0o700, exist_ok=True)
|
||||
system('ssh-keygen -t ed25519 -f ~/.ssh/sshyp')
|
||||
elif _ssh_gen.lower() == 'n':
|
||||
print(f"\n\u001b[4;1mensure that the key file you are using is located at "
|
||||
f"{path.expanduser('~/.ssh/sshyp')}\u001b[0m")
|
||||
elif _ssh_gen.lower() == 'o' or _ssh_gen.lower() == 'offline':
|
||||
_offline_mode = True
|
||||
print('\nsshyp has been set to offline mode - to enable syncing, run "sshyp tweak" again')
|
||||
|
||||
if not _offline_mode:
|
||||
# ssh ip+port configuration
|
||||
_ip_port = str(input(f"{_divider}example input: 10.10.10.10:9999\n\nip and ssh port of sshyp server: "))
|
||||
_ip, _sep, _port = _ip_port.partition(':')
|
||||
|
||||
# ssh user configuration
|
||||
_username_ssh = str(input('\nusername of the remote server: '))
|
||||
|
||||
# sshync profile generation
|
||||
sshync.make_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'),
|
||||
path.expanduser('~/.local/share/sshyp/'), f"/home/{_username_ssh}/.local/share/sshyp/",
|
||||
path.expanduser('~/.ssh/sshyp'), _ip, _port, _username_ssh)
|
||||
|
||||
# device id configuration
|
||||
for _id in listdir(path.expanduser('~/.config/sshyp/devices')): # remove existing device id
|
||||
remove(f"{path.expanduser('~/.config/sshyp/devices/')}{_id}")
|
||||
print(f"{_divider}\u001b[4;1mimportant:\u001b[0m this id \u001b[4;1mmust\u001b[0m be unique amongst your "
|
||||
f"client devices\n\nthis is used to keep track of database syncing and quick-unlock permissions\n")
|
||||
_device_id_prefix = str(input('device id: ')) + '-'
|
||||
_device_id_suffix = string_gen('f', randint(24, 48))
|
||||
_device_id = _device_id_prefix + _device_id_suffix
|
||||
open(f"{path.expanduser('~/.config/sshyp/devices/')}{_device_id}", 'w')
|
||||
|
||||
# quick-unlock configuration
|
||||
print(f"{_divider}this allows you to use a shorter version of your gpg key password and\n"
|
||||
f"requires a constant connection to your sshyp server to authenticate")
|
||||
_sshyp_data += [input('\nenable quick-unlock? (y/N) ').lower()]
|
||||
if _sshyp_data[3] == 'y':
|
||||
print(f"\nquick-unlock has been enabled client-side - in order for this device to be able to read "
|
||||
f"entries,\nyou must first login to the sshyp server and run:\n\nsshyp whitelist setup "
|
||||
f"(if not already done)\nsshyp whitelist add '{_device_id}'")
|
||||
|
||||
# test server connection and attempt to register device id
|
||||
copy_id_check(_port, _username_ssh, _ip, _device_id)
|
||||
|
||||
elif Path(path.expanduser('~/.config/sshyp/sshyp.sshync')).is_file():
|
||||
remove(path.expanduser('~/.config/sshyp/sshyp.sshync'))
|
||||
|
||||
# write main config file (sshyp-data)
|
||||
with open(path.expanduser('~/.config/sshyp/sshyp-data'), 'w') as _config_file:
|
||||
_lines = 0
|
||||
for _item in _sshyp_data:
|
||||
_lines += 1
|
||||
_config_file.write(_item + '\n')
|
||||
while _lines < 4:
|
||||
_lines += 1
|
||||
_config_file.write('n')
|
||||
print(f"{_divider}configuration complete\n")
|
||||
|
||||
|
||||
def print_info(): # prints help text based on argument
|
||||
if argument_list[1] == 'help' or argument_list[1] == '--help' or argument_list[1] == '-h':
|
||||
print('\n\u001b[1msshyp copyright (c) 2021-2022 randall winkhart\u001b[0m\n')
|
||||
print("this is free software, and you are welcome to redistribute it under certain conditions;\nthis program "
|
||||
"comes with absolutely no warranty;\ntype 'sshyp license' for details")
|
||||
if device_type == 'client':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp [option [flag] [<entry name>]] | [/<entry name>]\n')
|
||||
print('\u001b[1moptions:\u001b[0m')
|
||||
print('help/--help/-h bring up this menu')
|
||||
print('version/-v display sshyp version info')
|
||||
print('tweak configure sshyp')
|
||||
print('add add an entry')
|
||||
print('gen generate a new password')
|
||||
print('edit edit an existing entry')
|
||||
print('copy copy details of an entry to your clipboard')
|
||||
print('shear/-rm delete an existing entry')
|
||||
print('sync/-s manually sync the entry directory via sshync')
|
||||
print('\n\u001b[1mflags:\u001b[0m')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print(' note/-n change the note attached to an entry')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the url of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard')
|
||||
print('gen:')
|
||||
print(' update/-u generate a password for an existing entry')
|
||||
print("\n\u001b[1mtip:\u001b[0m you can quickly read an entry with 'sshyp /<entry name>'\n")
|
||||
else:
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp [option [flag] [<device id>]]\n')
|
||||
print('\u001b[1moptions:\u001b[0m')
|
||||
print('help/--help/-h bring up this menu')
|
||||
print('version/-v display sshyp version info')
|
||||
print('tweak configure sshyp')
|
||||
print('whitelist manage the quick-unlock whitelist')
|
||||
print('\n\u001b[1mflags:\u001b[0m')
|
||||
print('whitelist:')
|
||||
print(' setup set up the quick-unlock whitelist')
|
||||
print(' list/-l view all registered device ids and their quick-unlock whitelist status')
|
||||
print(' add whitelist a device id for quick-unlock')
|
||||
print(' delete/del remove a device id from the quick-unlock whitelist\n')
|
||||
elif argument_list[1] == 'version' or argument_list[1] == '-v':
|
||||
print('\nsshyp is a simple, self-hosted, sftp-synchronized password manager\nfor unix(-like) systems (haiku/'
|
||||
'freebsd/linux/termux)\n\nsshyp is a viable alternative to (and compatible with) pass/password-store\n')
|
||||
print(" .. \u001b[38;5;9m♥♥ ♥♥\u001b[0m ..\n .''.''/()\\ \u001b[38;5;13m"
|
||||
"♥♥♥♥♥♥♥\u001b[0m /()\\''.''.\n * : \u001b[38;5;9m♥♥♥♥♥\u001b[0m : *"
|
||||
"\n `..'..' \u001b[38;5;13m♥♥♥\u001b[0m `..'..'\n // \\\\ "
|
||||
"\u001b[38;5;9m♥\u001b[0m // \\\\")
|
||||
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8msshyp copyright (c) 2021-2022 '
|
||||
'randall winkhart\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mversion 1.2.0'
|
||||
'\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mthe brisk bahh '
|
||||
'update\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m\n')
|
||||
print('see https://github.com/rwinkhart/sshyp for more information\n')
|
||||
elif argument_list[1] == 'license':
|
||||
print('\nThis program is free software: you can redistribute it and/or modify it under the terms\nof version 3 '
|
||||
'(only) of the GNU General Public License as published by the Free Software Foundation.\n\nThis program '
|
||||
'is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;\nwithout even the implied '
|
||||
'warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.\nSee the GNU General Public License for'
|
||||
' more details.\n\nhttps://opensource.org/licenses/GPL-3.0\n')
|
||||
elif argument_list[1] == 'add':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp add [flag [<entry name>]]\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries\n')
|
||||
elif argument_list[1] == 'edit':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp edit [flag [<entry name>]]\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print(' note/-n change the note attached to an entry\n')
|
||||
elif argument_list[1] == 'copy':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp copy [flag [<entry name>]]\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the url of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard\n')
|
||||
elif argument_list[1] == 'whitelist':
|
||||
if device_type == 'server':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp whitelist [flag [<device id>]]\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('whitelist:')
|
||||
print(' setup set up the quick-unlock whitelist')
|
||||
print(' list/-l view all registered device ids and their quick-unlock whitelist status')
|
||||
print(' add whitelist a device id for quick-unlock')
|
||||
print(' delete/del remove a device id from the quick-unlock whitelist\n')
|
||||
else:
|
||||
print('\n\u001b[38;5;9merror: argument (whitelist) only available on server\u001b[0m\n')
|
||||
s_exit(0)
|
||||
|
||||
|
||||
def no_arg(): # displays a list of entries and gives an option to select one for viewing
|
||||
print("\nfor a list of usable commands, run 'sshyp help'")
|
||||
_entry_name = entry_name_fetch('entry to read: ')
|
||||
if not Path(f"{directory}{_entry_name}.gpg").exists():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(3)
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg)
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def read_shortcut(): # shortcut to quickly read an entry
|
||||
if not Path(f"{directory}{argument.replace('/', '', 1)}.gpg").exists():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({argument.replace('/', '', 1)}) does not exist\u001b[0m\n")
|
||||
s_exit(3)
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + argument.replace('/', '', 1), _shm_folder, _shm_entry, gpg)
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def sync(): # calls sshync to sync changes to the user's server
|
||||
print('\nsyncing entries with the server device...\n')
|
||||
# check for deletions
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /lib/sshyp; python -c "
|
||||
f"'import sshypRemote; sshypRemote.deletion_check(\"'\"{client_device_id}\"'\")'\"")
|
||||
system(f"scp -pqs -P {port} -i '{path.expanduser('~/.ssh/sshyp')}' {username_ssh}@{ip}:'/home/{username_ssh}"
|
||||
f"/.config/sshyp/deletion_database' {path.expanduser('~/.config/sshyp/')}")
|
||||
try:
|
||||
_deletion_database = open(path.expanduser('~/.config/sshyp/deletion_database')).readlines()
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\n\u001b[38;5;9merror: the deletion database does not exist or is corrupted\u001b[0m\n')
|
||||
_deletion_database = None
|
||||
s_exit(6)
|
||||
for _file in _deletion_database:
|
||||
try:
|
||||
if silent_sync != 1:
|
||||
print(f"\u001b[38;5;208m{_file[:-1]}\u001b[0m has been sheared, removing...")
|
||||
if _file[:-1].endswith('/'):
|
||||
rmtree(f"{directory}{_file[:-1]}")
|
||||
else:
|
||||
remove(f"{directory}{_file[:-1]}.gpg")
|
||||
except FileNotFoundError:
|
||||
if silent_sync != 1:
|
||||
print('location does not exist locally')
|
||||
# check for new folders
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /lib/sshyp; python -c "
|
||||
f"'import sshypRemote; sshypRemote.folder_check()'\"")
|
||||
system(f"scp -pqs -P {port} -i '{path.expanduser('~/.ssh/sshyp')}' {username_ssh}@{ip}:'/home/{username_ssh}"
|
||||
f"/.config/sshyp/folder_database' {path.expanduser('~/.config/sshyp/')}")
|
||||
try:
|
||||
_folder_database = open(path.expanduser('~/.config/sshyp/folder_database')).readlines()
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\n\u001b[38;5;9merror: the folder database does not exist or is corrupted\u001b[0m\n')
|
||||
_folder_database = None
|
||||
s_exit(6)
|
||||
for _folder in _folder_database:
|
||||
if Path(f"{path.expanduser('~')}{_folder[:-1]}").is_dir():
|
||||
pass
|
||||
else:
|
||||
print(f"\u001b[38;5;2m{_folder.replace('/.local/share/sshyp/', '')[:-1]}/\u001b[0m does not exist locally, "
|
||||
f"creating...")
|
||||
Path(f"{path.expanduser('~')}{_folder[:-1]}").mkdir(0o700, parents=True, exist_ok=True)
|
||||
# set permissions before uploading
|
||||
system('find ' + directory + ' -type d -exec chmod -R 700 {} +')
|
||||
system('find ' + directory + ' -type f -exec chmod -R 600 {} +')
|
||||
sshync.run_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'))
|
||||
|
||||
|
||||
def whitelist_setup(): # takes input from the user to set up quick-unlock password
|
||||
_gpg_password_temp = str(input('\nfull gpg passphrase: '))
|
||||
_half_length = int(len(_gpg_password_temp)/2)
|
||||
try:
|
||||
_short_password_length = int(input(f"\nquick unlock pin length (must be half the length of gpg password or "
|
||||
f"less) ({_half_length}): "))
|
||||
if _short_password_length > _half_length:
|
||||
_short_password_length = _half_length
|
||||
except ValueError:
|
||||
_short_password_length = _half_length
|
||||
_i, _quick_unlock_password, _quick_unlock_password_excluded = 0, '', ''
|
||||
for _char in _gpg_password_temp:
|
||||
if _i % 2 == 1 and _i < _short_password_length*2:
|
||||
_quick_unlock_password += _char
|
||||
else:
|
||||
_quick_unlock_password_excluded += _char
|
||||
_i += 1
|
||||
|
||||
# create assembly key
|
||||
open(path.expanduser('~/.config/sshyp/gpg-gen'), 'w').writelines([
|
||||
'Key-Type: 1\n', 'Key-Length: 4096\n', 'Key-Usage: sign encrypt\n', 'Name-Real: sshyp\n',
|
||||
'Name-Comment: gpg-sshyp-whitelist\n', 'Name-Email: https://github.com/rwinkhart/sshyp\n', 'Expire-Date: 0'])
|
||||
run('gpg -q --pinentry-mode loopback --batch --generate-key --passphrase ' + "'" + _quick_unlock_password + "'" +
|
||||
" '" + path.expanduser('~/.config/sshyp/gpg-gen') + "'", shell=True)
|
||||
remove(path.expanduser('~/.config/sshyp/gpg-gen'))
|
||||
_gpg_id = run(f"{gpg} -k", shell=True, stdout=PIPE, text=True).stdout.split('\n')[-4].strip()
|
||||
|
||||
# encrypt excluded with the assembly key
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').write(_quick_unlock_password_excluded)
|
||||
encrypt(path.expanduser('~/.config/sshyp/excluded'), _shm_folder, _shm_entry, gpg, _gpg_id)
|
||||
print(f"\nyour quick-unlock passphrase: {_quick_unlock_password}")
|
||||
|
||||
|
||||
def whitelist_verify(_port, _username_ssh, _ip, _client_device_id):
|
||||
# checks the user's whitelist status and fetches the full gpg key password if possible
|
||||
try:
|
||||
run(f"gpg --pinentry-mode cancel -qd --output /dev/null {path.expanduser('~/.config/sshyp/lock.gpg')}",
|
||||
shell=True, stderr=PIPE, check=True, close_fds=True)
|
||||
return False
|
||||
except CalledProcessError:
|
||||
_i, _full_password = 0, ''
|
||||
_server_whitelist = run('ssh -i ' + "'" + path.expanduser('~/.ssh/sshyp') + "' -p " + _port + " " +
|
||||
_username_ssh + '@' + _ip + " 'ls ~/.config/sshyp/whitelist'",
|
||||
shell=True, stdout=PIPE, text=True)
|
||||
for _device_id in _server_whitelist.stdout.rstrip().split('\n'):
|
||||
if _device_id == _client_device_id:
|
||||
_quick_unlock_password = input('\nquick-unlock passphrase: ')
|
||||
_quick_unlock_password_excluded = \
|
||||
run('ssh -i ' + "'" + path.expanduser('~/.ssh/sshyp') + "' -p " + _port + " " + _username_ssh + '@'
|
||||
+ _ip + f" 'gpg --pinentry-mode loopback --passphrase '{_quick_unlock_password}' -qd"
|
||||
f" ~/.config/sshyp/excluded.gpg'", shell=True, stdout=PIPE, text=True).stdout.rstrip()
|
||||
while _i < len(_quick_unlock_password_excluded):
|
||||
try:
|
||||
_full_password += _quick_unlock_password_excluded[_i]
|
||||
except IndexError:
|
||||
pass
|
||||
try:
|
||||
_full_password += _quick_unlock_password[_i]
|
||||
except IndexError:
|
||||
pass
|
||||
_i += 1
|
||||
break
|
||||
return _full_password
|
||||
|
||||
|
||||
def whitelist_list(): # shows the quick-unlock whitelist status of device ids
|
||||
_whitelisted_ids = listdir(path.expanduser('~/.config/sshyp/whitelist'))
|
||||
_device_ids = listdir(path.expanduser('~/.config/sshyp/devices'))
|
||||
print('\n\u001b[1mquick-unlock whitelisted device ids:\u001b[0m')
|
||||
for _id in _whitelisted_ids:
|
||||
print(_id)
|
||||
print('\n\u001b[1mother registered device ids:\u001b[0m')
|
||||
for _id in _device_ids:
|
||||
if _id not in _whitelisted_ids:
|
||||
print(_id)
|
||||
print()
|
||||
|
||||
|
||||
def whitelist_manage(): # adds or removes quick-unlock whitelisted device ids
|
||||
if len(argument_list) == 3:
|
||||
whitelist_list()
|
||||
_device_id = input('device id: ')
|
||||
else:
|
||||
_argument_split = argument.split(' ')
|
||||
del _argument_split[:2]
|
||||
_device_id = ' '.join(_argument_split)
|
||||
|
||||
if argument_list[2] == 'add':
|
||||
if _device_id in listdir(path.expanduser('~/.config/sshyp/devices')):
|
||||
open(path.expanduser(f"~/.config/sshyp/whitelist/{_device_id}"), 'w').write('')
|
||||
whitelist_list()
|
||||
else:
|
||||
print(f"\n\u001b[38;5;9merror: device id ({_device_id}) is not registered\u001b[0m\n")
|
||||
s_exit(2)
|
||||
|
||||
elif Path(path.expanduser(f"~/.config/sshyp/whitelist/{_device_id}")).is_file():
|
||||
remove(path.expanduser(f"~/.config/sshyp/whitelist/{_device_id}"))
|
||||
whitelist_list()
|
||||
|
||||
|
||||
def add_entry(): # adds a new entry
|
||||
_shm_folder, _shm_entry = None, None # sets base-line values to avoid errors
|
||||
if len(argument_list) < 4:
|
||||
_entry_name = entry_name_fetch('name of new entry: ')
|
||||
else:
|
||||
_entry_name = entry_name_fetch(2)
|
||||
if Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) already exists\u001b[0m\n")
|
||||
s_exit(4)
|
||||
if argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"{editor} '{tmp_dir}{_shm_folder}/{_shm_entry}-n'")
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(optimized_edit(['', '', '', _notes], None, -1))
|
||||
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||
_username = str(input('username: '))
|
||||
_password = str(input('password: '))
|
||||
_url = str(input('url: '))
|
||||
_add_note = input('add a note to this entry? (y/N) ')
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
if _add_note.lower() == 'y':
|
||||
system(f"{editor} '{tmp_dir}{_shm_folder}/{_shm_entry}-n'")
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
else:
|
||||
_notes = ''
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w')\
|
||||
.writelines(optimized_edit([_password, _username, _url, _notes], None, -1))
|
||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
encrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg, gpg_id)
|
||||
|
||||
|
||||
def add_folder(): # creates a new folder
|
||||
if len(argument_list) < 4:
|
||||
_entry_name = entry_name_fetch('name of new folder: ')
|
||||
else:
|
||||
_entry_name = entry_name_fetch(2)
|
||||
Path(directory + _entry_name).mkdir(0o700)
|
||||
if ssh_error != 1:
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"mkdir -p "
|
||||
f"'{directory_ssh}{_entry_name}'\"")
|
||||
|
||||
|
||||
def rename(): # renames an entry or folder
|
||||
if argument == 'edit rename' or argument == 'edit relocate' or argument == 'edit -r':
|
||||
_entry_name = entry_name_fetch('entry/folder to rename/relocate: ')
|
||||
else:
|
||||
_entry_name = entry_name_fetch(2)
|
||||
if not Path(f"{directory}{_entry_name}.gpg").is_file() and not Path(f"{directory}{_entry_name}").is_dir():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(3)
|
||||
_new_name = entry_name_fetch('new name: ')
|
||||
if Path(f"{directory}{_new_name}.gpg").is_file() or Path(f"{directory}{_new_name}").is_dir():
|
||||
print(f"\n\u001b[38;5;9merror: ({_new_name}) already exists\u001b[0m\n")
|
||||
s_exit(4)
|
||||
if _entry_name.endswith('/'):
|
||||
move(f"{directory}{_entry_name}", f"{directory}{_new_name}")
|
||||
if ssh_error != 1:
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"mkdir -p "
|
||||
f"'{directory_ssh}{_new_name}'\"")
|
||||
else:
|
||||
move(f"{directory}{_entry_name}.gpg", f"{directory}{_new_name}.gpg")
|
||||
if ssh_error != 1:
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /lib/sshyp; python -c "
|
||||
f"'import sshypRemote; sshypRemote.delete(\"'\"{_entry_name}\"'\", \"'\"remotely\"'\")'\"")
|
||||
|
||||
|
||||
def edit(): # edits the contents of an entry
|
||||
_shm_folder, _shm_entry, _detail, _edit_line = None, None, None, None # sets values to avoid PEP8 warnings
|
||||
if len(argument_list) < 4:
|
||||
_entry_name = entry_name_fetch('entry to edit: ')
|
||||
else:
|
||||
_entry_name = entry_name_fetch(2)
|
||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(3)
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg)
|
||||
if argument_list[2] == 'username' or argument_list[2] == '-u':
|
||||
_detail, _edit_line = str(input('username: ')), 1
|
||||
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||
_detail, _edit_line = str(input('password: ')), 0
|
||||
elif argument_list[2] == 'url' or argument_list[2] == '-l':
|
||||
_detail, _edit_line = str(input('url: ')), 2
|
||||
if argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
_edit_line = 2
|
||||
_new_lines = optimized_edit(edit_note(_shm_folder, _shm_entry,
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines()), None, -1)
|
||||
else:
|
||||
_new_lines = optimized_edit(open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), _detail, _edit_line)
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_new_lines)
|
||||
remove(f"{directory}{_entry_name}.gpg")
|
||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
encrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg, gpg_id)
|
||||
|
||||
|
||||
def gen(): # generates a password for a new or an existing entry
|
||||
_username, _url, _notes = None, None, None # sets base-line values to avoid errors
|
||||
if argument == 'gen update' or argument == 'gen -u' or argument == 'gen':
|
||||
_entry_name = entry_name_fetch('name of entry: ')
|
||||
elif argument_list[2] == 'update' or argument_list[2] == '-u':
|
||||
_entry_name = entry_name_fetch(2)
|
||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(3)
|
||||
else:
|
||||
_entry_name = entry_name_fetch(1)
|
||||
if len(argument_list) == 2 or (not argument_list[2] == 'update' and not argument_list[2] == '-u'):
|
||||
if Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) already exists\u001b[0m\n")
|
||||
s_exit(4)
|
||||
_username = str(input('username: '))
|
||||
_password = pass_gen()
|
||||
_url = str(input('url: '))
|
||||
_add_note = input('add a note to this entry? (y/N) ')
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
if _add_note.lower() == 'y':
|
||||
system(f"{editor} '{tmp_dir}{_shm_folder}/{_shm_entry}-n'")
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
else:
|
||||
_notes = ''
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w')\
|
||||
.writelines(optimized_edit([_password, _username, _url, _notes], None, -1))
|
||||
else:
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg)
|
||||
_new_lines = optimized_edit(open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), pass_gen(), 0)
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_new_lines)
|
||||
remove(f"{directory}{_entry_name}.gpg")
|
||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
encrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg, gpg_id)
|
||||
|
||||
|
||||
def copy_data(): # copies a specified field of an entry to the clipboard
|
||||
if len(argument_list) < 4:
|
||||
_entry_name = entry_name_fetch('entry to copy: ')
|
||||
else:
|
||||
_entry_name = entry_name_fetch(2)
|
||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||
print(f"\n\u001b[38;5;9merror: entry ({_entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(3)
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + _entry_name, _shm_folder, _shm_entry, gpg)
|
||||
_copy_line = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines()
|
||||
if uname()[0] == 'Haiku': # Haiku clipboard detection
|
||||
if argument_list[2] == 'username' or argument_list[2] == '-u':
|
||||
system('clipboard -c ' + "'" + _copy_line[1].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||
system('clipboard -c ' + "'" + _copy_line[0].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'url' or argument_list[2] == '-l':
|
||||
system('clipboard -c ' + "'" + _copy_line[2].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
system('clipboard -c ' + "'" + _copy_line[3].rstrip().replace("'", "'\\''") + "'")
|
||||
Popen('sleep 30; clipboard -r', shell=True, close_fds=True)
|
||||
elif Path("/data/data/com.termux").exists(): # Termux (Android) clipboard detection
|
||||
if argument_list[2] == 'username' or argument_list[2] == '-u':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[1].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[0].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'url' or argument_list[2] == '-l':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[2].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[3].rstrip().replace("'", "'\\''") + "'")
|
||||
Popen("sleep 30; termux-clipboard-set ''", shell=True, close_fds=True)
|
||||
elif environ.get('WAYLAND_DISPLAY') == 'wayland-0': # Wayland clipboard detection
|
||||
if argument_list[2] == 'username' or argument_list[2] == '-u':
|
||||
system('wl-copy ' + "'" + _copy_line[1].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||
system('wl-copy ' + "'" + _copy_line[0].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'url' or argument_list[2] == '-l':
|
||||
system('wl-copy ' + "'" + _copy_line[2].rstrip().replace("'", "'\\''") + "'")
|
||||
elif argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
system('wl-copy ' + "'" + _copy_line[3].rstrip().replace("'", "'\\''") + "'")
|
||||
Popen('sleep 30; wl-copy -c', shell=True, close_fds=True)
|
||||
else: # X11 clipboard detection
|
||||
if argument_list[2] == 'username' or argument_list[2] == '-u':
|
||||
system('echo -n ' + "'" + _copy_line[1].rstrip().replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
elif argument_list[2] == 'password' or argument_list[2] == '-p':
|
||||
system('echo -n ' + "'" + _copy_line[0].rstrip().replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
elif argument_list[2] == 'url' or argument_list[2] == '-l':
|
||||
system('echo -n ' + "'" + _copy_line[2].rstrip().replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
elif argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
system('echo -n ' + "'" + _copy_line[3].rstrip().replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
Popen("sleep 30; echo -n '' | xclip -sel c", shell=True, close_fds=True)
|
||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def remove_data(): # deletes an entry from the server and flags it for local deletion on sync
|
||||
if argument == 'shear' or argument == '-rm':
|
||||
_entry_name = entry_name_fetch('entry/folder to shear: ')
|
||||
else:
|
||||
_entry_name = entry_name_fetch(1)
|
||||
determine_decrypt(path.expanduser('~/.config/sshyp/lock.gpg'), 0, 0, gpg)
|
||||
if ssh_error != 1:
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"cd /lib/sshyp; python -c "
|
||||
f"'import sshypRemote; sshypRemote.delete(\"'\"{_entry_name}\"'\", \"'\"remotely\"'\")'\"")
|
||||
else:
|
||||
from sshypRemote import delete as offline_delete
|
||||
offline_delete(_entry_name, '')
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
try:
|
||||
silent_sync, ssh_error = 0, 0
|
||||
# retrieve typed argument
|
||||
argument_list = argv
|
||||
argument = ' '.join(argument_list[1:])
|
||||
if uname()[0] == 'Haiku': # set proper gpg command for OS
|
||||
gpg = 'gpg --pinentry-mode loopback'
|
||||
else:
|
||||
gpg = 'gpg'
|
||||
|
||||
# import saved userdata
|
||||
device_type = ''
|
||||
if argument != 'tweak':
|
||||
tmp_dir = path.expanduser('~/.config/sshyp/tmp/')
|
||||
try:
|
||||
sshyp_data = open(path.expanduser('~/.config/sshyp/sshyp-data')).readlines()
|
||||
device_type = sshyp_data[0].rstrip()
|
||||
if device_type == 'client':
|
||||
directory = path.expanduser('~/.local/share/sshyp/')
|
||||
gpg_id = sshyp_data[1].rstrip()
|
||||
editor = sshyp_data[2].rstrip()
|
||||
quick_unlock_enabled = sshyp_data[3].rstrip()
|
||||
if Path(path.expanduser('~/.config/sshyp/sshyp.sshync')).is_file():
|
||||
ssh_info = sshync.get_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'))
|
||||
username_ssh = ssh_info[0].rstrip()
|
||||
ip = ssh_info[1].rstrip()
|
||||
port = ssh_info[2].rstrip()
|
||||
directory_ssh = str(ssh_info[4].rstrip())
|
||||
client_device_id = listdir(path.expanduser('~/.config/sshyp/devices'))[0].rstrip()
|
||||
ssh_error = int(open(path.expanduser('~/.config/sshyp/ssh-error')).read().rstrip())
|
||||
if ssh_error != 0:
|
||||
ssh_error = copy_id_check(port, username_ssh, ip, client_device_id)
|
||||
else:
|
||||
ssh_error = 1
|
||||
elif len(argument_list) <= 1 or (argument_list[1] != "help" and argument_list[1] != "--help" and
|
||||
argument_list[1] != "-h" and argument_list[1] != "license" and
|
||||
argument_list[1] != "version" and argument_list[1] != "-v" and
|
||||
argument_list[1] != "whitelist"):
|
||||
print(f"\n\u001b[38;5;9merror: invalid server argument - run 'sshyp help' to "
|
||||
f"list usable commands\u001b[0m\n")
|
||||
s_exit(1)
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print("not all necessary configuration files are present - please run 'sshyp tweak'")
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
s_exit(2)
|
||||
else:
|
||||
tweak()
|
||||
s_exit(0)
|
||||
|
||||
# run function based on arguments
|
||||
if argument.startswith('/'):
|
||||
read_shortcut()
|
||||
elif argument == '':
|
||||
no_arg()
|
||||
elif argument == 'help' or argument == '--help' or argument == '-h' or argument == 'license' or argument \
|
||||
== 'version' or argument == '-v':
|
||||
print_info()
|
||||
elif argument_list[1] == 'whitelist':
|
||||
if device_type == 'server':
|
||||
if len(argument_list) == 2:
|
||||
print_info()
|
||||
elif argument_list[2] == 'list' or argument_list[2] == '-l':
|
||||
whitelist_list()
|
||||
elif argument_list[2] == 'add' or argument_list[2] == 'delete' or argument_list[2] == 'del':
|
||||
whitelist_manage()
|
||||
elif argument_list[2] == 'setup':
|
||||
whitelist_setup()
|
||||
else:
|
||||
print_info()
|
||||
else:
|
||||
print_info()
|
||||
elif argument_list[1] == 'add':
|
||||
if len(argument_list) == 2:
|
||||
print_info()
|
||||
elif argument_list[2] == 'note' or argument_list[2] == '-n' or argument_list[2] == 'password' or \
|
||||
argument_list[2] == '-p':
|
||||
add_entry()
|
||||
elif argument_list[2] == 'folder' or argument_list[2] == '-f':
|
||||
add_folder()
|
||||
else:
|
||||
print_info()
|
||||
elif argument_list[1] == 'edit':
|
||||
if len(argument_list) == 2:
|
||||
print_info()
|
||||
elif argument_list[2] == 'rename' or argument_list[2] == 'relocate' or argument_list[2] == '-r':
|
||||
silent_sync = 1
|
||||
rename()
|
||||
elif argument_list[2] == 'username' or argument_list[2] == '-u' or argument_list[2] == 'password' or \
|
||||
argument_list[2] == '-p' or argument_list[2] == 'url' or argument_list[2] == '-l' or \
|
||||
argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
edit()
|
||||
else:
|
||||
print_info()
|
||||
elif argument_list[1] == 'gen':
|
||||
gen()
|
||||
elif argument_list[1] == 'copy':
|
||||
if len(argument_list) == 2:
|
||||
print_info()
|
||||
elif argument_list[2] == 'username' or argument_list[2] == '-u' or argument_list[2] == 'password' or \
|
||||
argument_list[2] == '-p' or argument_list[2] == 'url' or argument_list[2] == '-l' or \
|
||||
argument_list[2] == 'note' or argument_list[2] == '-n':
|
||||
try:
|
||||
copy_data()
|
||||
except IndexError:
|
||||
print(f"\n\u001b[38;5;9merror: field does not exist in entry\u001b[0m\n")
|
||||
s_exit(3)
|
||||
else:
|
||||
print_info()
|
||||
elif argument_list[1] == 'shear' or argument_list[1] == '-rm':
|
||||
remove_data()
|
||||
elif argument_list[1] != 'sync' and argument_list[1] != '-s':
|
||||
print(f"\n\u001b[38;5;9merror: invalid argument - run 'sshyp help' to list usable commands\u001b[0m\n")
|
||||
s_exit(1)
|
||||
|
||||
# sync if any changes were made
|
||||
if len(argument_list) > 1 and ssh_error == 0 \
|
||||
and ((argument_list[1] == 'sync' or argument_list[1] == '-s' or argument_list[1] == 'gen' or
|
||||
argument_list[1] == 'shear' or argument_list[1] == '-rm') or
|
||||
((argument_list[1] == 'add' or argument_list[1] == 'edit') and len(argument_list) > 2)):
|
||||
sync()
|
||||
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
Executable
+42
@@ -0,0 +1,42 @@
|
||||
#!/usr/bin/env python3
|
||||
|
||||
# external modules
|
||||
|
||||
from os import listdir, remove, walk
|
||||
from os.path import expanduser
|
||||
from shutil import rmtree
|
||||
|
||||
|
||||
# utility functions
|
||||
|
||||
def delete(_file_path, _target_database): # deletes an entry or folder, should be run remotely via ssh
|
||||
try:
|
||||
if _file_path.endswith('/'):
|
||||
rmtree(f"{expanduser('~/.local/share/sshyp/')}{_file_path}")
|
||||
else:
|
||||
remove(f"{expanduser('~/.local/share/sshyp/')}{_file_path}.gpg")
|
||||
except FileNotFoundError:
|
||||
print(f"location does not exist {_target_database}")
|
||||
for _device_name in listdir(expanduser('~/.config/sshyp/devices')):
|
||||
open(f"{expanduser('~/.config/sshyp/deleted/')}{_file_path.replace('/', '@')}^&*{_device_name}", 'w')
|
||||
|
||||
|
||||
def deletion_check(_client_device_name): # creates a list of entries and folders to be deleted from a local machine
|
||||
open(expanduser('~/.config/sshyp/deletion_database'), 'w').write('')
|
||||
for _file in listdir(expanduser('~/.config/sshyp/deleted')):
|
||||
_file_path = _file.replace('@', '/').split('^&*')[0]
|
||||
_device = _file.split('^&*')[1]
|
||||
if _device == _client_device_name:
|
||||
try:
|
||||
remove(f"{expanduser('~/.config/sshyp/deleted/')}{_file}")
|
||||
except FileNotFoundError:
|
||||
pass
|
||||
open(expanduser('~/.config/sshyp/deletion_database'), 'a').write(_file_path + '\n')
|
||||
|
||||
|
||||
def folder_check(): # creates a list of folders to be compared with those of a local machine
|
||||
open(expanduser('~/.config/sshyp/folder_database'), 'w').write('')
|
||||
for _root, _directories, _files in walk(expanduser('~/.local/share/sshyp')):
|
||||
for _dir in _directories:
|
||||
open(expanduser('~/.config/sshyp/folder_database'), 'a')\
|
||||
.write(f"{_root.replace(expanduser('~'), '')}/{_dir}\n")
|
||||
Executable
+291
@@ -0,0 +1,291 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
version=$(sed -n '1{p;q}' share/doc/sshyp/changelog | cut -c8-)
|
||||
if [ -z "$2" ]; then
|
||||
revision=1
|
||||
else
|
||||
revision="$2"
|
||||
fi
|
||||
|
||||
_create_generic() {
|
||||
echo -e '\npackaging as generic...\n'
|
||||
mkdir -p output/generictemp/usr/{bin,lib/sshyp,share/{man/man1,bash-completion/completions}}
|
||||
cp -r lib/. output/generictemp/usr/lib/sshyp/
|
||||
ln -s /usr/lib/sshyp/sshyp.py output/generictemp/usr/bin/sshyp
|
||||
cp -r share output/generictemp/usr/
|
||||
cp extra/sshyp-completion.bash output/generictemp/usr/share/bash-completion/completions/sshyp
|
||||
cp extra/manpage output/generictemp/usr/share/man/man1/sshyp.1
|
||||
gzip output/generictemp/usr/share/man/man1/sshyp.1
|
||||
tar -C output/generictemp -cvJf output/sshyp-"$version".tar.xz usr/
|
||||
rm -rf output/generictemp
|
||||
sha512="$(sha512sum output/sshyp-"$version".tar.xz | awk '{print $1;}')"
|
||||
echo -e "\nsha512 sum:\n$sha512"
|
||||
echo -e "\ngeneric packaging complete\n"
|
||||
} &&
|
||||
|
||||
_create_pkgbuild() {
|
||||
source='https://github.com/rwinkhart/sshyp/releases/download/v$pkgver/sshyp-$pkgver.tar.xz'
|
||||
echo -e '\ngenerating PKGBUILD...'
|
||||
echo "# Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
pkgname=sshyp
|
||||
pkgver="$version"
|
||||
pkgrel="$revision"
|
||||
pkgdesc='A light-weight, self-hosted, synchronized password manager'
|
||||
url='https://github.com/rwinkhart/sshyp'
|
||||
arch=('any')
|
||||
license=('GPL-3.0-only')
|
||||
depends=(python gnupg openssh xclip wl-clipboard)
|
||||
optdepends=('bash-completion: bash completion support')
|
||||
source=(\""$source"\")
|
||||
sha512sums=('"$sha512"')
|
||||
|
||||
package() {
|
||||
tar xf sshyp-"\"\$pkgver\"".tar.xz -C "\"\${pkgdir}\""
|
||||
}
|
||||
" > output/PKGBUILD
|
||||
echo -e "\nPKGBUILD generated\n"
|
||||
} &&
|
||||
|
||||
_create_apkbuild() {
|
||||
echo -e '\ngenerating APKBUILD...'
|
||||
echo "# Maintainer: Randall Winkhart <idgr@tutanota.com>
|
||||
pkgname=sshyp
|
||||
pkgver="$version"
|
||||
pkgrel="$((revision-1))"
|
||||
pkgdesc='A light-weight, self-hosted, synchronized password manager'
|
||||
options=!check
|
||||
url='https://github.com/rwinkhart/sshyp'
|
||||
arch='noarch'
|
||||
license='GPL-3.0-only'
|
||||
depends='python3 gnupg openssh xclip wl-clipboard'
|
||||
source=\""$source"\"
|
||||
|
||||
package() {
|
||||
mkdir -p "\"\$pkgdir\""
|
||||
cp -r "\"\$srcdir/usr/"\" "\"\$pkgdir\""
|
||||
}
|
||||
|
||||
sha512sums=\"
|
||||
"$sha512' 'sshyp-\"\$pkgver\".tar.xz"
|
||||
\"
|
||||
" > output/APKBUILD
|
||||
echo -e "\nAPKBUILD generated\n"
|
||||
} &&
|
||||
|
||||
_create_hpkg() {
|
||||
echo -e '\npackaging for Haiku...\n'
|
||||
mkdir -p output/haikutemp/{bin,lib/sshyp,documentation/{packages/sshyp,man/man1},data/bash-completion/completions}
|
||||
echo "name sshyp
|
||||
version "$version"-"$revision"
|
||||
architecture any
|
||||
summary \"A light-weight, self-hosted, synchronized password manager\"
|
||||
description \"sshyp is the only password-store compatible CLI password manager available for Haiku - it is also available on Linux/Android (via Termux) so that you can sync your entries across all of your devices.\"
|
||||
packager \"Randall Winkhart <idgr at tutanota dot com>\"
|
||||
vendor \"Randall Winkhart\"
|
||||
licenses {
|
||||
\"GNU GPL v3\"
|
||||
}
|
||||
copyrights {
|
||||
\"2021-2022 Randall Winkhart\"
|
||||
}
|
||||
provides {
|
||||
sshyp = "$version"
|
||||
cmd:sshyp
|
||||
}
|
||||
requires {
|
||||
gnupg
|
||||
openssh
|
||||
python310
|
||||
}
|
||||
urls {
|
||||
\"https://github.com/rwinkhart/sshyp\"
|
||||
}
|
||||
" > output/haikutemp/.PackageInfo
|
||||
cp -r lib/. output/haikutemp/lib/sshyp/
|
||||
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshync.py
|
||||
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshyp.py
|
||||
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshypRemote.py
|
||||
ln -s /system/lib/sshyp/sshyp.py output/haikutemp/bin/sshyp
|
||||
cp -r share/doc/sshyp/. output/haikutemp/documentation/packages/sshyp/
|
||||
cp -r share/licenses/sshyp/. output/haikutemp/documentation/packages/sshyp/
|
||||
cp extra/sshyp-completion.bash output/haikutemp/data/bash-completion/completions/sshyp
|
||||
cp extra/manpage output/haikutemp/documentation/man/man1/sshyp.1
|
||||
gzip output/haikutemp/documentation/man/man1/sshyp.1
|
||||
cd output/haikutemp
|
||||
package create -b sshyp-"$version"-"$revision"_all.hpkg
|
||||
package add sshyp-"$version"-"$revision"_all.hpkg bin lib documentation data
|
||||
cd ../..
|
||||
mv output/haikutemp/sshyp-"$version"-"$revision"_all.hpkg output/
|
||||
rm -rf output/haikutemp
|
||||
echo -e "\nHaiku packaging complete\n"
|
||||
} &&
|
||||
|
||||
_create_deb() {
|
||||
echo -e '\npackaging for Debian/Ubuntu...\n'
|
||||
mkdir -p output/debiantemp/sshyp_"$version"-"$revision"_all/{DEBIAN,usr/{lib/sshyp,bin,share/{bash-completion/completions,man/man1}}}
|
||||
echo "Package: sshyp
|
||||
Version: $version
|
||||
Section: utils
|
||||
Architecture: all
|
||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
Description: A light-weight, self-hosted, synchronized password manager
|
||||
Depends: python3, gnupg, openssh-client, xclip, wl-clipboard
|
||||
Suggests: bash-completion
|
||||
Priority: optional
|
||||
Installed-Size: 14584
|
||||
" > output/debiantemp/sshyp_"$version"-"$revision"_all/DEBIAN/control
|
||||
cp -r lib/. output/debiantemp/sshyp_"$version"-"$revision"_all/usr/lib/sshyp/
|
||||
ln -s /usr/lib/sshyp/sshyp.py output/debiantemp/sshyp_"$version"-"$revision"_all/usr/bin/sshyp
|
||||
cp -r share output/debiantemp/sshyp_"$version"-"$revision"_all/usr/
|
||||
cp extra/sshyp-completion.bash output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/bash-completion/completions/sshyp
|
||||
cp extra/manpage output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||
gzip output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||
dpkg-deb --build --root-owner-group output/debiantemp/sshyp_"$version"-"$revision"_all/
|
||||
mv output/debiantemp/sshyp_"$version"-"$revision"_all.deb output/
|
||||
rm -rf output/debiantemp
|
||||
echo -e "\nDebian/Ubuntu packaging complete\n"
|
||||
} &&
|
||||
|
||||
_create_termux() {
|
||||
echo -e '\npackaging for Termux...\n'
|
||||
mkdir -p output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/{DEBIAN,data/data/com.termux/files/usr/{lib/sshyp,bin,share/{bash-completion/completions,man/man1}}}
|
||||
echo "Package: sshyp
|
||||
Version: $version
|
||||
Section: utils
|
||||
Architecture: all
|
||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
Description: A light-weight, self-hosted, synchronized password manager
|
||||
Depends: python, gnupg, openssh, termux-api, termux-am
|
||||
Suggests: bash-completion
|
||||
Priority: optional
|
||||
Installed-Size: 14584
|
||||
" > output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/DEBIAN/control
|
||||
cp -r lib/. output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/lib/sshyp/
|
||||
ln -s /data/data/com.termux/files/usr/lib/sshyp/sshyp.py output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/bin/sshyp
|
||||
cp -r share output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
|
||||
cp extra/sshyp-completion.bash output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/bash-completion/completions/sshyp
|
||||
cp extra/manpage output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||
gzip output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||
dpkg-deb --build --root-owner-group output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/
|
||||
mv output/termuxtemp/sshyp_"$version"-"$revision"_all_termux.deb output/
|
||||
rm -rf output/termuxtemp
|
||||
echo -e "\nTermux packaging complete\n"
|
||||
} &&
|
||||
|
||||
_create_rpm() {
|
||||
echo -e '\npackaging for Fedora...\n'
|
||||
rm -rf ~/rpmbuild
|
||||
rpmdev-setuptree
|
||||
cp output/sshyp-"$version".tar.xz ~/rpmbuild/SOURCES
|
||||
echo "Name: sshyp
|
||||
Version: "$version"
|
||||
Release: "$revision"
|
||||
Summary: A light-weight, self-hosted, synchronized password manager
|
||||
BuildArch: noarch
|
||||
License: GPL-3.0-only
|
||||
URL: https://github.com/rwinkhart/sshyp
|
||||
Source0: sshyp-"$version".tar.xz
|
||||
Requires: python gnupg openssh-clients wl-clipboard
|
||||
Recommends: bash-completion
|
||||
%description
|
||||
sshyp is a password-store compatible CLI password manager available for UNIX(-like) systems - its primary goal is to make syncing passwords and notes across devices as easy as possible via CLI.
|
||||
%install
|
||||
tar xf %{_sourcedir}/sshyp-"$version".tar.xz -C %{_sourcedir}
|
||||
cp -r %{_sourcedir}/usr %{buildroot}
|
||||
%files
|
||||
/usr/bin/sshyp
|
||||
/usr/lib/sshyp/sshyp.py
|
||||
/usr/lib/sshyp/sshync.py
|
||||
/usr/lib/sshyp/sshypRemote.py
|
||||
/usr/share/bash-completion/completions/sshyp
|
||||
%license /usr/share/licenses/sshyp/license
|
||||
%changelog /usr/share/doc/sshyp/changelog
|
||||
%doc /usr/share/man/man1/sshyp.1.gz
|
||||
" > ~/rpmbuild/SPECS/sshyp.spec
|
||||
rpmbuild -bb ~/rpmbuild/SPECS/sshyp.spec
|
||||
mv ~/rpmbuild/RPMS/noarch/* output/
|
||||
rm -rf ~/rpmbuild
|
||||
echo -e "\nFedora packaging complete\n"
|
||||
} &&
|
||||
|
||||
_create_freebsd_pkg() {
|
||||
echo -e '\npackaging for FreeBSD...'
|
||||
mkdir -p output/freebsdtemp/usr/{lib/sshyp,bin,share/{bash-completion/completions,man/man1}}
|
||||
echo "name: sshyp
|
||||
version: \""$version"\"
|
||||
abi = \"FreeBSD:13:*\";
|
||||
arch = \"freebsd:13:*\";
|
||||
origin: security/sshyp
|
||||
comment: \"a password manager\"
|
||||
desc: \"a light-weight, self-hosted, synchronized password manager\"
|
||||
maintainer: <idgr at tutanota dot com>
|
||||
www: https://github.com/rwinkhart/sshyp
|
||||
prefix: /
|
||||
\"deps\" : {
|
||||
\"python\" : {
|
||||
\"origin\" : \"lang/python\"
|
||||
},
|
||||
\"gnupg\" : {
|
||||
\"origin\" : \"security/gnupg\"
|
||||
},
|
||||
\"xclip\" : {
|
||||
\"origin\" : \"x11/xclip\"
|
||||
},
|
||||
\"wl-clipboard\" : {
|
||||
\"origin\" : \"x11/wl-clipboard\"
|
||||
},
|
||||
},
|
||||
" > output/freebsdtemp/+MANIFEST
|
||||
echo "/usr/bin/sshyp
|
||||
/usr/lib/sshyp/sshync.py
|
||||
/usr/lib/sshyp/sshyp.py
|
||||
/usr/lib/sshyp/sshypRemote.py
|
||||
/usr/share/bash-completion/completions/sshyp
|
||||
/usr/share/doc/sshyp/changelog
|
||||
/usr/share/licenses/sshyp/license
|
||||
/usr/share/man/man1/sshyp.1.gz
|
||||
" > output/freebsdtemp/plist
|
||||
cp -r lib/. output/freebsdtemp/usr/lib/sshyp/
|
||||
ln -s /usr/lib/sshyp/sshyp.py output/freebsdtemp/usr/bin/sshyp
|
||||
cp -r share output/freebsdtemp/usr/
|
||||
cp extra/sshyp-completion.bash output/freebsdtemp/usr/share/bash-completion/completions/sshyp
|
||||
cp extra/manpage output/freebsdtemp/usr/share/man/man1/sshyp.1
|
||||
gzip output/freebsdtemp/usr/share/man/man1/sshyp.1
|
||||
pkg create -m output/freebsdtemp/ -r output/freebsdtemp/ -p output/freebsdtemp/plist -o output/
|
||||
rm -rf output/freebsdtemp
|
||||
echo -e "\nFreeBSD packaging complete\n"
|
||||
} &&
|
||||
|
||||
if [ "$1" == "generic" ]; then # build scripts
|
||||
_create_generic
|
||||
elif [ "$1" == "pkgbuild" ]; then
|
||||
_create_generic
|
||||
_create_pkgbuild
|
||||
elif [ "$1" == "apkbuild" ]; then
|
||||
_create_generic
|
||||
_create_apkbuild
|
||||
elif [ "$1" == "haiku" ]; then # distribution packages
|
||||
_create_hpkg
|
||||
elif [ "$1" == "debian" ]; then
|
||||
_create_deb
|
||||
elif [ "$1" == "termux" ]; then
|
||||
_create_termux
|
||||
elif [ "$1" == "fedora" ]; then
|
||||
_create_generic
|
||||
_create_rpm
|
||||
elif [ "$1" == "freebsd" ]; then
|
||||
_create_freebsd_pkg
|
||||
elif [ "$1" == "buildable-arch" ]; then
|
||||
_create_generic
|
||||
_create_pkgbuild
|
||||
_create_apkbuild
|
||||
if [[ $(pacman -Q dpkg) == "dpkg"* ]]; then
|
||||
_create_deb
|
||||
_create_termux
|
||||
fi
|
||||
if [[ "$(pacman -Q freebsd-pkg)" == "freebsd-pkg"* ]]; then
|
||||
_create_freebsd_pkg
|
||||
fi
|
||||
else
|
||||
echo -e '\nusage: package.sh [target] <revision>\n\ntargets:\n mainline: pkgbuild apkbuild haiku fedora debian\n experimental: freebsd termux\n other: buildable-arch\n'
|
||||
fi
|
||||
+43
-35
@@ -1,49 +1,57 @@
|
||||
sshyp 2021.11.05.fr1
|
||||
sshyp v1.2.0
|
||||
|
||||
First public release of sshyp.
|
||||
the brisk bahh update
|
||||
|
||||
This release fixes major bugs from rpass and rebrands the project.
|
||||
this release focuses on speeding up the sshyp user experience by adding
|
||||
new features that reduce wasted time
|
||||
|
||||
New features:
|
||||
compatibility-breaking changes:
|
||||
|
||||
- an entirely new syncing back-end called sshync (custom Python wrapper around sftp)
|
||||
^ in thoery, all syncing-related data loss should now be fixed, however, this new
|
||||
system has just been created and is still under testing. Maybe wait for a few patches
|
||||
before trusting this system.
|
||||
- new configuration options (quick-unlock, offline mode) have been added and
|
||||
the configuration files have been reorganized
|
||||
^ simply running "sshyp tweak" and following the setup wizard will correct any compatibility
|
||||
issues
|
||||
- for quick-unlock security, device names have been replaced with more secure device ids
|
||||
^ older device names are still compatible, but for security reasons it is recommended
|
||||
to delete any pre-existing device names from the server and allow "sshyp tweak" to re-register
|
||||
your devices
|
||||
|
||||
Changes:
|
||||
user-facing features:
|
||||
|
||||
- branding has been updated to reflect new project name and goals
|
||||
- custom directories, custom ssh keys, and offline only mode are removed (may be temporary)
|
||||
^ the configuration wizard is being re-written in the next major update
|
||||
- quick-unlock mode has been added
|
||||
^ this allows you to use a shortened version of your password by verifying that your device
|
||||
is whitelisted on your sshyp server - it's both faster and more secure than standard unlock,
|
||||
but it requires an active connection to your sshyp server to authenticate (otherwise it will
|
||||
fall back to standard unlock)
|
||||
- full support for offline usage
|
||||
^ though sshyp could be used without a server before, it now can be configured to not attempt
|
||||
to find one ever - this saves time and hides sync failure error messages
|
||||
- bash completions have been added
|
||||
^ if you have bash-completion installed, you can now use the tab key in bash to auto-complete
|
||||
sshyp arguments and entry names (client only, not added for server-specific arguments)
|
||||
^ if you do not have bash-completion installed, you can source
|
||||
/usr/share/bash-completion/completions/sshyp (Linux/BSD) or
|
||||
/boot/system/data/bash-completion/completions/sshyp (Haiku) in your ~/.bashrc to
|
||||
use this feature
|
||||
|
||||
Planned for next update (The Fluffy Update):
|
||||
fixes/optimizations:
|
||||
|
||||
- modularized and optimized code
|
||||
^ some older, bad code from "rpass" will be re-written.
|
||||
- new visual features
|
||||
^ this includes the new file list and thematic text art. sshyp will be
|
||||
getting a retro computing theme.
|
||||
- packages for more environments
|
||||
^ "sshyp" will be officially packaged for Arch Linux, Alpine Linux, and Termux (Android).
|
||||
Debian/Ubuntu and Fedora packaging will come later.
|
||||
- fixed entries with multi-word titles failing to decrypt
|
||||
- password generation is now much faster and more resource efficient
|
||||
- there is no longer a length limit on generated passwords
|
||||
- improved visual consistency of help menus
|
||||
- rarely used modules are now imported only when needed
|
||||
- sshyp now uses one fewer configuration file
|
||||
|
||||
Planned for next update (The Sheep w/Shears Update):
|
||||
other notable changes:
|
||||
|
||||
- allow for copying entire notes (not just first line)
|
||||
- allow for multi-client deletion... somehow
|
||||
- ability to pass entries as arguments for more functions
|
||||
- detatch sshync and make it a separate package
|
||||
- manpage
|
||||
|
||||
Planned, no timeline:
|
||||
|
||||
- create separate gui frontend targetting mobile devices (Android + Linux phones)
|
||||
^ the gui will also function on desktop linux
|
||||
- package for more Linux distributions, such as Debian and Fedora)
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
- sshyp is now specifically licensed under the GPL-3.0-only (keyword: only)
|
||||
- sshyp now has some possible arguments and its own help menu when running in server mode
|
||||
- temporary files in /dev/shm are now generated with more complex names
|
||||
- sshyp now installs in /usr/lib/sshyp (Linux/BSD) or /system/lib/sshyp (Haiku) instead of
|
||||
/usr/bin or /bin (it is still symlinked to the old directories)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
The full history of changes to "sshyp" and "rpass" can be found on the following page:
|
||||
The full history of changes to "sshyp" can be found on the following page:
|
||||
https://raw.githubusercontent.com/rwinkhart/sshyp/main/extra/changelog-total
|
||||
|
||||
Executable → Regular
+5
-6
@@ -1,10 +1,9 @@
|
||||
sshyp is a FOSS password manager that takes advantage of rsync
|
||||
Copyright (C) 2021 Randall Winkhart idgr@tutanota.com
|
||||
sshyp is a FOSS password manager that uses an sftp-based syncing back-end.
|
||||
Copyright (C) 2022 Randall Winkhart idgr@tutanota.com
|
||||
|
||||
This program is free software: you can redistribute it and/or modify
|
||||
it under the terms of the GNU General Public License as published by
|
||||
the Free Software Foundation, either version 3 of the License, or
|
||||
(at your option) any later version.
|
||||
it under the terms of version 3 (only) of the GNU General Public License
|
||||
as published by the Free Software Foundation.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
@@ -12,4 +11,4 @@
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
Reference in New Issue
Block a user