mirror of
https://github.com/rwinkhart/sshyp.git
synced 2026-09-03 07:37:16 -04:00
Compare commits
415
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d9873df2d1 | ||
|
|
0c85703a73 | ||
|
|
41c9d0a22b | ||
|
|
aa65ecf8fb | ||
|
|
432a5f1e5a | ||
|
|
03c8bdbf74 | ||
|
|
1e0aa8aa39 | ||
|
|
924d066676 | ||
|
|
07cfc7ddaf | ||
|
|
6e0f19e8b8 | ||
|
|
d2ee90a52c | ||
|
|
3f4173b4fd | ||
|
|
fc94bfd774 | ||
|
|
0226180339 | ||
|
|
ed9c69248b | ||
|
|
902e041f51 | ||
|
|
648bed832f | ||
|
|
843dff6527 | ||
|
|
4f409f62d6 | ||
|
|
21550ddef2 | ||
|
|
c7dfb6a419 | ||
|
|
cc5d54914c | ||
|
|
b090c24d59 | ||
|
|
d1a994a103 | ||
|
|
6584686b2c | ||
|
|
0109816d3d | ||
|
|
30962b8cb2 | ||
|
|
fbf5ac02a4 | ||
|
|
6649fce7d1 | ||
|
|
6375a086cc | ||
|
|
43a53070a8 | ||
|
|
16f1225621 | ||
|
|
99cf9b7413 | ||
|
|
7d26170d7f | ||
|
|
6907c10f81 | ||
|
|
a5d36bf6b4 | ||
|
|
24ae771b85 | ||
|
|
0429070b5d | ||
|
|
6aa9a663b5 | ||
|
|
2c17a6b711 | ||
|
|
b649ae2c16 | ||
|
|
a0b533d9dd | ||
|
|
4c78ffb0de | ||
|
|
a2f2525df1 | ||
|
|
eefedde98c | ||
|
|
12cbcdd9af | ||
|
|
5219bf0448 | ||
|
|
a91c48533c | ||
|
|
e22066f015 | ||
|
|
d1cc6fe3e6 | ||
|
|
f9ad813ce6 | ||
|
|
bee3149c74 | ||
|
|
ccee566a22 | ||
|
|
e511159a6c | ||
|
|
f5bbe9516c | ||
|
|
6bbb84e1c0 | ||
|
|
39dbc1c83d | ||
|
|
1d969cc1f1 | ||
|
|
c5dd735f7a | ||
|
|
bf8adfc1c1 | ||
|
|
764d165ad4 | ||
|
|
9928a43d6a | ||
|
|
25121f3a5c | ||
|
|
2c78a1456c | ||
|
|
6173a11710 | ||
|
|
52e41dfab8 | ||
|
|
8b0f25479d | ||
|
|
0a210d0395 | ||
|
|
d29bee2d45 | ||
|
|
052a489bec | ||
|
|
b458265fd1 | ||
|
|
c916a738a2 | ||
|
|
9c5b007946 | ||
|
|
ff1c984024 | ||
|
|
164c719b90 | ||
|
|
d49ce1bb87 | ||
|
|
800a1181f8 | ||
|
|
d9414dbcdf | ||
|
|
0869b83505 | ||
|
|
7dfa12012a | ||
|
|
921630f5a8 | ||
|
|
627c6a1a14 | ||
|
|
a9f4435493 | ||
|
|
7d639ecca9 | ||
|
|
eefe5e39b5 | ||
|
|
c28b836c2a | ||
|
|
b53370a3e2 | ||
|
|
9776961f2a | ||
|
|
1a35aaf33b | ||
|
|
66b15ac22c | ||
|
|
56db2e65f8 | ||
|
|
1be67d404b | ||
|
|
a279819260 | ||
|
|
578f7dee14 | ||
|
|
5bec4fdaa9 | ||
|
|
5f903966da | ||
|
|
cfd551ef7c | ||
|
|
4d22b5b5a8 | ||
|
|
46d5f8d515 | ||
|
|
02ee2a5c0e | ||
|
|
fb1c3844a8 | ||
|
|
213ca41582 | ||
|
|
b8dc5c4f89 | ||
|
|
574637392a | ||
|
|
c6f31da6d4 | ||
|
|
0f4c57bec3 | ||
|
|
51b1b8c6ec | ||
|
|
5f0a40efc0 | ||
|
|
05c034652f | ||
|
|
1d185b1723 | ||
|
|
bca2af0ed8 | ||
|
|
d301cf6298 | ||
|
|
89c9a03cc1 | ||
|
|
3392e3ceea | ||
|
|
176ee623cf | ||
|
|
42abb7b674 | ||
|
|
3a6655e977 | ||
|
|
9d1f0a065b | ||
|
|
8298966d8f | ||
|
|
d4d9fb88fd | ||
|
|
2beeb1dc38 | ||
|
|
86ad4e5cad | ||
|
|
e55c812a06 | ||
|
|
a0351d19d3 | ||
|
|
90c15bcda8 | ||
|
|
cb754c5ba7 | ||
|
|
9979de26d0 | ||
|
|
4207ecb555 | ||
|
|
8bcfd3fcd8 | ||
|
|
78588f686e | ||
|
|
4753bb4c37 | ||
|
|
81ccdf71ea | ||
|
|
67eb1a44ca | ||
|
|
8af7de10a7 | ||
|
|
3108a072dd | ||
|
|
65be0eaf6f | ||
|
|
bb34025c31 | ||
|
|
278231fe40 | ||
|
|
7356777e50 | ||
|
|
5a33eb26f0 | ||
|
|
d796c48ede | ||
|
|
b1fd934b96 | ||
|
|
9848d38a0b | ||
|
|
2ab409e95e | ||
|
|
64d46f1746 | ||
|
|
e9c787cfe3 | ||
|
|
c200b5bbec | ||
|
|
b6593e609b | ||
|
|
32b0c39fb6 | ||
|
|
6b8e24b0b2 | ||
|
|
2d47f42414 | ||
|
|
a773056202 | ||
|
|
097aca8c43 | ||
|
|
275b07e53f | ||
|
|
46d539f386 | ||
|
|
0adf00d81e | ||
|
|
46b212988f | ||
|
|
3e8772786a | ||
|
|
3a01157cb3 | ||
|
|
079a1412ae | ||
|
|
359edcd46c | ||
|
|
60c2920f3c | ||
|
|
a3cd6a1f17 | ||
|
|
8c2b7df1da | ||
|
|
994eaee49b | ||
|
|
8f0eb1134a | ||
|
|
c95643ca89 | ||
|
|
35ea8bf7d7 | ||
|
|
60431b623c | ||
|
|
185ae4ebff | ||
|
|
1e290a1f26 | ||
|
|
71157633df | ||
|
|
03487348ea | ||
|
|
2d20ddbb97 | ||
|
|
21287ca57f | ||
|
|
612f288904 | ||
|
|
0fbe084ff7 | ||
|
|
fdf90e043a | ||
|
|
b89158d0bb | ||
|
|
dede7cf8ac | ||
|
|
6d3ba2714b | ||
|
|
09991a2a30 | ||
|
|
c5884024de | ||
|
|
1e2166ddaf | ||
|
|
86487b8ae5 | ||
|
|
fa05312d49 | ||
|
|
71d942ffae | ||
|
|
cc1a099363 | ||
|
|
d6342faf84 | ||
|
|
c7cae5303a | ||
|
|
1d80cb08ce | ||
|
|
8163aee868 | ||
|
|
7c061f561f | ||
|
|
339d20bc3e | ||
|
|
434f5f85cd | ||
|
|
22d9605781 | ||
|
|
d644f8df01 | ||
|
|
551789636d | ||
|
|
9ab175a8d8 | ||
|
|
e5a4d80e3b | ||
|
|
0920dcf004 | ||
|
|
e18b3b4d0a | ||
|
|
ffccc88a1d | ||
|
|
e1ec834e5c | ||
|
|
018d0c511d | ||
|
|
55b94fc4cc | ||
|
|
3f9c4e2c8d | ||
|
|
166ac50f42 | ||
|
|
df1c6482a8 | ||
|
|
38c6ef3d1b | ||
|
|
7bea6093b8 | ||
|
|
f9ca6f8e94 | ||
|
|
75d8eb7b7d | ||
|
|
39316d04a2 | ||
|
|
3e9a4c0403 | ||
|
|
3bc07b48ef | ||
|
|
5234e8c048 | ||
|
|
b7c3535955 | ||
|
|
1f52c45c43 | ||
|
|
7723baa69e | ||
|
|
b680cc96d6 | ||
|
|
f750fe1e4d | ||
|
|
b96db3ad92 | ||
|
|
224fc1fc6d | ||
|
|
0bd2e45dba | ||
|
|
6410843911 | ||
|
|
3dda6d8428 | ||
|
|
4f31af5eff | ||
|
|
bfb830c5e5 | ||
|
|
790121e7ea | ||
|
|
4168b800f8 | ||
|
|
801d515697 | ||
|
|
379970d53b | ||
|
|
4abb3ed718 | ||
|
|
6690fd15c9 | ||
|
|
1582e73a98 | ||
|
|
dfe1703e62 | ||
|
|
7a76130b26 | ||
|
|
98dcbf57c6 | ||
|
|
a5946d558a | ||
|
|
30fb5ed041 | ||
|
|
fb1f5b92c3 | ||
|
|
61b2186b0a | ||
|
|
2113b93481 | ||
|
|
2030d90114 | ||
|
|
75071601e6 | ||
|
|
9a0a261d55 | ||
|
|
4ca2d89464 | ||
|
|
f90ec5c900 | ||
|
|
fa0a4fe0b8 | ||
|
|
c85a9d2ccd | ||
|
|
43351fd66f | ||
|
|
096bdb0773 | ||
|
|
330396c5f1 | ||
|
|
8576f63479 | ||
|
|
393f241538 | ||
|
|
c557d5bfee | ||
|
|
acca7d888c | ||
|
|
2f3b3c67ba | ||
|
|
88d2402e88 | ||
|
|
928aacc64a | ||
|
|
094bdcb418 | ||
|
|
419ff51e75 | ||
|
|
2111a0454e | ||
|
|
5d902f0324 | ||
|
|
505ffdb489 | ||
|
|
5cab1ad091 | ||
|
|
2e2404636b | ||
|
|
6cb5bd405f | ||
|
|
c93965c9a5 | ||
|
|
d685e07d32 | ||
|
|
192f58fef5 | ||
|
|
106f22f757 | ||
|
|
ae414dadda | ||
|
|
c9e99732a2 | ||
|
|
fc37368447 | ||
|
|
ca2bc98735 | ||
|
|
f44391612d | ||
|
|
8c0e9eb6df | ||
|
|
c03e818560 | ||
|
|
0b653000ef | ||
|
|
9f89dce42b | ||
|
|
e7b2e19039 | ||
|
|
80b6b4abd2 | ||
|
|
758e9f331c | ||
|
|
ba14c0e74b | ||
|
|
1991672618 | ||
|
|
9b600dabbf | ||
|
|
e42641079d | ||
|
|
7c6cbaec35 | ||
|
|
cb441933db | ||
|
|
dad1a34575 | ||
|
|
3a30812de5 | ||
|
|
e1930f9457 | ||
|
|
05df3dd903 | ||
|
|
5c1195f42d | ||
|
|
30aa3e2438 | ||
|
|
a8ea1eb444 | ||
|
|
8e053f25b8 | ||
|
|
a175a270e0 | ||
|
|
d116582144 | ||
|
|
f760b5420c | ||
|
|
6498a076f2 | ||
|
|
f4a0c52ca8 | ||
|
|
ffafbd2b91 | ||
|
|
d7bf7da177 | ||
|
|
13d466bb21 | ||
|
|
7aa9ea63e2 | ||
|
|
208bd8707b | ||
|
|
fb398333a6 | ||
|
|
b369f9a530 | ||
|
|
747f83819d | ||
|
|
2f1e693991 | ||
|
|
dd811cbe35 | ||
|
|
87dee4f197 | ||
|
|
bf86d72472 | ||
|
|
a3722e3c29 | ||
|
|
1f4d5b0591 | ||
|
|
e21faa8bbb | ||
|
|
309a471e77 | ||
|
|
968a7322f8 | ||
|
|
75e152ebfe | ||
|
|
15204fb0e9 | ||
|
|
5977367f28 | ||
|
|
96eb80226f | ||
|
|
9ede33d3d8 | ||
|
|
4093c36d48 | ||
|
|
947754f87c | ||
|
|
84bfefb7b1 | ||
|
|
7ac5cd723e | ||
|
|
68aa5eee04 | ||
|
|
f869e3b45d | ||
|
|
551f1e8f50 | ||
|
|
1687d9e1e2 | ||
|
|
930595ecad | ||
|
|
2d00da0e18 | ||
|
|
c84d52fb8d | ||
|
|
88fd9e77a9 | ||
|
|
4258ad85ab | ||
|
|
337e68d088 | ||
|
|
fb8c5be284 | ||
|
|
0293d273a7 | ||
|
|
40a43ed86d | ||
|
|
18c78743ca | ||
|
|
2f5080fec0 | ||
|
|
99e0d5f666 | ||
|
|
be19e271c5 | ||
|
|
20d2de338f | ||
|
|
e830d8486b | ||
|
|
5fc74ac2b3 | ||
|
|
24acd1cb87 | ||
|
|
0079934354 | ||
|
|
399e291902 | ||
|
|
66a026e327 | ||
|
|
b5f4e776e5 | ||
|
|
0056f60af1 | ||
|
|
41aa093685 | ||
|
|
30034be36f | ||
|
|
a43530d34f | ||
|
|
7d14c49490 | ||
|
|
462ba05833 | ||
|
|
e89bf06d9a | ||
|
|
d33d07894f | ||
|
|
cade83a0f0 | ||
|
|
100edd07ea | ||
|
|
d19651819a | ||
|
|
d951284bcd | ||
|
|
3c9b80ec80 | ||
|
|
0f3d9854b7 | ||
|
|
0c52149c40 | ||
|
|
f838af0b4e | ||
|
|
72f126d21d | ||
|
|
2385f669f8 | ||
|
|
b8896a6b58 | ||
|
|
51ec2143e3 | ||
|
|
4c1989287a | ||
|
|
daba737ca6 | ||
|
|
8cac27c6f6 | ||
|
|
19d37dfdb6 | ||
|
|
87a56a80bd | ||
|
|
5aaa284cbf | ||
|
|
a6aa0561b4 | ||
|
|
b08456e873 | ||
|
|
ef828b88a0 | ||
|
|
bde243c644 | ||
|
|
894f406fd2 | ||
|
|
00b935f1bb | ||
|
|
49608cb839 | ||
|
|
a417478aa0 | ||
|
|
344c74b728 | ||
|
|
fc0e4bb4a5 | ||
|
|
37867cb673 | ||
|
|
86aa7da038 | ||
|
|
9231257af8 | ||
|
|
102f22143f | ||
|
|
3dd12b4d6d | ||
|
|
a0b5dad073 | ||
|
|
2ba19f9a39 | ||
|
|
8af71ceb1a | ||
|
|
81c9b35c75 | ||
|
|
eeabc18f18 | ||
|
|
73128665fb | ||
|
|
607a4709f6 | ||
|
|
c643e861d9 | ||
|
|
23e7e375ae | ||
|
|
b8743d5fe2 | ||
|
|
e95aa85453 | ||
|
|
caf130568e | ||
|
|
f65adc17f3 | ||
|
|
fc2f42a1aa | ||
|
|
8403f4af98 | ||
|
|
4b24df0e97 | ||
|
|
ca007f55ac | ||
|
|
7afcfdb43d | ||
|
|
5178377827 |
@@ -0,0 +1,72 @@
|
||||
# For most projects, this workflow file will not need changing; you simply need
|
||||
# to commit it to your repository.
|
||||
#
|
||||
# You may wish to alter this file to override the set of languages analyzed,
|
||||
# or to provide custom queries or build logic.
|
||||
#
|
||||
# ******** NOTE ********
|
||||
# We have attempted to detect the languages in your repository. Please check
|
||||
# the `language` matrix defined below to confirm you have the correct set of
|
||||
# supported CodeQL languages.
|
||||
#
|
||||
name: "CodeQL"
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ "main" ]
|
||||
pull_request:
|
||||
# The branches below must be a subset of the branches above
|
||||
branches: [ "main" ]
|
||||
schedule:
|
||||
- cron: '34 22 * * 5'
|
||||
|
||||
jobs:
|
||||
analyze:
|
||||
name: Analyze
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
security-events: write
|
||||
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
language: [ 'python' ]
|
||||
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
|
||||
# Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v3
|
||||
|
||||
# Initializes the CodeQL tools for scanning.
|
||||
- name: Initialize CodeQL
|
||||
uses: github/codeql-action/init@v2
|
||||
with:
|
||||
languages: ${{ matrix.language }}
|
||||
# If you wish to specify custom queries, you can do so here or in a config file.
|
||||
# By default, queries listed here will override any specified in a config file.
|
||||
# Prefix the list here with "+" to use these queries and those in the config file.
|
||||
|
||||
# Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
|
||||
# queries: security-extended,security-and-quality
|
||||
|
||||
|
||||
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
|
||||
# If this step fails, then you should remove it and run the build manually (see below)
|
||||
- name: Autobuild
|
||||
uses: github/codeql-action/autobuild@v2
|
||||
|
||||
# ℹ️ Command-line programs to run using the OS shell.
|
||||
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
|
||||
|
||||
# If the Autobuild fails above, remove it and uncomment the following three lines.
|
||||
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.
|
||||
|
||||
# - run: |
|
||||
# echo "Run, Build Application using script"
|
||||
# ./location_of_script_within_repo/buildscript.sh
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@v2
|
||||
@@ -1,8 +1,20 @@
|
||||
# sshyp
|
||||
A very simple self-hosted, synchronized password manager. Alternative to GNU pass.
|
||||

|
||||
|
||||
"sshyp" stands for "sshync passwords", or "ssh sync passwords".
|
||||
"sshync" is the custom syncing backend (based on sftp) used by "sshyp".
|
||||
[](https://github.com/rwinkhart/sshyp/releases)
|
||||

|
||||
[](https://github.com/rwinkhart/sshyp/releases)
|
||||
|
||||
[](https://github.com/rwinkhart/sshyp/actions/workflows/codeql-analysis.yml)
|
||||
|
||||
pronounced as: 'sheep', 'shēp'
|
||||
|
||||
sshyp is a very simple self-hosted, synchronized password manager for UNIX(-like) systems (currently Haiku/FreeBSD/Linux).
|
||||
|
||||
sshyp is compatible with entries created by pass/password-store, as its original goal was to be like pass/password-store, but far more user-friendly to synchronize with a self-hosted server.
|
||||
|
||||
sshyp makes use of a custom sftp wrapper, called sshync (ssh+sync), to reliably sync user entries with a local or remote server.
|
||||
|
||||
The name "sshyp" is a combination of its syncing library, "sshync", and "passwords".
|
||||
|
||||
# WARNING
|
||||
It is your responsibility to assess the security and stability of "sshyp" before using it and ensure it meets your needs.
|
||||
@@ -16,50 +28,38 @@ What sshyp can do:
|
||||
|
||||
- securely manage a collection of encrypted passwords and notes via CLI
|
||||
- generate new, secure passwords to the user's choice in length and complexity
|
||||
- securely sync said passwords and notes seamlessly between multiple POSIX compliant Unix devices
|
||||
|
||||
What sshyp will do:
|
||||
|
||||
- everything it already does, but also in a GUI for Linux/Android
|
||||
- have a distinct retro theme
|
||||
- receive many usability enhancements
|
||||
|
||||
What sshyp definitely won't do:
|
||||
|
||||
- 2FA/MFA (for security purposes, this should not be handled by your password manager)
|
||||
- Windows support (I don't use Windows and I have no interest in developing for it)
|
||||
- securely sync said passwords and notes seamlessly between devices (or just manage them offline)
|
||||
- utilize [extensions](https://github.com/rwinkhart/sshyp-labs) to interact with your entries is additional ways (such as generating TOTP keys or managing your entries in a GUI)
|
||||
- everything above with entries created by pass/password-store!
|
||||
- everything above on Haiku, FreeBSD, Linux, and Termux!
|
||||
|
||||
# Installation
|
||||
Arch Linux (all ISAs)
|
||||
**Important:** *Shell completions (both Bash and ZSH) may require additional configuration on some distributions - please see [this page](https://github.com/rwinkhart/sshyp/wiki/Completions) of the wiki for support.*
|
||||
|
||||
sshyp releases are available in the Arch User Repository as 'sshyp'.
|
||||
Please see the [installation guide](https://github.com/rwinkhart/sshyp/wiki/Installation) in the sshyp wiki for directions specific to your distribution/OS.
|
||||
|
||||
Install with your preferred AUR helper or use:
|
||||
Pre-built packages exist for Haiku, FreeBSD, Alpine Linux, Arch Linux, Debian/Ubuntu Linux, Fedora Linux, and Termux. These can be downloaded from the releases page.
|
||||
|
||||
```
|
||||
git clone https://aur.archlinux.org/sshyp.git
|
||||
cd sshyp
|
||||
makepkg -si
|
||||
```
|
||||
Support for additional environments, such as MacOS and OpenBSD, is coming soon.
|
||||
|
||||
Pre-built packages exist for Arch, Debian, and Termux. These can be downloaded from the releases page.
|
||||
Extensions are available in the [sshyp-labs](https://github.com/rwinkhart/sshyp-labs) repository.
|
||||
|
||||
# Building
|
||||
Since sshyp is written entirely in Python, it doesn't need to be compiled. It does, however, need to be packaged for installation.
|
||||
|
||||
A packaging script is included in the root directory of the repo in order to package sshyp for your distribution. To package sshyp from source, simply run:
|
||||
|
||||
```
|
||||
git clone https://github.com/rwinkhart/sshyp.git
|
||||
cd sshyp
|
||||
./package.sh
|
||||
./package.sh [target] <revision>
|
||||
```
|
||||
|
||||
The packaging script has been tested on Arch Linux with dpkg as a dependency for Debian and Termux packaging.
|
||||
The packaging script has been tested on Arch Linux with "dpkg" as a dependency for Debian/Ubuntu/Termux packaging and "freebsd-pkg" as a dependency for FreeBSD packaging.
|
||||
|
||||
The AUR version and the packages attatched to the release tags were already packaged using this script.
|
||||
Haiku and Fedora packaging must be done on their own respective distributions.
|
||||
|
||||
Currently, the script can create packages for Arch (PKGBUILD), Debian, Termux, and generic. Packaging for other distributions coming soon.
|
||||
The AUR version and the packages attached to the release tags were already packaged using this script.
|
||||
|
||||
Currently, the script can create packages for Haiku, FreeBSD, Alpine Linux (APKBUILD), Arch Linux (PKGBUILD), Debian/Ubuntu Linux, Fedora Linux, Termux, and generic.
|
||||
|
||||
# Usage
|
||||
Upon initial installation (on both the server and client devices), be sure to run:
|
||||
@@ -68,18 +68,17 @@ Upon initial installation (on both the server and client devices), be sure to ru
|
||||
sshyp tweak
|
||||
```
|
||||
|
||||
This command will allow you to configure the settings necessary for sshyp to function.
|
||||
As of right now, sshyp is rapidly changing, and as such, it is a good idea to run "sshyp tweak" after each update.
|
||||
This command will allow you to configure the settings necessary for sshyp to function. To ensure configuration compatibility, it is a good idea to run 'sshyp tweak' after each major update.
|
||||
|
||||
Please note that decrypting and reading entries is disabled on server devices for security reasons. Only devices configured as clients can use the gpg key to decrypt entries.
|
||||
Please note that decrypting and reading entries is disabled on server devices for security reasons. Only devices configured as clients can use the GPG key to decrypt entries.
|
||||
|
||||
All available options can be found with:
|
||||
|
||||
```
|
||||
sshyp --help
|
||||
sshyp help
|
||||
```
|
||||
|
||||
Or alternatively, in the new manpage:
|
||||
Or alternatively, in the man page:
|
||||
|
||||
```
|
||||
man sshyp
|
||||
@@ -88,22 +87,11 @@ man sshyp
|
||||
# Roadmap
|
||||
Short-term Goals:
|
||||
|
||||
- create new file list w/color and w/o file extensions
|
||||
- overhaul argument system
|
||||
- fix lots of bugs!
|
||||
- make lots of optimizations!
|
||||
|
||||
Medium-term Goals:
|
||||
|
||||
- create minimal GUI apps (Linux x86_64, Linux aarch64)
|
||||
- auto-completion on tab for CLI version
|
||||
- MacOS support
|
||||
- improved temporary directory security
|
||||
- a minimal GUI app - being made as an [extension](https://github.com/rwinkhart/sshyp-labs)
|
||||
|
||||
Long-term Goals:
|
||||
|
||||
- a fun surprise
|
||||
- seize the thrones, shear the humans
|
||||
|
||||
# Known Issues
|
||||
|
||||
Currently, files deleted from a client or server may re-appear if another client that had the same file reconnects and later re-uploads it to the server. This will be addressed.
|
||||
|
||||
Currently, if a client is missing folders that exist on the server, the contents of the missing folders will fail to download. A temporary workaround is to manually create the folders on the client. This will be addressed.
|
||||
|
||||
-105
@@ -1,105 +0,0 @@
|
||||
#!/usr/bin/python3
|
||||
|
||||
# sshync 2022.01.17.unreleased13
|
||||
|
||||
# external modules
|
||||
|
||||
from os import path, system, walk
|
||||
from os.path import getmtime, join, expanduser
|
||||
from sys import exit as s_exit
|
||||
from pathlib import Path
|
||||
|
||||
|
||||
# utility functions
|
||||
|
||||
def get_titles_mods(_directory, _destination, _user_data):
|
||||
_title_list, _mod_list = [], []
|
||||
Path(path.expanduser('~/.config/sshync')).mkdir(0o700, parents=True, exist_ok=True) # create config directory
|
||||
# local fetching
|
||||
if _destination == 'l':
|
||||
open(expanduser('~/.config/sshync/database'), 'w').write('') # blanks out database file
|
||||
for _root, _directories, _files in walk(_directory):
|
||||
for _filename in _files:
|
||||
_title_list.append(join(_root.replace(_directory, '', 1), _filename))
|
||||
_mod_list.append(int(getmtime(join(_root, _filename))))
|
||||
for _title in _title_list:
|
||||
open(expanduser('~/.config/sshync/database'), 'a').write(str(_title) + '\n')
|
||||
open(expanduser('~/.config/sshync/database'), 'a').write('^&*\n')
|
||||
for _mod in _mod_list:
|
||||
open(expanduser('~/.config/sshync/database'), 'a').write(str(_mod) + '\n')
|
||||
# remote fetching
|
||||
if _destination == 'r':
|
||||
system(f"ssh -i '{_user_data[5]}' -p {_user_data[2]} {_user_data[0]}@{_user_data[1]} \"python -c 'import sshync"
|
||||
f"; sshync.get_titles_mods(\"'\"{_user_data[4]}\"'\", \"'\"l\"'\", \"'\"{_user_data}\"'\")'\"")
|
||||
system(f"sftp -i '{_user_data[5]}' -P {_user_data[2]} {_user_data[0]}@{_user_data[1]}:"
|
||||
f"'{expanduser(f'/home/{_user_data[0]}/.config/sshync/database')}' '{expanduser('~/.config/sshync/')}'")
|
||||
_titles, _sep, _mods = ' '.join(open(expanduser('~/.config/sshync/database')).readlines()).replace('\n', '')\
|
||||
.partition('^&*')
|
||||
_title_list, _mod_list = _titles.split(' ')[:-1], _mods.split(' ')[1:]
|
||||
return _title_list, _mod_list
|
||||
|
||||
|
||||
def sort_titles_mods(_list_1, _list_2):
|
||||
_title_list_2_sorted, _mod_list_2_sorted = [], []
|
||||
# title sorting
|
||||
for _title in _list_1[0]:
|
||||
if _title in _list_2[0]:
|
||||
_title_list_2_sorted.append(_title)
|
||||
for _title in _list_2[0]:
|
||||
if _title not in _title_list_2_sorted:
|
||||
_title_list_2_sorted.append(_title)
|
||||
# mod time sorting
|
||||
for _title in _title_list_2_sorted:
|
||||
_mod_list_2_sorted.append(_list_2[1][_list_2[0].index(_title)])
|
||||
return _title_list_2_sorted, _mod_list_2_sorted
|
||||
|
||||
|
||||
def make_profile(_profile_dir, _local_dir, _remote_dir, _identity, _ip, _port, _user):
|
||||
open(_profile_dir, 'w').write(_user + '\n' + _ip + '\n' + _port + '\n' + _local_dir + '\n' + _remote_dir + '\n' +
|
||||
_identity + '\n')
|
||||
|
||||
|
||||
def get_profile(_profile_dir):
|
||||
try:
|
||||
_profile_data = open(_profile_dir).readlines()
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\nEither the profile does not exist, or it is corrupted.\n')
|
||||
_profile_data = None
|
||||
s_exit()
|
||||
# extract data from profile
|
||||
_user = _profile_data[0].replace('\n', '')
|
||||
_ip = _profile_data[1].replace('\n', '')
|
||||
_port = _profile_data[2].replace('\n', '')
|
||||
_local_dir = _profile_data[3].replace('\n', '')
|
||||
_remote_dir = _profile_data[4].replace('\n', '')
|
||||
_identity = _profile_data[5].replace('\n', '')
|
||||
return _user, _ip, _port, _local_dir, _remote_dir, _identity
|
||||
|
||||
|
||||
def run_profile(_profile_dir):
|
||||
_user_data = get_profile(_profile_dir)
|
||||
_remote_titles_mods_saver = get_titles_mods(_user_data[4], 'r', _user_data) # saved to prevent re-walking directory
|
||||
_index_l = sort_titles_mods(_remote_titles_mods_saver, get_titles_mods(_user_data[3], 'l', _user_data))
|
||||
_index_r = sort_titles_mods(_index_l, _remote_titles_mods_saver)
|
||||
_i = -1
|
||||
for _title in _index_l[0]:
|
||||
_i += 1
|
||||
if _title in _index_r[0]:
|
||||
# compare mod times and sync
|
||||
if int(_index_l[1][_i]) > int(_index_r[1][_i]):
|
||||
print(f"[{_title}] Local is newer, uploading...")
|
||||
system(f"sftp -p -q -i '{_user_data[5]}' -P {_user_data[2]} {_user_data[0]}@{_user_data[1]}:"
|
||||
f"{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'} <<< $'put {_user_data[3]}{_title}'")
|
||||
elif int(_index_l[1][_i]) < int(_index_r[1][_i]):
|
||||
print(f"[{_title}] Remote is newer, downloading...")
|
||||
system(f"sftp -p -q -i '{_user_data[5]}' -P {_user_data[2]} {_user_data[0]}@{_user_data[1]}:"
|
||||
f"'{_user_data[4]}'{_title} {_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}")
|
||||
else:
|
||||
print(f"[{_title}] Not on remote server, uploading...")
|
||||
system(f"sftp -p -q -i '{_user_data[5]}' -P {_user_data[2]} {_user_data[0]}@{_user_data[1]}:{_user_data[4]}"
|
||||
f"{'/'.join(_title.split('/')[:-1]) + '/'} <<< $'put {_user_data[3]}{_title}'")
|
||||
for _title in _index_r[0]:
|
||||
if _title not in _index_l[0]:
|
||||
print(f"[{_title}] Not in local directory, downloading...")
|
||||
system(f"sftp -p -q -i '{_user_data[5]}' -P {_user_data[2]} {_user_data[0]}@{_user_data[1]}:"
|
||||
f"'{_user_data[4]}{_title}' {_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}")
|
||||
@@ -1,534 +0,0 @@
|
||||
#!/usr/bin/python3
|
||||
|
||||
# external modules
|
||||
|
||||
from os import environ, listdir, path, remove, system
|
||||
from shutil import copy, move, rmtree
|
||||
from sys import argv, exit as s_exit
|
||||
from pathlib import Path
|
||||
import random
|
||||
import sshync
|
||||
import string
|
||||
|
||||
|
||||
# utility functions
|
||||
|
||||
def replace_line(file_name, line_num, text): # replaces text in a given line with different text
|
||||
_lines = open(file_name, 'r').readlines()
|
||||
_lines[line_num] = text
|
||||
open(file_name, 'w').writelines(_lines)
|
||||
|
||||
|
||||
def shm_gen(): # generates a random temporary folder for security and returns random names for the folder and temp file
|
||||
_shm_folder_gen = ''.join(random.SystemRandom().choice(string.ascii_letters + string.digits)
|
||||
for _ in range(random.randint(10, 30)))
|
||||
_shm_entry_gen = ''.join(random.SystemRandom().choice(string.ascii_letters + string.digits)
|
||||
for _ in range(random.randint(10, 30)))
|
||||
Path(tmp_dir + _shm_folder_gen).mkdir(0o700)
|
||||
return _shm_folder_gen, _shm_entry_gen
|
||||
|
||||
|
||||
def encrypt(_shm_folder, _shm_entry, _location):
|
||||
system(f"gpg -r {str(gpg_id)} -e '{tmp_dir}{_shm_folder}/{_shm_entry}'")
|
||||
move(f"{tmp_dir}{_shm_folder}/{_shm_entry}.gpg", f"{directory}{_location}.gpg")
|
||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def edit_note(_shm_folder, _shm_entry):
|
||||
lines = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}").readlines()
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(lines[0:3])
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'w').writelines(lines[4:-2])
|
||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
||||
edit_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n").read()
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'a').write('\n' + edit_notes + '\n\n')
|
||||
|
||||
|
||||
# argument-specific functions
|
||||
|
||||
|
||||
def tweak(): # runs configuration wizard
|
||||
# storage/config directory creation
|
||||
Path(path.expanduser('~/.password-pasture')).mkdir(0o700, parents=True, exist_ok=True)
|
||||
Path(path.expanduser('~/.config/sshyp/devices')).mkdir(0o700, parents=True, exist_ok=True)
|
||||
if not Path(f"{path.expanduser('~/.config/sshyp/tmp')}").exists():
|
||||
if Path("/data/data/com.termux").exists():
|
||||
system(f"ln -s '/data/data/com.termux/files/usr/tmp' {path.expanduser('~/.config/sshyp/tmp')}")
|
||||
else:
|
||||
system(f"ln -s /dev/shm {path.expanduser('~/.config/sshyp/tmp')}")
|
||||
# device type configuration
|
||||
_device_type = input('\nIs this installation for a client or for a server? (C/s) ')
|
||||
if _device_type.lower() == 's':
|
||||
open(path.expanduser('~/.config/sshyp/sshyp-device'), 'w').write(_device_type)
|
||||
Path(path.expanduser('~/.config/sshyp/deleted')).mkdir(0o700, parents=True, exist_ok=True)
|
||||
copy('/usr/bin/sshync.py', path.expanduser('~/'))
|
||||
copy('/usr/bin/sshyp-shear.py', path.expanduser('~/shear.py'))
|
||||
print('\nMake sure the ssh service is running and properly configured.\n\nConfiguration complete!\n')
|
||||
s_exit()
|
||||
else:
|
||||
# device type configuration
|
||||
_device_type = 'c' # ensure device type flag is properly set
|
||||
open(path.expanduser('~/.config/sshyp/sshyp-device'), 'w').write(_device_type)
|
||||
|
||||
# gpg configuration
|
||||
_gpg_id = input('\nsshyp requires the use of a unique gpg key. Do you already have one that you are '
|
||||
'willing to use? (y/N)')
|
||||
if _gpg_id.lower() != 'y':
|
||||
print('\nA unique gpg key has been generated for you.')
|
||||
system('gpg --full-generate-key')
|
||||
_gpg_id = str(input('\nPlease input the ID of your gpg key: '))
|
||||
open(path.expanduser('~/.config/sshyp/sshyp-gpg'), 'w').write(_gpg_id + '\n')
|
||||
|
||||
# lock file generation
|
||||
open(path.expanduser('~/.config/sshyp/lock'), 'w')
|
||||
system(f"gpg -r {str(_gpg_id)} -e {path.expanduser('~/.config/sshyp/lock')}")
|
||||
remove(f"{path.expanduser('~/.config/sshyp')}/lock")
|
||||
|
||||
# ssh key configuration
|
||||
_ssh_gen = (input('\nMake sure the ssh service on the remote server is running and properly configured.'
|
||||
'\n\nSync support requires a unique ssh key. Would you like to have this automatically '
|
||||
'generated? (Y/n) '))
|
||||
if _ssh_gen.lower() != 'n':
|
||||
system('ssh-keygen -t ed25519 -f ~/.ssh/sshyp')
|
||||
else:
|
||||
print(f"\nEnsure that the key file you are using is located at {path.expanduser('~/.ssh/sshyp')}")
|
||||
|
||||
# ssh ip+port configuration
|
||||
print('\nExample input: 10.10.10.10:9999\n')
|
||||
_ip_port = str(input('What is the IP and ssh port of the remote server? '))
|
||||
_ip, _sep, _port = _ip_port.partition(':')
|
||||
|
||||
# ssh user configuration
|
||||
_username_ssh = str(input('\nWhat is the username of the remote server? '))
|
||||
print(f"\nEntry directory: /home/{_username_ssh}/.password-pasture/")
|
||||
|
||||
# sshync profile generation
|
||||
sshync.make_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'),
|
||||
path.expanduser('~/.password-pasture/'), f"/home/{_username_ssh}/.password-pasture/",
|
||||
path.expanduser('~/.ssh/sshyp'), _ip, _port, _username_ssh)
|
||||
|
||||
# device name configuration
|
||||
print('\nIMPORTANT: This name MUST be unique amongst your client devices. '
|
||||
'\nThis is used to keep track of which devices have up-to-date databases.\n')
|
||||
_client_device_name = str(input('What would you like to name this device? '))
|
||||
open(f"{path.expanduser('~/.config/sshyp/devices/')}{_client_device_name}", 'w')
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {_port} {_username_ssh}@{_ip} "
|
||||
f"\"touch '/home/{_username_ssh}/.config/sshyp/devices/{_client_device_name}'\"")
|
||||
|
||||
print('\nConfiguration complete!\n')
|
||||
|
||||
|
||||
def print_info(): # prints help text based on argument
|
||||
if argument == 'help' or argument == '--help' or argument == '-h':
|
||||
print('\nsshyp Copyright (C) 2021 Randall Winkhart')
|
||||
print("This is free software, and you are welcome to redistribute it under certain conditions;\nthis program "
|
||||
"comes with ABSOLUTELY NO WARRANTY;\ntype `sshyp license' for details.")
|
||||
print('\nUSAGE: sshyp [/<entry name>] [OPTION] [FLAG]\n')
|
||||
print('Options: ')
|
||||
print('help/--help/-h bring up this menu')
|
||||
print('version/-v display sshyp version info')
|
||||
print('tweak configure sshyp')
|
||||
print('add add an entry')
|
||||
print('gen generate a new password')
|
||||
print('edit edit an existing entry')
|
||||
print('copy copy details of an entry to your clipboard')
|
||||
print('shear/-rm delete an existing entry')
|
||||
print('sync/-s manually sync the entry directory via sshync\n')
|
||||
print('Flags:')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' note/-n change the note attached to an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the URL of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard')
|
||||
print('gen:')
|
||||
print(' update/-u generate a password for an existing entry\n')
|
||||
print("Tip: You can quickly read an entry with 'sshyp /<entry name>'!")
|
||||
print("When specifying entry names, do not include the file extension! '.gpg' is assumed!\n")
|
||||
elif argument == 'version' or argument == '-v':
|
||||
print('\n////////////////////////////////////////////////////////')
|
||||
print('/ /')
|
||||
print('/ sshyp Copyright (C) 2021-2022 Randall Winkhart /')
|
||||
print('/ /')
|
||||
print('/ Version 2022.02.16.fr4 /')
|
||||
print('/ The High-Tech Shears Update /')
|
||||
print('/ /')
|
||||
print('////////////////////////////////////////////////////////\n')
|
||||
elif argument == 'license':
|
||||
print('\nThis program is free software: you can redistribute it and/or modify it under the terms of the GNU '
|
||||
'General\nPublic License as published by the Free Software Foundation, either version 3 of the License,'
|
||||
'\nor (at your option) any later version.\n\nThis program is distributed in the hope that it will be '
|
||||
'useful, but WITHOUT ANY WARRANTY;\nwithout even the implied warranty of MERCHANTABILITY or FITNESS FOR A'
|
||||
' PARTICULAR PURPOSE.\nSee the GNU General Public License for more details.'
|
||||
'\n\nhttps://opensource.org/licenses/GPL-3.0\n')
|
||||
elif argument == 'add':
|
||||
print('\nUSAGE: sshyp add [FLAG]')
|
||||
print('Flags:')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries\n')
|
||||
elif argument == 'edit':
|
||||
print('\nUSAGE: sshyp edit [FLAG]')
|
||||
print('Flags:')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print(' note/-n change the note attached to an entry\n')
|
||||
elif argument == 'copy':
|
||||
print('\nUSAGE: sshyp copy [FLAG]')
|
||||
print('Flags:')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the URL of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard\n')
|
||||
|
||||
|
||||
def no_arg(): # displays a list of entries and gives an option to select one for viewing
|
||||
print("\nFor a list of usable commands, run 'sshyp help'.\n")
|
||||
system(f"cd {directory}; ls -1 *")
|
||||
_read_entry = str(input('\nEntry to read: '))
|
||||
system(f"gpg -d '{directory}{_read_entry.replace('/', '', 1)}.gpg'")
|
||||
print()
|
||||
|
||||
|
||||
def read_shortcut(): # shortcut to quickly read an entry
|
||||
system(f"gpg -d '{directory}{argument.replace('/', '', 1)}.gpg'")
|
||||
|
||||
|
||||
def sync(): # calls sshync to sync changes to the user's server
|
||||
print('\nSyncing entries with the server device...\n')
|
||||
# check for deletions
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"python -c 'import shear"
|
||||
f"; shear.check(\"'\"{client_device_name}\"'\")'\"")
|
||||
system(f"sftp -p -q -i '{path.expanduser('~/.ssh/sshyp')}' -P {port} {username_ssh}@{ip}:"
|
||||
f"'/home/{username_ssh}/.config/sshyp/deletion_database' {path.expanduser('~/.config/sshyp/')}")
|
||||
try:
|
||||
_deletion_database = open(path.expanduser('~/.config/sshyp/deletion_database')).readlines()
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\nThe deletion database does not exist or is corrupted.\n')
|
||||
_deletion_database = None
|
||||
s_exit()
|
||||
for _file in _deletion_database:
|
||||
if _file.endswith('/'):
|
||||
try:
|
||||
rmtree(f"{path.expanduser('~/.password-pasture/')}{_file[:-1]}")
|
||||
except FileNotFoundError:
|
||||
print('\nFolder does not exist locally.\n')
|
||||
else:
|
||||
try:
|
||||
remove(f"{path.expanduser('~/.password-pasture/')}{_file[:-1]}")
|
||||
except FileNotFoundError:
|
||||
print('\nFile does not exist locally.\n')
|
||||
# set permissions before uploading
|
||||
system('find ' + directory + ' -type d -exec chmod -R 700 {} +')
|
||||
system('find ' + directory + ' -type f -exec chmod -R 600 {} +')
|
||||
sshync.run_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'))
|
||||
|
||||
|
||||
def add_entry(): # adds a new entry
|
||||
_shm_folder, _shm_entry = None, None # sets base-line values to avoid errors
|
||||
_entry_name = str(input('\nName of entry: '))
|
||||
if _entry_name.startswith('/'):
|
||||
_entry_name = _entry_name.replace('/', '', 1)
|
||||
if argument == 'add note' or argument == 'add -n':
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines('\n\n\n\n' + _notes + '\n\n')
|
||||
elif argument == 'add password' or argument == 'add -p':
|
||||
_username = str(input('Username: '))
|
||||
_password = str(input('Password: '))
|
||||
_url = str(input('URL: '))
|
||||
_add_note = input('Add a note to this entry? (y/N) ')
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
if _add_note.lower() == 'y':
|
||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
else:
|
||||
_notes = ''
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_username + '\n' + _password + '\n' + _url + '\n\n'
|
||||
+ _notes + '\n\n')
|
||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
||||
system(f"gpg -d '{directory}{_entry_name}.gpg'")
|
||||
|
||||
|
||||
def add_folder(): # creates a new folder
|
||||
_folder_name = str(input('Name of new folder: '))
|
||||
Path(directory + _folder_name).mkdir(0o700)
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"mkdir -p '{directory_ssh}"
|
||||
f"{_folder_name}'\"")
|
||||
|
||||
|
||||
def rename(): # renames an entry or folder TODO delete original from server to prevent re-downloading
|
||||
print()
|
||||
system(f"cd {directory}; ls -1 *") # TODO replace with new list
|
||||
_entry_name = str(input('\nWhat would you like to rename/relocate? '))
|
||||
_new_name = str(input('New Name: '))
|
||||
if _entry_name.startswith('/'):
|
||||
if _entry_name.replace('/', '', 1).__contains__('/'):
|
||||
_folder, _sep, _folder_entry = _entry_name.replace('/', '', 1).partition('/')
|
||||
move(f"{directory}{_folder}/{_folder_entry}.gpg", f"{directory}/{_new_name}.gpg")
|
||||
else:
|
||||
move(f"{directory}{_entry_name.replace('/', '', 1)}.gpg", f"{directory}{_new_name.replace('/', '', 1)}.gpg")
|
||||
else:
|
||||
move(f"{directory}{_entry_name}.gpg", f"{directory}{_new_name}.gpg")
|
||||
|
||||
|
||||
def edit(): # edits the contents of an entry
|
||||
_shm_folder, _shm_entry = None, None # sets base-line values to avoid errors
|
||||
print()
|
||||
system(f"cd {directory}; ls -1 *") # TODO replace with new list
|
||||
_entry_name = str(input('\nWhat file would you like to edit? '))
|
||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||
print("\nYou are trying to edit a file that does not exist!\n")
|
||||
s_exit()
|
||||
if _entry_name.startswith('/'):
|
||||
_entry_name = _entry_name.replace('/', '', 1)
|
||||
if argument == 'edit username' or argument == 'edit -u':
|
||||
_detail = str(input('New Username: '))
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"gpg -d --output {tmp_dir}{_shm_folder}/{_shm_entry} '{directory}{_entry_name}.gpg'")
|
||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 0, _detail + '\n')
|
||||
elif argument == 'edit password' or argument == 'edit -p':
|
||||
_detail = str(input('New Password: '))
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"gpg -d --output {tmp_dir}{_shm_folder}/{_shm_entry} '{directory}{_entry_name}.gpg'")
|
||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 1, _detail + '\n')
|
||||
elif argument == 'edit url' or argument == 'edit -l':
|
||||
_detail = str(input('New URL: '))
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"gpg -d --output {tmp_dir}{_shm_folder}/{_shm_entry} '{directory}{_entry_name}.gpg'")
|
||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 2, _detail + '\n')
|
||||
elif argument == 'edit note' or argument == 'edit -n':
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"gpg -d --output {tmp_dir}{_shm_folder}/{_shm_entry} '{directory}{_entry_name}.gpg'")
|
||||
edit_note(_shm_folder, _shm_entry)
|
||||
remove(f"{directory}{_entry_name}.gpg")
|
||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
||||
system(f"gpg -d '{directory}{_entry_name}.gpg'")
|
||||
|
||||
|
||||
def gen(): # generates a password for a new or an existing entry
|
||||
_username, _url, _notes = None, None, None # sets base-line values to avoid errors
|
||||
if argument == 'gen update' or argument == 'gen -u':
|
||||
print()
|
||||
system(f"cd {directory}; ls -1 *") # TODO replace with new list
|
||||
_entry_name = str(input('\nName of service: '))
|
||||
if _entry_name.startswith('/'):
|
||||
_entry_name = _entry_name.replace('/', '', 1)
|
||||
if argument == 'gen update' or argument == 'gen -u':
|
||||
if not Path(f"{directory}{_entry_name}.gpg").is_file():
|
||||
print("\nYou are trying to edit a file that does not exist!\n")
|
||||
s_exit()
|
||||
if argument != 'gen update' and argument != 'gen -u':
|
||||
_username = str(input('Username: '))
|
||||
_pass_length = int(input('How many characters should be in the password? '))
|
||||
_pass_type = str(input('Should the password be simple (for compatibility) or complex (for security)? (s/C) '))
|
||||
if _pass_type.lower() == 's':
|
||||
_pass_type = string.ascii_letters + string.digits
|
||||
else:
|
||||
_pass_type = string.ascii_letters + string.digits + string.punctuation
|
||||
_pass_gen = ''.join(random.SystemRandom().choice(_pass_type) for _ in range(_pass_length))
|
||||
if argument != 'gen update' and argument != 'gen -u':
|
||||
_url = str(input('URL: '))
|
||||
_add_note = input('Add a note to this entry? (y/N) ')
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
if _add_note.lower() == 'y':
|
||||
system(f"nano {tmp_dir}{_shm_folder}/{_shm_entry}-n")
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
else:
|
||||
_notes = ''
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_username + '\n' + _pass_gen + '\n' + _url + '\n\n'
|
||||
+ _notes + '\n\n')
|
||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
||||
system(f"gpg -d '{directory}{_entry_name}.gpg'")
|
||||
else:
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"gpg -d --output {tmp_dir}{_shm_folder}/{_shm_entry} '{directory}{_entry_name}.gpg'")
|
||||
replace_line(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 1, _pass_gen + '\n')
|
||||
remove(f"{directory}{_entry_name}.gpg")
|
||||
encrypt(_shm_folder, _shm_entry, _entry_name)
|
||||
system(f"gpg -d '{directory}{_entry_name}.gpg'")
|
||||
|
||||
|
||||
def copy_data(): # copies a specified field of an entry to the clipboard
|
||||
print()
|
||||
system(f"cd {directory}; ls -1 *") # TODO replace with new list
|
||||
_read_entry = str(input('\nEntry to copy: '))
|
||||
if not Path(f"{directory}{_read_entry}.gpg").is_file():
|
||||
print("\nThe file does not exist!\n")
|
||||
s_exit()
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
system(f"gpg -d --output {tmp_dir}{_shm_folder}/{_shm_entry} '{directory}{_read_entry}.gpg'")
|
||||
_copy_line = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines()
|
||||
if Path("/data/data/com.termux").exists(): # checks for Termux, Wayland, or X
|
||||
if argument == 'copy username' or argument == 'copy -u':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[0].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
elif argument == 'copy password' or argument == 'copy -p':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[1].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
elif argument == 'copy url' or argument == 'copy -l':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[2].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
elif argument == 'copy note' or argument == 'copy -n':
|
||||
system('termux-clipboard-set ' + "'" + _copy_line[4].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
elif environ.get('WAYLAND_DISPLAY') == 'wayland-0':
|
||||
if argument == 'copy username' or argument == 'copy -u':
|
||||
system('wl-copy ' + "'" + _copy_line[0].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
elif argument == 'copy password' or argument == 'copy -p':
|
||||
system('wl-copy ' + "'" + _copy_line[1].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
elif argument == 'copy url' or argument == 'copy -l':
|
||||
system('wl-copy ' + "'" + _copy_line[2].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
elif argument == 'copy note' or argument == 'copy -n':
|
||||
system('wl-copy ' + "'" + _copy_line[4].replace('\n', '').replace("'", "'\\''") + "'")
|
||||
else:
|
||||
if argument == 'copy username' or argument == 'copy -u':
|
||||
system('echo -n ' + "'" + _copy_line[0].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
elif argument == 'copy password' or argument == 'copy -p':
|
||||
system('echo -n ' + "'" + _copy_line[1].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
elif argument == 'copy url' or argument == 'copy -l':
|
||||
system('echo -n ' + "'" + _copy_line[2].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
elif argument == 'copy note' or argument == 'copy -n':
|
||||
system('echo -n ' + "'" + _copy_line[4].replace('\n', '').replace("'", "'\\''") + "'" + ' | xclip -sel c')
|
||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def remove_data(): # deletes an entry from the server and flags it for local deletion on sync
|
||||
print()
|
||||
system(f"cd {directory}; ls -1 *") # TODO replace with new list
|
||||
_entry_name = str(input('\nWhat would you like to delete? '))
|
||||
if _entry_name.startswith('/'):
|
||||
_entry_name = _entry_name.replace('/', '', 1)
|
||||
try:
|
||||
system(f"gpg -d --output {tmp_dir}sshyp.lock {path.expanduser('~/.config/sshyp/lock.gpg')}")
|
||||
_unlock = open(f"{tmp_dir}sshyp.lock", 'r').readlines()
|
||||
remove(f"{tmp_dir}sshyp.lock")
|
||||
except FileNotFoundError:
|
||||
print('\nAccess denied.\n')
|
||||
s_exit()
|
||||
system(f"ssh -i '{path.expanduser('~/.ssh/sshyp')}' -p {port} {username_ssh}@{ip} \"python -c 'import shear"
|
||||
f"; shear.delete(\"'\"{_entry_name}\"'\")'\"")
|
||||
|
||||
|
||||
# program start sequence
|
||||
|
||||
# retrieve typed argument
|
||||
argument_list = argv
|
||||
i, argument = 0, ''
|
||||
for _ in argument_list:
|
||||
while i < len(argument_list) - 1:
|
||||
i += 1
|
||||
argument += argument_list[i] + ' '
|
||||
argument = argument[:-1]
|
||||
|
||||
# import saved userdata
|
||||
if argument != 'tweak':
|
||||
device_type = ''
|
||||
tmp_dir = path.expanduser('~/.config/sshyp/tmp/')
|
||||
try:
|
||||
device_type = open(path.expanduser('~/.config/sshyp/sshyp-device')).read().strip()
|
||||
if device_type == 'c':
|
||||
gpg_id = open(path.expanduser('~/.config/sshyp/sshyp-gpg')).read().strip()
|
||||
ssh_info = sshync.get_profile(path.expanduser('~/.config/sshyp/sshyp.sshync'))
|
||||
username_ssh = ssh_info[0].replace('\n', '')
|
||||
ip = ssh_info[1].replace('\n', '')
|
||||
port = ssh_info[2].replace('\n', '')
|
||||
directory = str(ssh_info[3].replace('\n', ''))
|
||||
directory_ssh = '/home/' + username_ssh + '/.password-pasture/'
|
||||
client_device_name = listdir(path.expanduser('~/.config/sshyp/devices'))[0]
|
||||
except FileNotFoundError:
|
||||
if device_type.lower() != 's':
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print("Not all necessary configuration files are present. Please run 'sshyp tweak'!")
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
s_exit()
|
||||
else:
|
||||
try:
|
||||
tweak()
|
||||
s_exit()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
|
||||
# run function based on argument
|
||||
error = 0 # create an error flag to determine if syncing should occur at end
|
||||
if argument.startswith('/'):
|
||||
read_shortcut()
|
||||
elif argument == '':
|
||||
try:
|
||||
no_arg()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'help' or argument == '--help' or argument == '-h' or argument == 'license' or argument == 'version' \
|
||||
or argument == '-v' or argument == 'add' or argument == 'edit' or argument == 'copy':
|
||||
print_info()
|
||||
elif argument == 'add note' or argument == 'add -n' or argument == 'add password' or argument == 'add -p':
|
||||
try:
|
||||
add_entry()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'add folder' or argument == 'add -f':
|
||||
try:
|
||||
add_folder()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'edit rename' or argument == 'edit relocate' or argument == 'edit -r':
|
||||
try:
|
||||
rename()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'edit username' or argument == 'edit -u' or argument == 'edit password' or argument == 'edit -p' or \
|
||||
argument == 'edit url' or argument == 'edit -l' or argument == 'edit note' or argument == 'edit -n':
|
||||
try:
|
||||
edit()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'gen' or argument == 'gen update' or argument == 'gen -u':
|
||||
try:
|
||||
gen()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'copy username' or argument == 'copy -u' or argument == 'copy password' or argument == 'copy -p' or \
|
||||
argument == 'copy url' or argument == 'copy -l' or argument == 'copy note' or argument == 'copy -n':
|
||||
try:
|
||||
copy_data()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'shear' or argument == '-rm':
|
||||
try:
|
||||
remove_data()
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
s_exit()
|
||||
elif argument == 'sync' or argument == '-s':
|
||||
sync()
|
||||
else:
|
||||
error = 1 # set error flag to 1 to stop syncing
|
||||
print("\nArgument error! Please run 'sshyp help' for a list of usable commands.\n")
|
||||
s_exit()
|
||||
|
||||
# sync at end of program if any changes were made
|
||||
if argument != '' and argument != 'help' and argument != '--help' and argument != '-h' and argument != 'license' and \
|
||||
argument != 'add' and argument != 'sync' and argument != 'edit' and argument != 'copy username' and argument \
|
||||
!= 'copy -u' and argument != 'copy password' and argument != 'copy -p' and argument != 'copy url' and argument \
|
||||
!= 'copy -l' and argument != 'copy note' and argument != 'copy -n' and argument != 'copy' and argument \
|
||||
!= 'version' and argument != '-v' and error == 0 and \
|
||||
argument.startswith('/') is False:
|
||||
sync()
|
||||
@@ -1,37 +0,0 @@
|
||||
#!/usr/bin/python3
|
||||
|
||||
# external modules
|
||||
|
||||
from os import remove, listdir
|
||||
from os.path import expanduser
|
||||
from shutil import rmtree
|
||||
|
||||
|
||||
# utility functions
|
||||
|
||||
def delete(_file_path):
|
||||
if _file_path.endswith('/'):
|
||||
try:
|
||||
rmtree(f"{expanduser('~/.password-pasture/')}{_file_path}")
|
||||
except FileNotFoundError:
|
||||
print('\nFolder does not exist remotely.')
|
||||
else:
|
||||
try:
|
||||
remove(f"{expanduser('~/.password-pasture/')}{_file_path}.gpg")
|
||||
except FileNotFoundError:
|
||||
print('\nFile does not exist remotely.\n')
|
||||
for _device_name in listdir(expanduser('~/.config/sshyp/devices')):
|
||||
open(f"{expanduser('~/.config/sshyp/deleted/')}{_file_path.replace('/', '@')}.{_device_name}.del", 'w')
|
||||
|
||||
|
||||
def check(_client_device_name):
|
||||
open(expanduser('~/.config/sshyp/deletion_database'), 'w').write('')
|
||||
for _file in listdir(expanduser('~/.config/sshyp/deleted')):
|
||||
_file_path = _file.replace('.gpg', '').replace('@', '/').split('.')[0]
|
||||
_device = _file.replace('.gpg', '').split('.')[1]
|
||||
if _device == _client_device_name:
|
||||
try:
|
||||
remove(f"{expanduser('~/.config/sshyp/deleted/')}{_file}")
|
||||
except FileNotFoundError:
|
||||
pass
|
||||
open(expanduser('~/.config/sshyp/deletion_database'), 'a').write(_file_path + '.gpg\n')
|
||||
Executable → Regular
+692
-73
@@ -1,3 +1,624 @@
|
||||
sshyp v1.4.1
|
||||
|
||||
the argumentative agronomist update - patch one
|
||||
|
||||
this release improves sshyp's shell completions by adding zsh support and significantly optimizing and improving Bash support
|
||||
|
||||
user-facing features:
|
||||
|
||||
- zsh completion support
|
||||
^ ensure modern completions are enabled in your ~/.zshrc
|
||||
|
||||
fixes/optimizations:
|
||||
|
||||
- Bash completions are now much faster due to the use of recursive globbing
|
||||
- Bash completions have been modified to be functionally similar to the new zsh completions
|
||||
|
||||
other notable changes:
|
||||
|
||||
- some official packages now use more space-efficient compression
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.4.0
|
||||
|
||||
the argumentative agronomist update
|
||||
|
||||
this release overhauls sshyp's argument system and further streamlines
|
||||
the experience with optimizations and the removal of legacy features
|
||||
|
||||
compatibility-breaking changes:
|
||||
|
||||
- there are no technical breaking changes, but the UX has changed significantly due to the new argument system (detailed below)
|
||||
|
||||
user-facing features:
|
||||
|
||||
- when typing an entry/folder name, it is now always the FIRST argument
|
||||
^ e.g. instead of "sshyp copy -p /example/test", it would now be "sshyp /example/test copy -p"
|
||||
^ this allows more easily editing the previous command to copy/edit a different field
|
||||
- better extension integration
|
||||
^ extensions can now ship with a config file that sshyp can use to call them from standard sshyp arguments
|
||||
^ the first extension supporting this is sshyp-mfa
|
||||
^ if sshyp-mfa v1.4.0.1+ is installed, "sshyp /example/test copy -m" will copy MFA keys to your clipboard
|
||||
- entry/folder names now MUST be specified as arguments
|
||||
^ there is no longer a separate input prompt if the entry/folder name is not provided as an argument
|
||||
^ the input prompt was a legacy feature from before arguments could specify entrys/folders with shell completion
|
||||
^ the entry list generated by entry_list_gen() is still present and can be viewed by running "sshyp" with no arguments
|
||||
- better Bash completions
|
||||
^ now correctly places backslashes to escape spaces in entry/folder names
|
||||
^ slightly faster than the previous iteration
|
||||
- IPv6 configuration support
|
||||
|
||||
fixes/optimizations:
|
||||
|
||||
- replaced "+=" with ".append" when extending lists to prevent creating an additional list
|
||||
- optimized usage of "str.split()" and replaced it with "str.splitlines()" where applicable
|
||||
- more concise "if... in ()" syntax replaces long "if" statement chains
|
||||
- lists have been substituted with tuples where applicable
|
||||
- entry_list_gen() has been re-written to be much smaller and faster
|
||||
- os.path is now used in place of pathlib.Path in areas where it is faster
|
||||
- the user's home directory is saved to a variable to prevent running expanduser() every time it is needed
|
||||
|
||||
other notable changes:
|
||||
|
||||
- removed some uncommonly used, redundant arguments
|
||||
^ e.g. "-rm", "-s", "delete"
|
||||
^ their functionality was NOT removed, just their redundant arguments, since "shear", "sync", and "del" are the accepted syntax
|
||||
- errors containing entry/folder names reinforce correct syntax by adding leading/following slashes where necessary
|
||||
- thanks to pull request #25, there are new error messages for the read shortcut
|
||||
^ includes when no entry name is provided or the entry name only refers to a directory
|
||||
- directories provided in user input are no longer denoted by a following slash
|
||||
^ instead, os.path is used to determine if the user is referring to a file or directory
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.3.0
|
||||
|
||||
the serious shepherd update
|
||||
|
||||
this release ties up many of sshyp's loose ends where there was
|
||||
room for major performance, compatibility, and security improvements
|
||||
|
||||
compatibility-breaking changes:
|
||||
|
||||
- due to a near full re-write of the syncing functionality, all clients and servers
|
||||
must be updated to this release (v1.3.0 is not backwards compatible with any prior release)
|
||||
- it is recommended to either delete the contents of ~/.config/sshyp/deleted (on the server-side)
|
||||
or sync all of your clients before updating
|
||||
^ old entries in this folder will throw errors with v1.3.0
|
||||
|
||||
user-facing features:
|
||||
|
||||
- none - all changes were under-the-hood - the user experience should be
|
||||
exactly the same as v1.2.0 - just faster, less buggy, and more secure
|
||||
|
||||
major fixes/optimizations:
|
||||
|
||||
- a near full re-write of the syncing functionality
|
||||
^ all syncing logic has been moved into sshync.py (from sshyp.py and sshypRemote.py)
|
||||
^ in my setup, a dry, local "sshyp sync" went from 2.00+ seconds (v1.2.0) to 0.36 seconds (v1.3.0)
|
||||
^ the performance improvements are even greater when syncing from outside your local network
|
||||
- the following character sequences will no longer break the syncing logic: "@", "^&*", and "*&^"
|
||||
^ ASCII separator characters 29-31 are now used, instead
|
||||
- os.system has been replaced with subprocess.run in all cases, shell=True is no longer used with subprocess.run
|
||||
^ this protects against shell escape attacks and potentially makes sshyp more compatible with some environments
|
||||
- replaced shell commands with python built-in library functions where applicable
|
||||
^ this brings speed and compatibility improvements
|
||||
- sshyp should no longer incorrectly assume an X11 environment when Wayland is in use
|
||||
^ this fixes clipboard support in some Wayland environments, such as Sway (Plasma/Gnome/Phosh were unaffected)
|
||||
- sshyp now uses the default pinentry on Haiku thanks to haikuports/haikuports#7457
|
||||
^ this brings the Haiku port in-line with the other sshyp packages in terms of security
|
||||
- "python3" is now called over ssh, rather than "python"
|
||||
^ some environments do not have a "python" symlink, or it links to "python2" - changing this increases compatibility
|
||||
- fixed an issue from v1.2.0 where renaming threw an error if not in offline mode
|
||||
|
||||
other notable changes:
|
||||
|
||||
- quick-unlock password input is now hidden while the user is typing
|
||||
^ user input is now invisible to prevent snooping
|
||||
- lots of smaller optimizations not listed here
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.2.0
|
||||
|
||||
the brisk bahh update
|
||||
|
||||
this release focuses on speeding up the sshyp user experience by adding
|
||||
new features that reduce wasted time
|
||||
|
||||
compatibility-breaking changes:
|
||||
|
||||
- new configuration options (quick-unlock, offline mode) have been added and
|
||||
the configuration files have been reorganized
|
||||
^ simply running "sshyp tweak" and following the setup wizard will correct any compatibility
|
||||
issues
|
||||
- for quick-unlock security, device names have been replaced with more secure device ids
|
||||
^ older device names are still compatible, but for security reasons it is recommended
|
||||
to delete any pre-existing device names from the server and allow "sshyp tweak" to re-register
|
||||
your devices
|
||||
|
||||
user-facing features:
|
||||
|
||||
- quick-unlock mode has been added
|
||||
^ this allows you to use a shortened version of your password by verifying that your device
|
||||
is whitelisted on your sshyp server - it's both faster and more secure than standard unlock,
|
||||
but it requires an active connection to your sshyp server to authenticate (otherwise it will
|
||||
fall back to standard unlock)
|
||||
- full support for offline usage
|
||||
^ though sshyp could be used without a server before, it now can be configured to not attempt
|
||||
to find one ever - this saves time and hides sync failure error messages
|
||||
- bash completions have been added
|
||||
^ if you have bash-completion installed, you can now use the tab key in bash to auto-complete
|
||||
sshyp arguments and entry names (client only, not added for server-specific arguments)
|
||||
^ if you do not have bash-completion installed, you can source
|
||||
/usr/share/bash-completion/completions/sshyp (Linux/BSD) or
|
||||
/boot/system/data/bash-completion/completions/sshyp (Haiku) in your ~/.bashrc to
|
||||
use this feature
|
||||
|
||||
fixes/optimizations:
|
||||
|
||||
- fixed entries with multi-word titles failing to decrypt
|
||||
- password generation is now much faster and more resource efficient
|
||||
- there is no longer a length limit on generated passwords
|
||||
- improved visual consistency of help menus
|
||||
- rarely used modules are now imported only when needed
|
||||
- sshyp now uses one fewer configuration file
|
||||
|
||||
other notable changes:
|
||||
|
||||
- sshyp is now specifically licensed under the GPL-3.0-only (keyword: only)
|
||||
- sshyp now has some possible arguments and its own help menu when running in server mode
|
||||
- temporary files in /dev/shm are now generated with more complex names
|
||||
- sshyp now installs in /usr/lib/sshyp (Linux/BSD) or /system/lib/sshyp (Haiku) instead of
|
||||
/usr/bin or /bin (it is still symlinked to the old directories)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.1.2
|
||||
|
||||
the sheecrets update - patch two
|
||||
|
||||
this is a general polish/bugfix release
|
||||
|
||||
user-facing features:
|
||||
|
||||
- packaging support for Alpine Linux/postmarketOS
|
||||
- the rename() function is no longer unnecessarily verbose
|
||||
- handled exception for when the user attempts to copy an entry field that does not exist
|
||||
|
||||
fixes/optimizations:
|
||||
|
||||
- replaced shebang with "#!/usr/bin/env python3" for improved compatibility with various systems
|
||||
^ does not affect Haiku packaging
|
||||
- fixed the generic package not actually being compressed
|
||||
- reduced lines of code used for cross-device entry deletion
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.1.1
|
||||
|
||||
the sheecrets update - patch one
|
||||
|
||||
this is a polish/bug fix release that makes tweaks to the entry format (without breaking compatibility)
|
||||
|
||||
compatibility-breaking changes:
|
||||
|
||||
- none; the entry format tweaks are backward compatible with sshyp v1.0.0+
|
||||
^ the new format is slightly more efficient in terms of storage space
|
||||
^ if you would like to upgrade to it, run this script (after updating to v1.1.1):
|
||||
https://raw.githubusercontent.com/rwinkhart/sshyp-labs/main/extra/conversion-scripts/sshyp-refresh-1.1.1%2B.py
|
||||
|
||||
user-facing features:
|
||||
|
||||
- entries (when editing or adding) are now run through the new optimized_edit() function to strip trailing new lines
|
||||
and ensure the format of the entries is fully compatible with all of sshyp's functions
|
||||
|
||||
fixes:
|
||||
|
||||
- when adding a note to an entry, there is no longer a chance the first note line will be added as a url
|
||||
if the entry is using an older format/pass format
|
||||
- the gpg auto-generation file temporarily created by sshyp no longer includes extra spaces
|
||||
^ seems to serve no functional purpose - fixed for the sake of polish
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.1.0
|
||||
|
||||
the sheecrets update
|
||||
|
||||
the main focus of this release was adding extension support (particularly for sshyp-mfa)
|
||||
and cleaning up the configuration experience
|
||||
|
||||
compatibility-breaking changes:
|
||||
|
||||
- the entry directory has been moved from ~/.password-pasture to ~/.local/share/sshyp
|
||||
as a means of complying with the XDG base directory spec
|
||||
^ this requires the user to move their entry directory to the new location manually
|
||||
^ if this is not done, sshyp will not be able to find entries made prior to v1.1.0
|
||||
- due to a new configuration option (preferred text editor), 'sshyp tweak' must be run after updating
|
||||
|
||||
user-facing features:
|
||||
|
||||
- extension support
|
||||
^ some of sshyp's critical functions can now be imported into other programs to extend
|
||||
upon sshyp's functionality
|
||||
^ the first usecase of this is sshyp-mfa, which can be found at https://github.com/rwinkhart/sshyp-labs
|
||||
- a new configuration experience
|
||||
^ the 'sshyp tweak' menu has been made much more readable, and now the automatically generated
|
||||
gpg key has its id automatically input, making the process easier for the user
|
||||
- customizable text editor
|
||||
^ the text editor used for editing notes can now be set to any editor preferred by the user
|
||||
^ this means that nano was dropped as a dependency
|
||||
|
||||
fixes:
|
||||
|
||||
- to avoid exceptions on server devices, all arguments (apart from 'tweak') have been disabled on servers
|
||||
- fixed entry readout not printing blank lines between fields under certain conditions
|
||||
- various optimizations
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.0.1
|
||||
|
||||
The Polished Trotters Update - Patch 1
|
||||
|
||||
This is a hotfix for the Haiku decryption bug.
|
||||
|
||||
Changes:
|
||||
|
||||
- subprocess.Popen has been replaced with subprocess.run where applicable
|
||||
- stdout is no longer captured with any subprocess.Popen or subprocess.run usages
|
||||
^ this fixes decryption on Haiku
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp v1.0.0
|
||||
|
||||
The Polished Trotters Update
|
||||
|
||||
This release brings 'sshyp' in line with the original goals of the project.
|
||||
As such, it is being crowned "v1.0.0", and is considered a stable base for future expansions.
|
||||
|
||||
Features:
|
||||
|
||||
- sshyp has been modified to run on Haiku, an open-source re-implementation of BeOS
|
||||
^ new package formats have been added for Haiku, FreeBSD, and Fedora Linux
|
||||
- the entry format has been changed to support entries created in pass/password-store
|
||||
^ this change requires existing entry libraries to be converted - see the sshyp v1.0.0 release page on GitHub for a conversion script
|
||||
- majorly overhauled visual experience for sshyp
|
||||
^ this includes a new entry list, a new entry readout, colored output, ascii art, and more!
|
||||
- entries can now optionally be passed as arguments, directly
|
||||
^ as opposed to the user being prompted for an entry name after running a command
|
||||
|
||||
Changes:
|
||||
|
||||
- corrected outdated licensing and copyright information
|
||||
- 'if __name__=="__main__":' convention is now used
|
||||
- help screens have been overhauled
|
||||
- improved password generator to guarantee more secure results
|
||||
- fixed errors when trying to sync with a multi-word entry on the server
|
||||
- sshync now uses 'scp' (via the sftp protocol), rather than 'sftp'
|
||||
- rename function now properly allows for renaming folders
|
||||
- renaming an entry/folder will now properly delete the old entry/folder from the server
|
||||
- entry previews at the time of entry creation/editing no longer require entering the gpg password more times than necessary
|
||||
- entries will no longer be overwritten if attempting to create a new entry that uses an already existing name
|
||||
- the clipboard now automatically clears after 30 seconds
|
||||
- sshyp server no longer needs to create copies of its libraries in ~/
|
||||
- added more and improved existing exceptions
|
||||
- the lock file is now decrypted to /dev/null
|
||||
- ...and lots of minor (under the hood) changes!
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4.7
|
||||
|
||||
The High-Tech Shears Update - Patch 7
|
||||
|
||||
This release enables recursive folder syncing.
|
||||
|
||||
Note: Upgrading from releases older than fr4.7 requires the configuration ("sshyp tweak") to be re-done, as the configuration process has changed.
|
||||
|
||||
Changes:
|
||||
|
||||
- re-wrote folder checking function to fetch subdirectories recursively
|
||||
- added in user-facing messages for when folders are being synced or entries are being removed
|
||||
- fixed a typo preventing folder syncing from working (actually tested this time)
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4.6
|
||||
|
||||
The High-Tech Shears Update - Patch 6
|
||||
|
||||
This release addresses a critical typo.
|
||||
|
||||
Note: Upgrading from releases older than fr4.6 requires the configuration ("sshyp tweak") to be re-done, as the configuration process has changed.
|
||||
|
||||
Changes:
|
||||
|
||||
- corrected a typo error causing folder syncing issues
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4.5
|
||||
|
||||
The High-Tech Shears Update - Patch 5
|
||||
|
||||
This release addresses a critical syntax error.
|
||||
|
||||
Note: Upgrading from releases older than fr4.5 requires the configuration ("sshyp tweak") to be re-done, as the configuration process has changed.
|
||||
|
||||
Changes:
|
||||
|
||||
- corrected a syntax error causing critical functionality issues
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4.4
|
||||
|
||||
The High-Tech Shears Update - Patch 4
|
||||
|
||||
This release automatically generates user-created folders on new client devices.
|
||||
|
||||
Note: Upgrading to releases in the fr4 series requires the configuration ("sshyp tweak") to be re-done, as a device name now must be set (for multi-client deletion). Even upgrading from fr4.3 to fr4.4 will require re-running "sshyp tweak" due to file name changes.
|
||||
|
||||
Features:
|
||||
|
||||
- implemented proper folder syncing for new clients and clients missing folders that exist server-side
|
||||
|
||||
Changes:
|
||||
|
||||
- old device names are now automatically deleted (locally) when running "sshyp tweak", to prevent conflicts
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4.3
|
||||
|
||||
The High-Tech Shears Update - Patch 3
|
||||
|
||||
This release addresses a bug with local entry deletion.
|
||||
|
||||
Note: Upgrading to releases in the fr4 series requires the configuration ("sshyp tweak") to be re-done, as a device name now must be set (for multi-client deletion).
|
||||
|
||||
Changes:
|
||||
|
||||
- fixed an issue where entries could not be deleted locally
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4.2
|
||||
|
||||
The High-Tech Shears Update - Patch 2
|
||||
|
||||
This release re-addresses a bug with local folder deletion.
|
||||
|
||||
Note: Upgrading to releases in the fr4 series requires the configuration ("sshyp tweak") to be re-done, as a device name now must be set (for multi-client deletion).
|
||||
|
||||
Changes:
|
||||
|
||||
- fixed an issue where folders could not be deleted locally (actually, this time)
|
||||
- properly handled an exception for when the user forgets a following '/' when attempting to delete a folder
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4.1
|
||||
|
||||
The High-Tech Shears Update - Patch 1
|
||||
|
||||
This release addresses a bug with local folder deletion.
|
||||
|
||||
Note: Upgrading to releases in the fr4 series requires the configuration ("sshyp tweak") to be re-done, as a device name now must be set (for multi-client deletion).
|
||||
|
||||
Changes:
|
||||
|
||||
- fixed an issue where folders could not be deleted locally
|
||||
- optimized deletion flags
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
sshyp 2022.02.16.fr4
|
||||
|
||||
The High-Tech Shears Update
|
||||
@@ -23,29 +644,29 @@ Changes:
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
** sshyp has recieved a major visual overhaul
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
** sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
** when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
** imporove password generator to guarantee more secure results
|
||||
** enforce permissions on the server-side
|
||||
** allow for copying entire notes (not just first line)
|
||||
** ability to pass entries as arguments for more functions
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
** create separate gui frontend targetting mobile and desktop Linux
|
||||
** auto-completion on tab (currently unsure of best way to make this work)
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
@@ -66,30 +687,30 @@ Changes:
|
||||
Planned for next major update (fr4, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
** sshyp has recieved a major visual overhaul
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
** sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr5, The Farmer Shearing the sshyp Update):
|
||||
|
||||
** allow for multi-client deletion... somehow (in sshync)
|
||||
** when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
** imporove password generator to guarantee more secure results
|
||||
** enforce permissions on the server-side
|
||||
** allow for copying entire notes (not just first line)
|
||||
** ability to pass entries as arguments for more functions
|
||||
- allow for multi-client deletion... somehow (in sshync)
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
** create separate gui frontend targetting mobile and desktop Linux
|
||||
** auto-completion on tab (currently unsure of best way to make this work)
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
@@ -110,39 +731,39 @@ Changes:
|
||||
|
||||
Additions planned for minor releases:
|
||||
|
||||
** updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
** ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
** reduced total lines of code with small optimizations
|
||||
- updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
- ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
- reduced total lines of code with small optimizations
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr4, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
** sshyp has recieved a major visual overhaul
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
** sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr5, The Farmer Shearing the sshyp Update):
|
||||
|
||||
** allow for multi-client deletion... somehow (in sshync)
|
||||
** when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
** imporove password generator to guarantee more secure results
|
||||
** enforce permissions on the server-side
|
||||
** allow for copying entire notes (not just first line)
|
||||
** ability to pass entries as arguments for more functions
|
||||
- allow for multi-client deletion... somehow (in sshync)
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
** create separate gui frontend targetting mobile and desktop Linux
|
||||
** auto-completion on tab (currently unsure of best way to make this work)
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
@@ -160,39 +781,39 @@ Changes:
|
||||
|
||||
Additions planned for minor releases:
|
||||
|
||||
** updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
** ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
** reduced total lines of code with small optimizations
|
||||
- updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
- ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
- reduced total lines of code with small optimizations
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr4, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
** sshyp has recieved a major visual overhaul
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
** sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr5, The Farmer Shearing the sshyp Update):
|
||||
|
||||
** allow for multi-client deletion... somehow (in sshync)
|
||||
** when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
** imporove password generator to guarantee more secure results
|
||||
** enforce permissions on the server-side
|
||||
** allow for copying entire notes (not just first line)
|
||||
** ability to pass entries as arguments for more functions
|
||||
- allow for multi-client deletion... somehow (in sshync)
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
** create separate gui frontend targetting mobile and desktop Linux
|
||||
** auto-completion on tab (currently unsure of best way to make this work)
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
@@ -211,39 +832,39 @@ Changes:
|
||||
|
||||
Additions planned for minor releases:
|
||||
|
||||
** updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
** ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
** reduced total lines of code with small optimizations
|
||||
- updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
- ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
- reduced total lines of code with small optimizations
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr4, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
** sshyp has recieved a major visual overhaul
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
** sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr5, The Farmer Shearing the sshyp Update):
|
||||
|
||||
** allow for multi-client deletion... somehow (in sshync)
|
||||
** when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
** imporove password generator to guarantee more secure results
|
||||
** enforce permissions on the server-side
|
||||
** allow for copying entire notes (not just first line)
|
||||
** ability to pass entries as arguments for more functions
|
||||
- allow for multi-client deletion... somehow (in sshync)
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
** create separate gui frontend targetting mobile and desktop Linux
|
||||
** auto-completion on tab (currently unsure of best way to make this work)
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
@@ -266,39 +887,39 @@ Changes:
|
||||
|
||||
Additions planned for minor releases:
|
||||
|
||||
** updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
** ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
** reduced total lines of code with small optimizations
|
||||
- updated the manpage with more information regarding how sshyp works and how to set it up
|
||||
- ensured that it is now impossible for ghosts of entires to remain in /dev/shm
|
||||
- reduced total lines of code with small optimizations
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr4, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
** sshyp has recieved a major visual overhaul
|
||||
- sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
** sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
- sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr5, The Farmer Shearing the sshyp Update):
|
||||
|
||||
** allow for multi-client deletion... somehow (in sshync)
|
||||
** when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
** imporove password generator to guarantee more secure results
|
||||
** enforce permissions on the server-side
|
||||
** allow for copying entire notes (not just first line)
|
||||
** ability to pass entries as arguments for more functions
|
||||
- allow for multi-client deletion... somehow (in sshync)
|
||||
- when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
- imporove password generator to guarantee more secure results
|
||||
- enforce permissions on the server-side
|
||||
- allow for copying entire notes (not just first line)
|
||||
- ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
** create separate gui frontend targetting mobile and desktop Linux
|
||||
** auto-completion on tab (currently unsure of best way to make this work)
|
||||
- create separate gui frontend targetting mobile and desktop Linux
|
||||
- auto-completion on tab (currently unsure of best way to make this work)
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
@@ -813,5 +1434,3 @@ What is currently functional:
|
||||
- sort notes and passwords into folders
|
||||
- gpg encryption
|
||||
- edit password/note entries
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
Executable
+41
@@ -0,0 +1,41 @@
|
||||
# sshyp(1) completion
|
||||
|
||||
_path_gen() {
|
||||
local sshyp_path="$HOME/.local/share/sshyp"
|
||||
local glob_status=$(shopt -p globstar)
|
||||
[ -z "${glob_status##*u*}" ] && shopt -s globstar # if recursive globbing is disabled, enable it
|
||||
local full_paths=("$sshyp_path"/**/*.gpg)
|
||||
$glob_status # set recursive globbing to user default
|
||||
for scan_path in "${full_paths[@]}"; do
|
||||
trimmed_paths+=("${scan_path:${#sshyp_path}:-4}")
|
||||
done
|
||||
if [ "${trimmed_paths[0]}" == '/**/*' ]; then trimmed_paths[0]=help; fi
|
||||
} &&
|
||||
|
||||
_sshyp_completions() {
|
||||
local cur=${COMP_WORDS[COMP_CWORD]}
|
||||
local prev=${COMP_WORDS[COMP_CWORD-1]}
|
||||
|
||||
case $prev in
|
||||
sshyp )
|
||||
while read -r; do ITEM=${REPLY// /\\ }; COMPREPLY+=( "$ITEM" ); done < <( compgen -W "$(printf "'%s' " "${trimmed_paths[@]}")" -- "$cur" )
|
||||
;;
|
||||
/* )
|
||||
while read -r; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "add gen edit copy shear" -- "$cur" )
|
||||
;;
|
||||
add )
|
||||
while read -r; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "password note folder" -- "$cur" )
|
||||
;;
|
||||
copy )
|
||||
while read -r; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "password username url note" -- "$cur" )
|
||||
;;
|
||||
edit )
|
||||
while read -r; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "password username url note relocate" -- "$cur" )
|
||||
;;
|
||||
gen )
|
||||
while read -r; do COMPREPLY+=( "$REPLY" ); done < <( compgen -W "update" -- "$cur" )
|
||||
;;
|
||||
esac
|
||||
|
||||
} &&
|
||||
_path_gen && complete -F _sshyp_completions sshyp
|
||||
Executable
+30
@@ -0,0 +1,30 @@
|
||||
#compdef sshyp
|
||||
|
||||
sshyp_path="$HOME/.local/share/sshyp"
|
||||
full_paths=("$sshyp_path"/**/*.gpg)
|
||||
trimmed_paths=()
|
||||
for scan_path in "${full_paths[@]}"; do
|
||||
trimmed_paths+=("${${scan_path#$sshyp_path}%????}")
|
||||
done
|
||||
[[ -z $trimmed_paths ]] && trimmed_paths=(help)
|
||||
|
||||
case ${words[-2]} in
|
||||
sshyp )
|
||||
compadd $trimmed_paths
|
||||
;;
|
||||
/* )
|
||||
compadd {add,gen,edit,copy,shear}
|
||||
;;
|
||||
add )
|
||||
compadd {password,note,folder}
|
||||
;;
|
||||
copy )
|
||||
compadd {password,username,url,note}
|
||||
;;
|
||||
edit )
|
||||
compadd {password,username,url,note,relocate}
|
||||
;;
|
||||
gen )
|
||||
compadd update
|
||||
;;
|
||||
esac
|
||||
+78
-53
@@ -1,101 +1,126 @@
|
||||
.TH sshyp 1 "16 February 2022" "2022.02.16.fr4" "sshyp man page"
|
||||
.TH sshyp 1 "02 April 2023" "v1.4.1" "sshyp man page"
|
||||
.SH NAME
|
||||
sshyp \- A very simple self-hosted, synchronized password manager. Alternative to GNU pass.
|
||||
sshyp \- A very simple self-hosted, synchronized password manager for UNIX(-like) systems. Alternative to (and compatible with) pass/password-store.
|
||||
.SH SYNOPSIS
|
||||
sshyp [OPTION] [[FLAG]] [/<entry name>]
|
||||
Client Usage: sshyp [</entry name> [option] [flag]] [option]
|
||||
|
||||
Server Usage: sshyp <option> [flag] [<device id>]
|
||||
.SH DESCRIPTION
|
||||
sshyp is a lightweight password and note management program written in Python. sshyp is used via CLI and is self-hosted with a client-server model. sshyp expects that you have access to a personal server with a properly configured ssh server, ideally accepting remote connections.
|
||||
.SH EXAMPLES
|
||||
.SH EXAMPLES (CLIENT)
|
||||
Setting up sshyp for the first time or altering its configuration (also recommended after major updates):
|
||||
sshyp tweak
|
||||
*follow the prompts
|
||||
|
||||
Reading an existing entry saved as ~/.password-pasture/development/github.gpg:
|
||||
Viewing the entry database:
|
||||
sshyp
|
||||
|
||||
Reading an existing entry saved as '~/.local/share/sshyp/development/github.gpg':
|
||||
sshyp /development/github
|
||||
|
||||
Copying the password of an existing entry saved as ~/.password-pasture/financial/bank.gpg:
|
||||
sshyp copy -p
|
||||
*answer the prompt with "/financial/bank"
|
||||
*enter decryption password
|
||||
Copying the password of an existing entry saved as '~/.local/share/sshyp/financial/bank.gpg':
|
||||
sshyp /financial/bank copy -p
|
||||
|
||||
Editing the username of an existing entry saved as ~/.password-pasture/game.gpg:
|
||||
sshyp edit -u
|
||||
*answer the first prompt with "game"
|
||||
*follow the prompts
|
||||
Editing the username of an existing entry saved as '~/.local/share/sshyp/game.gpg':
|
||||
sshyp /game edit -u
|
||||
|
||||
Making a new entry using the built-in password generator:
|
||||
sshyp gen
|
||||
*follow the prompts
|
||||
Making a new entry saved as '~/.local/share/sshyp/school/university.gpg' using the built-in password generator:
|
||||
sshyp /school/university gen
|
||||
|
||||
Creating a note-only entry:
|
||||
sshyp add -n
|
||||
*follow the prompts
|
||||
Creating a note-only entry saved as '~/.local/share/sshyp/notes/test note.gpg':
|
||||
sshyp /notes/test\ note add -n
|
||||
|
||||
Syncing entries with the server:
|
||||
Manually syncing entries with the server:
|
||||
sshyp sync
|
||||
|
||||
Removing an existing folder saved as ~/.password-pasture/social:
|
||||
sshyp shear
|
||||
*when prompted for what to delete, since you are deleting a folder, be sure to enter your choice with a following "/", e.g. "social/" or "/social/"
|
||||
Removing an existing folder saved as '~/.local/share/sshyp/social':
|
||||
sshyp /social/ shear
|
||||
.SH EXAMPLES (SERVER)
|
||||
Setting up the quick-unlock whitelist:
|
||||
sshyp whitelist setup
|
||||
|
||||
.SH OPTIONS
|
||||
In order to quickly read an existing entry, just run "sshyp </entry name>".
|
||||
Checking the quick-unlock whitelist status of all registered client devices:
|
||||
sshyp whitelist list
|
||||
|
||||
Options for other operations are as follows:
|
||||
Adding a device with the id 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_' to the quick-unlock whitelist:
|
||||
sshyp whitelist add 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_'
|
||||
|
||||
help/--help/-h bring up the help menu
|
||||
Removing a device with the id 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_' from the quick-unlock whitelist:
|
||||
sshyp whitelist del 'laptop-im|lAoa;&;r&o:ez((g/Dz;EVb.nO_'
|
||||
.SH OPTIONS (CLIENT)
|
||||
help/-h bring up the help menu
|
||||
version/-v display sshyp version info
|
||||
tweak configure sshyp
|
||||
add add an entry
|
||||
gen generate a new password
|
||||
edit edit an existing entry
|
||||
copy copy details of an entry to your clipboard
|
||||
shear/-rm delete an existing entry
|
||||
sync/-s manually sync the entry directory via sshync
|
||||
.SH FLAGS
|
||||
shear delete an existing entry
|
||||
sync manually sync the entry directory via sshync
|
||||
.SH FLAGS (CLIENT)
|
||||
add:
|
||||
password/-p add a password entry
|
||||
note/-n add a note entry
|
||||
folder/-f add a new folder for entries
|
||||
password/-p add a password entry
|
||||
note/-n add a note entry
|
||||
folder/-f add a new folder for entries
|
||||
|
||||
edit:
|
||||
rename/relocate/-r rename or relocate an entry
|
||||
username/-u change the username of an entry
|
||||
password/-p change the password of an entry
|
||||
note/-n change the note attached to an entry
|
||||
url/-l change the url attached to an entry
|
||||
rename/relocate/-r rename or relocate an entry
|
||||
username/-u change the username of an entry
|
||||
password/-p change the password of an entry
|
||||
note/-n change the note attached to an entry
|
||||
url/-l change the url attached to an entry
|
||||
|
||||
copy:
|
||||
username/-u copy the username of an entry to your clipboard
|
||||
password/-p copy the password of an entry to your clipboard
|
||||
url/-l copy the URL of an entry to your clipboard
|
||||
note/-n copy the note of an entry to your clipboard
|
||||
username/-u copy the username of an entry to your clipboard
|
||||
password/-p copy the password of an entry to your clipboard
|
||||
url/-l copy the URL of an entry to your clipboard
|
||||
note/-n copy the note of an entry to your clipboard
|
||||
|
||||
gen:
|
||||
update/-u generate a password for an existing entry
|
||||
.SH LIMITATIONS
|
||||
The following limitations will be corrected in future updates:
|
||||
|
||||
Currently, folders (for sorting) are not replicated onto new clients (they need to be manually created before syncing).
|
||||
|
||||
Currently, the entry list displays each entry with the file extension ".gpg" visible (which you do not type when reading, modifying, or creating an entry). This will be corrected when the new entry list is added.
|
||||
update/-u generate a password for an existing entry
|
||||
.SH OPTIONS (SERVER)
|
||||
help/-h bring up this menu
|
||||
version/-v display sshyp version info
|
||||
tweak configure sshyp
|
||||
whitelist manage the quick-unlock whitelist
|
||||
.SH FLAGS (SERVER)
|
||||
whitelist:
|
||||
setup set up the quick-unlock whitelist
|
||||
list/-l view all registered device ids and their quick-unlock whitelist status
|
||||
add whitelist a device id for quick-unlock
|
||||
del remove a device id from the quick-unlock whitelist
|
||||
.SH SETUP
|
||||
sshyp operates on a client-server model, and thus requires you to have access to your own server (whether it be a physical home server or a cloud rental) with remote access via SSH.
|
||||
|
||||
The sshyp package includes modes for operating on both client and server devices, so only one package is necessary.
|
||||
|
||||
Server setup:
|
||||
Configure an openssh server (if sshyp was installed from the Debian package, the ssh server was not installed as a dependency and needs to be installed manually)
|
||||
Configure an OpenSSH server (if sshyp was installed from the Debian package, openssh-server and openssh-sftp-server must be installed manually - if sshyp was installed from the Fedora package, openssh-server must be installed manually)
|
||||
Allow remote access to the SSH server w/public key authentication (disabling password-only authentication recommended)
|
||||
Install sshyp
|
||||
Run "sshyp tweak" and set the device type as server
|
||||
Optionally, run "sshyp whitelist setup" and configure quick-unlock
|
||||
Done!
|
||||
|
||||
Client setup:
|
||||
Install sshyp
|
||||
Run "sshyp tweak" and follow the prompts
|
||||
Copy the generated public SSH key to the server using preferred method (manually adding to authorized_keys, ssh-copy-id, etc.)
|
||||
**this step will be automated in the future: if an entry library already exists on the server, make sure to manually recreate any folders that exist on the server in the ~/.password-pasture directory
|
||||
Copy the generated public SSH key (located at ~/.ssh/sshyp.pub) to the server using preferred method (manually adding to authorized_keys, ssh-copy-id, etc.)
|
||||
If you already have entries on the server, sync them using "sshyp sync"
|
||||
Optionally, shell completions (both Bash and ZSH) can be enabled with your shell's respective method
|
||||
Done!
|
||||
|
||||
Please note that the server setup intentionally does not allow the reading of entries (it does not allow adding a gpg decryption key). For security purposes, only clients can read entries.
|
||||
.SH EXIT CODES
|
||||
0 - no error
|
||||
|
||||
1 - configuration error
|
||||
|
||||
2 - data not found error
|
||||
|
||||
3 - data already exists error
|
||||
|
||||
4 - decryption/encryption error
|
||||
|
||||
5 - server connection error
|
||||
.SH AUTHOR
|
||||
Randall Winkhart (https://github.com/rwinkhart)
|
||||
|
||||
Executable
+170
@@ -0,0 +1,170 @@
|
||||
#!/usr/bin/env python3
|
||||
from os import listdir, remove, walk
|
||||
from os.path import expanduser, isdir, getmtime, join
|
||||
from subprocess import CalledProcessError, PIPE, run
|
||||
from sys import exit as s_exit
|
||||
home = expanduser("~")
|
||||
|
||||
|
||||
# REMOTE
|
||||
|
||||
def remote_list_gen(_client_device_name, _remote_dir): # prints all necessary remote data to stdout
|
||||
# deletions
|
||||
for _file in listdir(f"{home}/.config/sshyp/deleted"):
|
||||
_file_path, _sep, _device = _file.partition('\x1f')
|
||||
_file_path = _file_path.replace('\x1e', '/')
|
||||
if _device == _client_device_name:
|
||||
print(_file_path)
|
||||
try:
|
||||
remove(f"{home}/.config/sshyp/deleted/{_file}")
|
||||
except FileNotFoundError:
|
||||
pass
|
||||
print('\x1d')
|
||||
# folders
|
||||
for _root, _directories, _files in walk(f"{home}/.local/share/sshyp"):
|
||||
for _dir in _directories:
|
||||
print(f"{_root.replace(home, '')}/{_dir}")
|
||||
print('\x1d')
|
||||
get_local_data(_remote_dir, 'server') # titles and mod times
|
||||
|
||||
|
||||
# HYBRID
|
||||
|
||||
def delete(_file_path, _target_database): # deletes a file or folder and/or marks it for deletion upon syncing
|
||||
from shutil import rmtree
|
||||
_directory = f"{home}/.local/share/sshyp/"
|
||||
try:
|
||||
if isdir(_directory + _file_path):
|
||||
rmtree(_directory + _file_path)
|
||||
else:
|
||||
remove(f"{_directory}{_file_path}.gpg")
|
||||
except FileNotFoundError:
|
||||
print(f"location does not exist {_target_database}")
|
||||
if _target_database == 'remotely':
|
||||
for _device_name in listdir(f"{home}/.config/sshyp/devices"):
|
||||
open(f"{home}/.config/sshyp/deleted/" + _file_path.replace('/', '\x1e') + '\x1f' + _device_name, 'w')
|
||||
|
||||
|
||||
def get_local_data(_directory, _device): # retrieves and returns titles and mod times from the local device
|
||||
_title_list, _mod_list = [], []
|
||||
for _root, _directories, _files in walk(_directory):
|
||||
for _filename in _files:
|
||||
_title_list.append(join(_root.replace(_directory, '', 1), _filename))
|
||||
_mod_list.append(int(getmtime(join(_root, _filename))))
|
||||
if _device == 'server':
|
||||
for _title in _title_list:
|
||||
print(_title.rstrip())
|
||||
for _time in _mod_list:
|
||||
print(_time)
|
||||
return _title_list, _mod_list
|
||||
|
||||
|
||||
# LOCAL
|
||||
|
||||
def remote_list_fetch(_user_data): # captures and returns all necessary data from the remote server
|
||||
try:
|
||||
_remote_data = run(['ssh', '-i', _user_data[5], '-p', _user_data[2], f"{_user_data[0]}@{_user_data[1]}",
|
||||
f'cd /lib/sshyp; python3 -c \'from sshync import remote_list_gen; remote_list_gen'
|
||||
f'("{_user_data[6]}", "{_user_data[4]}")\''], stdout=PIPE, text=True, check=True
|
||||
).stdout.split('\x1d')
|
||||
except CalledProcessError:
|
||||
print('\n\u001b[38;5;9merror: failed to connect to the remote server\u001b[0m\n')
|
||||
_remote_data = ''
|
||||
s_exit(5)
|
||||
_deletion_database = _remote_data[0].strip().splitlines()
|
||||
_folder_database = _remote_data[1].strip().splitlines()
|
||||
_titles_mods = _remote_data[2].strip().splitlines()
|
||||
return _deletion_database, _folder_database, _titles_mods[:len(_titles_mods)//2], \
|
||||
_titles_mods[len(_titles_mods)//2:]
|
||||
|
||||
|
||||
def deletion_sync(_deletion_database, _silent): # checks for and acts upon files and folders marked for deletion
|
||||
for _file in _deletion_database:
|
||||
if _file != '':
|
||||
if not _silent:
|
||||
print(f"\u001b[38;5;208m{_file}\u001b[0m has been sheared, removing...")
|
||||
delete(_file, 'locally')
|
||||
|
||||
|
||||
def folder_sync(_folder_database): # creates matches of remote folders on the local client
|
||||
from pathlib import Path
|
||||
for _folder in _folder_database:
|
||||
if _folder != '' and not isdir(home + _folder):
|
||||
print(f"\u001b[38;5;2m{_folder.replace('/.local/share/sshyp/', '')}/\u001b[0m does not exist locally, "
|
||||
f"creating...")
|
||||
Path(home + _folder).mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||
|
||||
|
||||
def sort_titles_mods(_list_1, _list_2): # creates and returns two lists (of titles and mod times) generated by sorting
|
||||
# information from two provided 2D lists
|
||||
_title_list_2_sorted, _mod_list_2_sorted = [], []
|
||||
# title sorting
|
||||
for _title in _list_1[0]:
|
||||
if _title in _list_2[0]:
|
||||
_title_list_2_sorted.append(_title)
|
||||
for _title in _list_2[0]:
|
||||
if _title not in _title_list_2_sorted:
|
||||
_title_list_2_sorted.append(_title)
|
||||
# mod time sorting
|
||||
for _title in _title_list_2_sorted:
|
||||
_mod_list_2_sorted.append(_list_2[1][_list_2[0].index(_title)])
|
||||
return _title_list_2_sorted, _mod_list_2_sorted
|
||||
|
||||
|
||||
def make_profile(_profile_dir, _local_dir, _remote_dir, _identity, _ip, _port, _user): # creates a sshync job profile
|
||||
open(_profile_dir, 'w').write(f"{_user}\n{_ip}\n{_port}\n{_local_dir}\n{_remote_dir}\n{_identity}\n")
|
||||
|
||||
|
||||
def get_profile(_profile_dir): # returns a list of data read from a sshync job profile
|
||||
try:
|
||||
_profile_data = open(_profile_dir).readlines()
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\n\u001b[38;5;9merror: the profile does not exist or is corrupted\u001b[0m\n')
|
||||
_profile_data = None
|
||||
s_exit(2)
|
||||
_user = _profile_data[0].rstrip()
|
||||
_ip = _profile_data[1].rstrip()
|
||||
_port = _profile_data[2].rstrip()
|
||||
_local_dir = _profile_data[3].rstrip()
|
||||
_remote_dir = _profile_data[4].rstrip()
|
||||
_identity = _profile_data[5].rstrip()
|
||||
_client_device_id = listdir(f"{home}/.config/sshyp/devices")[0].rstrip()
|
||||
return _user, _ip, _port, _local_dir, _remote_dir, _identity, _client_device_id
|
||||
|
||||
|
||||
def run_profile(_profile_dir, _silent): # runs a sshync job profile
|
||||
_user_data = get_profile(_profile_dir) # import profile data
|
||||
# fetch remote lists
|
||||
_deletion_database, _folder_database, _remote_titles, _remote_mods = remote_list_fetch(_user_data)
|
||||
_remote_titles_mods = (_remote_titles, _remote_mods)
|
||||
# sync deletions and folders
|
||||
deletion_sync(_deletion_database, _silent)
|
||||
folder_sync(_folder_database)
|
||||
# sort titles and mods
|
||||
_index_local = sort_titles_mods(_remote_titles_mods, get_local_data(_user_data[3], 'client'))
|
||||
_index_remote = sort_titles_mods(_index_local, _remote_titles_mods)
|
||||
# sync new and updated files
|
||||
_i = -1
|
||||
for _title in _index_local[0]:
|
||||
_i += 1
|
||||
if _title in _index_remote[0]:
|
||||
# compare mod times and sync
|
||||
if int(_index_local[1][_i]) > int(_index_remote[1][_i]):
|
||||
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is newer locally, uploading...")
|
||||
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5], _user_data[3] + _title,
|
||||
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||
elif int(_index_local[1][_i]) < int(_index_remote[1][_i]):
|
||||
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is newer remotely, downloading...")
|
||||
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5],
|
||||
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{_title}",
|
||||
f"{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||
else:
|
||||
print(f"\u001b[38;5;4m{_title[:-4]}\u001b[0m is not on remote server, uploading...")
|
||||
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5], _user_data[3] + _title,
|
||||
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||
for _title in _index_remote[0]:
|
||||
if _title not in _index_local[0]:
|
||||
print(f"\u001b[38;5;2m{_title[:-4]}\u001b[0m is not in local directory, downloading...")
|
||||
run(['scp', '-pqs', '-P', _user_data[2], '-i', _user_data[5],
|
||||
f"{_user_data[0]}@{_user_data[1]}:{_user_data[4]}{_title}",
|
||||
f"{_user_data[3]}{'/'.join(_title.split('/')[:-1]) + '/'}"])
|
||||
Executable
+861
@@ -0,0 +1,861 @@
|
||||
#!/usr/bin/env python3
|
||||
from os import chmod, environ, listdir, remove, uname, walk
|
||||
from os.path import exists, expanduser, isdir, isfile, realpath
|
||||
from pathlib import Path
|
||||
from random import randint
|
||||
from shutil import get_terminal_size, move, rmtree
|
||||
from sshync import delete as offline_delete, run_profile, make_profile, get_profile
|
||||
from subprocess import CalledProcessError, DEVNULL, PIPE, run
|
||||
from sys import argv, exit as s_exit
|
||||
home = expanduser("~")
|
||||
|
||||
|
||||
# UTILITY FUNCTIONS
|
||||
|
||||
def entry_list_gen(_directory=f"{home}/.local/share/sshyp/"): # generates and prints full entry list
|
||||
from textwrap import fill
|
||||
_ran = False
|
||||
print("\nfor a list of usable commands, run 'sshyp help'\n\n\u001b[38;5;0;48;5;15msshyp entries:\u001b[0m\n")
|
||||
for _root, _dirs, _files in sorted(walk(_directory, topdown=True)):
|
||||
_entry_list, _color_alternator = [], 1
|
||||
if _ran:
|
||||
print(f"\u001b[38;5;15;48;5;238m{_root.replace(f'{home}/.local/share/sshyp', '', 1)}/\u001b[0m")
|
||||
for filename in sorted(_files):
|
||||
if _color_alternator > 0:
|
||||
_entry_list.append(filename[:-4])
|
||||
else:
|
||||
_entry_list.append(f"\u001b[38;5;8m{filename[:-4]}\u001b[0m")
|
||||
_color_alternator = _color_alternator * -1
|
||||
_real = len(' '.join(_entry_list)) - (5.5 * len(_entry_list))
|
||||
if _real <= get_terminal_size()[0]:
|
||||
_width = len(' '.join(_entry_list))
|
||||
else:
|
||||
_width = (len(' '.join(_entry_list)) / (_real / get_terminal_size()[0]) - 25)
|
||||
if len(_entry_list) > 0:
|
||||
print(fill(' '.join(_entry_list), width=_width) + '\n')
|
||||
elif _ran:
|
||||
print('\u001b[38;5;9m-empty directory-\u001b[0m\n')
|
||||
_ran = True
|
||||
|
||||
|
||||
def entry_reader(_decrypted_entry): # displays the contents of an entry in a readable format
|
||||
_entry_lines, _notes_flag = open(_decrypted_entry, 'r').readlines(), 0
|
||||
print()
|
||||
for _num in range(len(_entry_lines)):
|
||||
try:
|
||||
if _num == 0 and _entry_lines[1] != '\n':
|
||||
print(f"\u001b[38;5;15;48;5;238musername:\u001b[0m\n{_entry_lines[1].strip()}\n")
|
||||
elif _num == 1 and _entry_lines[0] != '\n':
|
||||
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0].strip()}\n")
|
||||
elif _num == 2 and _entry_lines[2] != '\n':
|
||||
print(f"\u001b[38;5;15;48;5;238murl:\u001b[0m\n{_entry_lines[_num].strip()}\n")
|
||||
elif _num >= 3 and _entry_lines[_num] != '\n' and _notes_flag != 1:
|
||||
_notes_flag = 1
|
||||
print(f"\u001b[38;5;15;48;5;238mnotes:\u001b[0m\n{_entry_lines[_num].strip()}")
|
||||
elif _num >= 3 and _notes_flag == 1:
|
||||
print(_entry_lines[_num].replace('\n', ''))
|
||||
if _notes_flag == 1:
|
||||
try:
|
||||
_line_test = _entry_lines[_num + 1]
|
||||
except IndexError:
|
||||
print()
|
||||
except IndexError:
|
||||
if _num == 0:
|
||||
print(f"\u001b[38;5;15;48;5;238mpassword:\u001b[0m\n{_entry_lines[0]}\n")
|
||||
|
||||
|
||||
def string_gen(_complexity, _length): # generates and returns a random string based on input
|
||||
from random import SystemRandom
|
||||
import string
|
||||
if _complexity == 's':
|
||||
_character_pool = string.ascii_letters + string.digits
|
||||
elif _complexity == 'f':
|
||||
_character_pool = string.digits + string.ascii_letters + string.punctuation.replace('/', '').replace('\\', '')\
|
||||
.replace("'", '').replace('"', '').replace('`', '').replace('~', '')
|
||||
else:
|
||||
_character_pool = string.digits + string.ascii_letters + string.punctuation
|
||||
_min_special, _special = round(.2 * _length), 0
|
||||
while True:
|
||||
_gen = ''.join(SystemRandom().choice(_character_pool) for _ in range(_length))
|
||||
for _character in _gen:
|
||||
if not _character.isalpha():
|
||||
_special += 1
|
||||
if _special >= _min_special:
|
||||
break
|
||||
return _gen
|
||||
|
||||
|
||||
def pass_gen(): # prompts the user for necessary information to generate a password and passes it to string_gen
|
||||
_length = 9
|
||||
while True:
|
||||
try:
|
||||
_length = int(input('password length: '))
|
||||
except ValueError:
|
||||
continue
|
||||
else:
|
||||
if _length < 1:
|
||||
continue
|
||||
else:
|
||||
break
|
||||
_complexity = str(input('password complexity - simple (for compatibility) or complex (for security)? (s/C) '))
|
||||
if _complexity not in ('s', 'S'):
|
||||
_complexity = 'c'
|
||||
_gen = string_gen(_complexity.lower(), _length)
|
||||
return _gen
|
||||
|
||||
|
||||
def shm_gen(_tmp_dir=f"{home}/.config/sshyp/tmp/"): # creates a temporary directory for entry editing
|
||||
_shm_folder_gen = string_gen('f', randint(12, 48))
|
||||
_shm_entry_gen = string_gen('f', randint(12, 48))
|
||||
Path(_tmp_dir + _shm_folder_gen).mkdir(mode=0o700)
|
||||
return _shm_folder_gen, _shm_entry_gen
|
||||
|
||||
|
||||
def encrypt(_entry_dir, _shm_folder, _shm_entry, _gpg_id, _tmp_dir=f"{home}/.config/sshyp/tmp/"):
|
||||
# encrypts an entry and cleans up the temporary files
|
||||
run(['gpg', '-qr', str(_gpg_id), '-e', f"{_tmp_dir}{_shm_folder}/{_shm_entry}"])
|
||||
move(f"{_tmp_dir}{_shm_folder}/{_shm_entry}.gpg", f"{_entry_dir}.gpg")
|
||||
rmtree(f"{_tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def decrypt(_entry_dir, _shm_folder, _shm_entry, _quick_pass,
|
||||
_tmp_dir=f"{home}/.config/sshyp/tmp/"): # decrypts an entry to a temporary directory
|
||||
if not isinstance(_quick_pass, bool):
|
||||
_unlock_method = ['gpg', '--pinentry-mode', 'loopback', '--passphrase', _quick_pass, '-qd', '--output']
|
||||
else:
|
||||
_unlock_method = ['gpg', '-qd', '--output']
|
||||
if _shm_folder is None and _shm_entry is None:
|
||||
_output_target = ['/dev/null', f"{home}/.config/sshyp/lock.gpg"]
|
||||
else:
|
||||
_output_target = [f"{_tmp_dir}{_shm_folder}/{_shm_entry}", f"{_entry_dir}.gpg"]
|
||||
try:
|
||||
run(_unlock_method + _output_target, stderr=DEVNULL, check=True)
|
||||
except CalledProcessError:
|
||||
if not isinstance(_quick_pass, bool):
|
||||
print('\n\u001b[38;5;9merror: quick-unlock failed as a result of an incorrect passphrase, an unreachable '
|
||||
'sshyp server, or an invalid configuration\n\nfalling back to standard unlock\u001b[0m\n')
|
||||
try:
|
||||
run(['gpg', '-qd', '--output'] + _output_target, stderr=DEVNULL, check=True)
|
||||
except CalledProcessError:
|
||||
print('\n\u001b[38;5;9merror: could not decrypt - ensure the correct gpg key is present\u001b[0m\n')
|
||||
s_exit(4)
|
||||
else:
|
||||
print('\n\u001b[38;5;9merror: could not decrypt - ensure the correct gpg key is present\u001b[0m\n')
|
||||
s_exit(4)
|
||||
|
||||
|
||||
def determine_decrypt(_entry_dir, _shm_folder, _shm_entry): # call decrypt() based on quick-unlock status
|
||||
if quick_unlock_enabled == 'y':
|
||||
decrypt(_entry_dir, _shm_folder, _shm_entry, whitelist_verify(port, username_ssh, ip, client_device_id))
|
||||
else:
|
||||
decrypt(_entry_dir, _shm_folder, _shm_entry, False)
|
||||
|
||||
|
||||
def optimized_edit(_lines, _edit_data, _edit_line): # ensures an edited entry is optimized for best compatibility
|
||||
while len(_lines) < _edit_line + 1:
|
||||
_lines.append('\n')
|
||||
if _edit_data is not None:
|
||||
_lines[_edit_line] = _edit_data.strip('\n').rstrip() + '\n'
|
||||
for _num in range(len(_lines)):
|
||||
if not _lines[_num].endswith('\n'):
|
||||
_lines[_num] += '\n'
|
||||
for _num in reversed(range(len(_lines))):
|
||||
if _lines[_num] == '\n':
|
||||
_lines = _lines[:-1]
|
||||
elif _lines[_num].endswith('\n'):
|
||||
_lines[_num] = _lines[_num].rstrip()
|
||||
break
|
||||
else:
|
||||
break
|
||||
return _lines
|
||||
|
||||
|
||||
def edit_note(_shm_folder, _shm_entry, _lines): # edits the note attached to an entry
|
||||
_reg_lines = _lines[0:3]
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'w').writelines(_lines[3:])
|
||||
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||
_new_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n").readlines()
|
||||
while len(_reg_lines) < 3:
|
||||
_reg_lines.append('\n')
|
||||
_noted_lines = _reg_lines + _new_notes
|
||||
return _noted_lines
|
||||
|
||||
|
||||
def copy_id_check(_port, _username_ssh, _ip, _client_device_id):
|
||||
# attempts to connect to the user's server via ssh to register the device for syncing
|
||||
try:
|
||||
run(['ssh', '-o', 'ConnectTimeout=3', '-i', f"{home}/.ssh/sshyp", '-p', _port, f"{_username_ssh}@{_ip}",
|
||||
f'python3 -c \'from pathlib import Path; Path("/home/{_username_ssh}/.config/sshyp/devices/'
|
||||
f'{_client_device_id}").touch(mode=0o400, exist_ok=True)\''], stderr=DEVNULL, check=True)
|
||||
except CalledProcessError:
|
||||
print('\n\u001b[38;5;9mwarning: ssh connection could not be made - ensure the public key (~/.ssh/sshyp.pub) is '
|
||||
'registered on the remote server and that the entered ip, port, and username are correct\n\nsyncing '
|
||||
'functionality will be disabled until this is addressed\u001b[0m\n')
|
||||
open(f"{home}/.config/sshyp/ssh-error", 'w').write('1')
|
||||
return True
|
||||
open(f"{home}/.config/sshyp/ssh-error", 'w').write('0')
|
||||
return False
|
||||
|
||||
|
||||
# ARGUMENT-SPECIFIC FUNCTIONS
|
||||
|
||||
def tweak(): # runs configuration wizard
|
||||
from os import symlink
|
||||
_divider = f"\n{'=' * (get_terminal_size()[0] - int((.5 * get_terminal_size()[0])))}\n\n"
|
||||
|
||||
# config directory creation
|
||||
Path(f"{home}/.config/sshyp/devices").mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||
if not exists(f"{home}/.config/sshyp/tmp"):
|
||||
if uname()[0] in ('Haiku', 'FreeBSD'):
|
||||
symlink('/tmp', f"{home}/.config/sshyp/tmp")
|
||||
elif exists('/data/data/com.termux'):
|
||||
symlink('/data/data/com.termux/files/usr/tmp', f"{home}/.config/sshyp/tmp")
|
||||
else:
|
||||
symlink('/dev/shm', f"{home}/.config/sshyp/tmp")
|
||||
|
||||
# device type configuration
|
||||
_device_type = input('\nclient or server installation? (C/s) ')
|
||||
if _device_type.lower() == 's':
|
||||
_sshyp_data = ['server']
|
||||
Path(f"{home}/.config/sshyp/deleted").mkdir(mode=0o700, exist_ok=True)
|
||||
Path(f"{home}/.config/sshyp/whitelist").mkdir(mode=0o700, exist_ok=True)
|
||||
print(f"\n\u001b[4;1mmake sure the ssh service is running and properly configured\u001b[0m")
|
||||
else:
|
||||
_sshyp_data = ['client']
|
||||
Path(f"{home}/.local/share/sshyp").mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||
|
||||
# gpg configuration
|
||||
_gpg_gen = input(f"{_divider}sshyp requires the use of a unique gpg key - use an (e)xisting key or (g)enerate a"
|
||||
f" new one? (E/g) ")
|
||||
if _gpg_gen.lower() != 'g':
|
||||
run(['gpg', '-k'])
|
||||
_sshyp_data.append(str(input('gpg key id: ')))
|
||||
else:
|
||||
print('\na unique gpg key is being generated for you...')
|
||||
if not isfile(f"{home}/.config/sshyp/gpg-gen"):
|
||||
open(f"{home}/.config/sshyp/gpg-gen", 'w').writelines([
|
||||
'Key-Type: 1\n', 'Key-Length: 4096\n', 'Key-Usage: sign encrypt\n', 'Name-Real: sshyp\n',
|
||||
'Name-Comment: gpg-sshyp\n', 'Name-Email: https://github.com/rwinkhart/sshyp\n', 'Expire-Date: 0'])
|
||||
run(['gpg', '--batch', '--generate-key', f"{home}/.config/sshyp/gpg-gen"])
|
||||
remove(f"{home}/.config/sshyp/gpg-gen")
|
||||
_sshyp_data.append(run(['gpg', '-k'], stdout=PIPE, text=True).stdout.splitlines()[-3].strip())
|
||||
|
||||
# text editor configuration
|
||||
_sshyp_data.append(input(f"{_divider}example input: vim\n\npreferred text editor: "))
|
||||
|
||||
# lock file generation
|
||||
if isfile(f"{home}/.config/sshyp/lock.gpg"):
|
||||
remove(f"{home}/.config/sshyp/lock.gpg")
|
||||
open(f"{home}/.config/sshyp/lock", 'w')
|
||||
run(['gpg', '-qr', str(_sshyp_data[1]), '-e', f"{home}/.config/sshyp/lock"])
|
||||
remove(f"{home}/.config/sshyp/lock")
|
||||
|
||||
# ssh key configuration
|
||||
_offline_mode = False
|
||||
_ssh_gen = (input(f"{_divider}make sure the ssh service on the remote server is running and properly "
|
||||
f"configured\n\nsync support requires a unique ssh key - would you like to have this "
|
||||
f"automatically generated? (Y/n/o(ffline)) "))
|
||||
if _ssh_gen.lower() not in ('n', 'o', 'offline'):
|
||||
Path(f"{home}/.ssh").mkdir(mode=0o700, exist_ok=True)
|
||||
run(['ssh-keygen', '-t', 'ed25519', '-f', f"{home}/.ssh/sshyp"])
|
||||
elif _ssh_gen.lower() == 'n':
|
||||
print(f"\n\u001b[4;1mensure that the key file you are using is located at {home}/.ssh/sshyp\u001b[0m")
|
||||
elif _ssh_gen.lower() in ('o', 'offline'):
|
||||
_offline_mode = True
|
||||
print('\nsshyp has been set to offline mode - to enable syncing, run "sshyp tweak" again')
|
||||
|
||||
if not _offline_mode:
|
||||
# ssh ip+port configuration
|
||||
_iport = str(input(f"{_divider}example inputs:\n\n ipv4: 10.10.10.10:22\n ipv6: [2000:2000:2000:2000:"
|
||||
f"2000:2000:2000:2000]:22\n domain: mydomain.com:22\n\nip and ssh port of sshyp server: "
|
||||
)).lstrip('[').replace(']', '').rsplit(':', 1)
|
||||
|
||||
# ssh user configuration
|
||||
_username_ssh = str(input('\nusername of the remote server: '))
|
||||
|
||||
# sshync profile generation
|
||||
make_profile(f"{home}/.config/sshyp/sshyp.sshync",
|
||||
f"{home}/.local/share/sshyp/", f"/home/{_username_ssh}/.local/share/sshyp/",
|
||||
f"{home}/.ssh/sshyp", _iport[0], _iport[1], _username_ssh)
|
||||
|
||||
# device id configuration
|
||||
for _id in listdir(f"{home}/.config/sshyp/devices"): # remove existing device id
|
||||
remove(f"{home}/.config/sshyp/devices/{_id}")
|
||||
print(f"{_divider}\u001b[4;1mimportant:\u001b[0m this id \u001b[4;1mmust\u001b[0m be unique amongst your "
|
||||
f"client devices\n\nthis is used to keep track of database syncing and quick-unlock permissions\n")
|
||||
_device_id_prefix = str(input('device id: ')) + '-'
|
||||
_device_id_suffix = string_gen('f', randint(24, 48))
|
||||
_device_id = _device_id_prefix + _device_id_suffix
|
||||
open(f"{home}/.config/sshyp/devices/{_device_id}", 'w')
|
||||
|
||||
# quick-unlock configuration
|
||||
print(f"{_divider}this allows you to use a shorter version of your gpg key password and\n"
|
||||
f"requires a constant connection to your sshyp server to authenticate")
|
||||
_sshyp_data.append(input('\nenable quick-unlock? (y/N) ').lower())
|
||||
if _sshyp_data[3] == 'y':
|
||||
print(f"\nquick-unlock has been enabled client-side - in order for this device to be able to read "
|
||||
f"entries,\nyou must first login to the sshyp server and run:\n\nsshyp whitelist setup "
|
||||
f"(if not already done)\nsshyp whitelist add '{_device_id}'")
|
||||
|
||||
# test server connection and attempt to register device id
|
||||
copy_id_check(_iport[1], _username_ssh, _iport[0], _device_id)
|
||||
|
||||
elif isfile(f"{home}/.config/sshyp/sshyp.sshync"):
|
||||
remove(f"{home}/.config/sshyp/sshyp.sshync")
|
||||
|
||||
# write main config file (sshyp-data)
|
||||
with open(f"{home}/.config/sshyp/sshyp-data", 'w') as _config_file:
|
||||
_lines = 0
|
||||
for _item in _sshyp_data:
|
||||
_lines += 1
|
||||
_config_file.write(_item + '\n')
|
||||
while _lines < 4:
|
||||
_lines += 1
|
||||
_config_file.write('n')
|
||||
print(f"{_divider}configuration complete\n")
|
||||
|
||||
|
||||
def print_info(): # prints help text based on argument
|
||||
if arguments[0] in ('version', '-v'):
|
||||
print('\nsshyp is a simple, self-hosted, sftp-synchronized\npassword manager for unix(-like) systems\n')
|
||||
print(" .. \u001b[38;5;9m♥♥ ♥♥\u001b[0m ..\n .''.''/()\\ \u001b[38;5;13m"
|
||||
"♥♥♥♥♥♥♥\u001b[0m /()\\''.''.\n * : \u001b[38;5;9m♥♥♥♥♥\u001b[0m : *"
|
||||
"\n `..'..' \u001b[38;5;13m♥♥♥\u001b[0m `..'..'\n // \\\\ "
|
||||
"\u001b[38;5;9m♥\u001b[0m // \\\\")
|
||||
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8msshyp copyright (c) 2021-2023 '
|
||||
'randall winkhart\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mversion 1.4.1'
|
||||
'\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m \u001b[38;5;15;48;5;8mthe argumentative '
|
||||
'agronomist update\u001b[38;5;15;48;5;15m \u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m/\u001b[38;5;15;48;5;15m '
|
||||
'\u001b[38;5;7;48;5;8m/\u001b[0m')
|
||||
print('\u001b[38;5;7;48;5;8m<><><><><><><><><><><><><><><><><><><><><><><><><><><><>\u001b[0m\n')
|
||||
print('see https://github.com/rwinkhart/sshyp for more information\n')
|
||||
elif arguments[0] == 'license':
|
||||
print('\nThis program is free software: you can redistribute it and/or modify it under the terms\nof version 3 '
|
||||
'(only) of the GNU General Public License as published by the Free Software Foundation.\n\nThis program '
|
||||
'is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;\nwithout even the implied '
|
||||
'warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.\nSee the GNU General Public License for'
|
||||
' more details.\n\nhttps://opensource.org/licenses/GPL-3.0\n')
|
||||
elif arguments[0] == 'add' and device_type == 'client':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp </entry name> add <flag>\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries\n')
|
||||
elif arguments[0] == 'edit' and device_type == 'client':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp </entry name> edit <flag>\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print(' note/-n change the note attached to an entry\n')
|
||||
elif arguments[0] == 'copy' and device_type == 'client':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp </entry name> copy <flag>\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the url of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard\n')
|
||||
elif arguments[0] == 'whitelist':
|
||||
if device_type == 'server':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp whitelist <flag> [device id]\u001b[0m\n')
|
||||
print('\u001b[1mflags:\u001b[0m')
|
||||
print('whitelist:')
|
||||
print(' setup set up the quick-unlock whitelist')
|
||||
print(' list/-l view all registered device ids and their quick-unlock whitelist status')
|
||||
print(' add whitelist a device id for quick-unlock')
|
||||
print(' delete/del remove a device id from the quick-unlock whitelist\n')
|
||||
else:
|
||||
print('\n\u001b[38;5;9merror: argument (whitelist) only available on server\u001b[0m\n')
|
||||
else:
|
||||
print('\n\u001b[1msshyp copyright (c) 2021-2023 randall winkhart\u001b[0m\n')
|
||||
print("this is free software, and you are welcome to redistribute it under certain conditions;\nthis program "
|
||||
"comes with absolutely no warranty;\ntype 'sshyp license' for details")
|
||||
if device_type == 'client':
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp [</entry name> [option] [flag]] [option]\n')
|
||||
print('\u001b[1moptions:\u001b[0m')
|
||||
print('help/-h bring up this menu')
|
||||
print('version/-v display sshyp version info')
|
||||
print('tweak configure sshyp')
|
||||
print('add add an entry')
|
||||
print('gen generate a new password')
|
||||
print('edit edit an existing entry')
|
||||
print('copy copy details of an entry to your clipboard')
|
||||
print('shear delete an existing entry')
|
||||
print('sync manually sync the entry directory via sshync')
|
||||
print('\n\u001b[1mflags:\u001b[0m')
|
||||
print('add:')
|
||||
print(' password/-p add a password entry')
|
||||
print(' note/-n add a note entry')
|
||||
print(' folder/-f add a new folder for entries')
|
||||
print('edit:')
|
||||
print(' rename/relocate/-r rename or relocate an entry')
|
||||
print(' username/-u change the username of an entry')
|
||||
print(' password/-p change the password of an entry')
|
||||
print(' url/-l change the url attached to an entry')
|
||||
print(' note/-n change the note attached to an entry')
|
||||
print('copy:')
|
||||
print(' username/-u copy the username of an entry to your clipboard')
|
||||
print(' password/-p copy the password of an entry to your clipboard')
|
||||
print(' url/-l copy the url of an entry to your clipboard')
|
||||
print(' note/-n copy the note of an entry to your clipboard')
|
||||
print('gen:')
|
||||
print(' update/-u generate a password for an existing entry')
|
||||
print("\n\u001b[1mtip 1:\u001b[0m you can quickly read an entry with 'sshyp </entry name>'")
|
||||
print("\u001b[1mtip 2:\u001b[0m type 'sshyp' to view a list of saved entries\n")
|
||||
else:
|
||||
print('\n\u001b[1musage:\u001b[0m sshyp <option> [flag] [<device id>]\n')
|
||||
print('\u001b[1moptions:\u001b[0m')
|
||||
print('help/-h bring up this menu')
|
||||
print('version/-v display sshyp version info')
|
||||
print('tweak configure sshyp')
|
||||
print('whitelist manage the quick-unlock whitelist')
|
||||
print('\n\u001b[1mflags:\u001b[0m')
|
||||
print('whitelist:')
|
||||
print(' setup set up the quick-unlock whitelist')
|
||||
print(' list/-l view all registered device ids and their quick-unlock whitelist status')
|
||||
print(' add whitelist a device id for quick-unlock')
|
||||
print(' del remove a device id from the quick-unlock whitelist\n')
|
||||
|
||||
|
||||
def read_shortcut(): # shortcut to quickly read an entry
|
||||
if not exists(f"{directory}{entry_name}.gpg"):
|
||||
if not entry_name:
|
||||
print(f"\n\u001b[38;5;9merror: missing entry name\u001b[0m\n")
|
||||
elif isdir(f"{directory}{entry_name}"):
|
||||
print(f"\n\u001b[38;5;9merror: entry ({arguments[0]}) is a directory\u001b[0m\n")
|
||||
else:
|
||||
print(f"\n\u001b[38;5;9merror: entry ({arguments[0]}) does not exist\u001b[0m\n")
|
||||
s_exit(2)
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + entry_name, _shm_folder, _shm_entry)
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def sync(): # calls sshync to sync changes to the user's server
|
||||
print('\nsyncing entries with the server device...\n')
|
||||
# set permissions before uploading
|
||||
for _root, _dirs, _files in walk(f"{home}/.local/share/sshyp"):
|
||||
for _path in _root.splitlines():
|
||||
chmod(_path, 0o700)
|
||||
for _file in _files:
|
||||
chmod(_root + '/' + _file, 0o600)
|
||||
run_profile(f"{home}/.config/sshyp/sshyp.sshync", silent_sync)
|
||||
|
||||
|
||||
def whitelist_setup(): # takes input from the user to set up quick-unlock password
|
||||
_gpg_password_temp = str(input('\nfull gpg passphrase: '))
|
||||
_half_length = int(len(_gpg_password_temp)/2)
|
||||
try:
|
||||
_short_password_length = int(input(f"\nquick unlock pin length (must be half the length of gpg password or "
|
||||
f"less) ({_half_length}): "))
|
||||
if _short_password_length > _half_length:
|
||||
_short_password_length = _half_length
|
||||
except ValueError:
|
||||
_short_password_length = _half_length
|
||||
_i, _quick_unlock_password, _quick_unlock_password_excluded = 0, '', ''
|
||||
for _char in _gpg_password_temp:
|
||||
if _i % 2 == 1 and _i < _short_password_length*2:
|
||||
_quick_unlock_password += _char
|
||||
else:
|
||||
_quick_unlock_password_excluded += _char
|
||||
_i += 1
|
||||
|
||||
# create assembly key
|
||||
open(f"{home}/.config/sshyp/gpg-gen", 'w').writelines([
|
||||
'Key-Type: 1\n', 'Key-Length: 4096\n', 'Key-Usage: sign encrypt\n', 'Name-Real: sshyp\n',
|
||||
'Name-Comment: gpg-sshyp-whitelist\n', 'Name-Email: https://github.com/rwinkhart/sshyp\n', 'Expire-Date: 0'])
|
||||
run(['gpg', '-q', '--pinentry-mode', 'loopback', '--batch', '--generate-key', '--passphrase',
|
||||
_quick_unlock_password, f"{home}/.config/sshyp/gpg-gen"])
|
||||
remove(f"{home}/.config/sshyp/gpg-gen")
|
||||
_gpg_id = run(['gpg', '-k'], stdout=PIPE, text=True).stdout.splitlines()[-3].strip()
|
||||
|
||||
# encrypt excluded with the assembly key
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').write(_quick_unlock_password_excluded)
|
||||
encrypt(f"{home}/.config/sshyp/excluded", _shm_folder, _shm_entry, _gpg_id)
|
||||
print(f"\nyour quick-unlock passphrase: {_quick_unlock_password}")
|
||||
|
||||
|
||||
def whitelist_verify(_port, _username_ssh, _ip, _client_device_id):
|
||||
# checks the user's whitelist status and fetches the full gpg key password if possible
|
||||
try:
|
||||
run(['gpg', '--pinentry-mode', 'cancel', '-qd', '--output', '/dev/null',
|
||||
f"{home}/.config/sshyp/lock.gpg"], stderr=DEVNULL, check=True)
|
||||
return False
|
||||
except CalledProcessError:
|
||||
_i, _full_password = 0, ''
|
||||
_server_whitelist = run(['ssh', '-i', f"{home}/.ssh/sshyp", '-p', _port, f"{_username_ssh}@{_ip}",
|
||||
f'python3 -c \'from os import listdir; print(*listdir("/home/{_username_ssh}'
|
||||
f'/.config/sshyp/whitelist"))\''], stdout=PIPE, text=True).stdout.rstrip().split()
|
||||
for _device_id in _server_whitelist:
|
||||
if _device_id == _client_device_id:
|
||||
from getpass import getpass
|
||||
_quick_unlock_password = getpass(prompt='\nquick-unlock passphrase: ')
|
||||
_quick_unlock_password_excluded = \
|
||||
run(['ssh', '-i', f"{home}/.ssh/sshyp", '-p', _port, f"{_username_ssh}@{_ip}",
|
||||
f"gpg --pinentry-mode loopback --passphrase '{_quick_unlock_password}' "
|
||||
f"-qd ~/.config/sshyp/excluded.gpg"], stdout=PIPE, text=True).stdout.rstrip()
|
||||
while _i < len(_quick_unlock_password_excluded):
|
||||
try:
|
||||
_full_password += _quick_unlock_password_excluded[_i]
|
||||
except IndexError:
|
||||
pass
|
||||
try:
|
||||
_full_password += _quick_unlock_password[_i]
|
||||
except IndexError:
|
||||
pass
|
||||
_i += 1
|
||||
break
|
||||
return _full_password
|
||||
|
||||
|
||||
def whitelist_list(): # shows the quick-unlock whitelist status of device ids
|
||||
_whitelisted_ids = listdir(f"{home}/.config/sshyp/whitelist")
|
||||
_device_ids = listdir(f"{home}/.config/sshyp/devices")
|
||||
print('\n\u001b[1mquick-unlock whitelisted device ids:\u001b[0m')
|
||||
for _id in _whitelisted_ids:
|
||||
print(_id)
|
||||
print('\n\u001b[1mother registered device ids:\u001b[0m')
|
||||
for _id in _device_ids:
|
||||
if _id not in _whitelisted_ids:
|
||||
print(_id)
|
||||
print()
|
||||
|
||||
|
||||
def whitelist_manage(): # adds or removes quick-unlock whitelisted device ids
|
||||
if arg_count == 2:
|
||||
whitelist_list()
|
||||
_device_id = input('device id: ')
|
||||
else:
|
||||
_device_id = arguments[2]
|
||||
|
||||
if arguments[1] == 'add':
|
||||
if _device_id in listdir(f"{home}/.config/sshyp/devices"):
|
||||
open(f"{home}/.config/sshyp/whitelist/{_device_id}", 'w').write('')
|
||||
whitelist_list()
|
||||
else:
|
||||
print(f"\n\u001b[38;5;9merror: device id ({_device_id}) is not registered\u001b[0m\n")
|
||||
s_exit(1)
|
||||
|
||||
elif isfile(f"{home}/.config/sshyp/whitelist/{_device_id}"):
|
||||
remove(f"{home}/.config/sshyp/whitelist/{_device_id}")
|
||||
whitelist_list()
|
||||
|
||||
|
||||
def add_entry(): # adds a new entry
|
||||
_shm_folder, _shm_entry = None, None # set to avoid PEP8 warnings
|
||||
if isfile(f"{directory}{entry_name}.gpg"):
|
||||
print(f"\n\u001b[38;5;9merror: entry (/{entry_name}) already exists\u001b[0m\n")
|
||||
s_exit(3)
|
||||
if arguments[2] in ('note', '-n'): # note entry
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(optimized_edit(['', '', '', _notes], None, -1))
|
||||
else: # password entry
|
||||
_username = str(input('username: '))
|
||||
_password = str(input('password: '))
|
||||
_url = str(input('url: '))
|
||||
_add_note = input('add a note to this entry? (y/N) ')
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
if _add_note.lower() == 'y':
|
||||
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
else:
|
||||
_notes = ''
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w')\
|
||||
.writelines(optimized_edit([_password, _username, _url, _notes], None, -1))
|
||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
encrypt(directory + entry_name, _shm_folder, _shm_entry, gpg_id)
|
||||
|
||||
|
||||
def add_folder(): # creates a new folder
|
||||
Path(directory + entry_name).mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||
if not ssh_error:
|
||||
run(['ssh', '-i', f"{home}/.ssh/sshyp", '-p', port, f"{username_ssh}@{ip}",
|
||||
f'python3 -c \'from pathlib import Path; Path("{directory_ssh}{entry_name}")'
|
||||
f'.mkdir(mode=0o700, parents=True, exist_ok=True)\''])
|
||||
|
||||
|
||||
def rename(): # renames an entry or folder
|
||||
from shutil import copy
|
||||
_file = True
|
||||
if not exists(f"{directory}{entry_name}.gpg") and not exists(f"{directory}{entry_name}"):
|
||||
print(f"\n\u001b[38;5;9merror: (/{entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(2)
|
||||
elif not isfile(f"{directory}{entry_name}.gpg"):
|
||||
_file = False
|
||||
_new_name = str(input('new name: ')).strip('/')
|
||||
if _file: # if renaming a file
|
||||
if isfile(f"{directory}{_new_name}.gpg"): # check if the new file already exists
|
||||
print(f"\n\u001b[38;5;9merror: (/{_new_name}) already exists\u001b[0m\n")
|
||||
s_exit(3)
|
||||
if not ssh_error:
|
||||
copy(f"{directory}{entry_name}.gpg", f"{directory}{_new_name}.gpg")
|
||||
else:
|
||||
move(f"{directory}{entry_name}.gpg", f"{directory}{_new_name}.gpg")
|
||||
else: # if renaming a folder
|
||||
if isdir(f"{directory}{_new_name}"): # check if the new folder already exists
|
||||
print(f"\n\u001b[38;5;9merror: (/{_new_name}/) already exists\u001b[0m\n")
|
||||
s_exit(3)
|
||||
if not ssh_error:
|
||||
Path(f"{directory}{_new_name}").mkdir(mode=0o700, parents=True, exist_ok=True)
|
||||
run(['ssh', '-i', f"{home}/.ssh/sshyp", '-p', port, f"{username_ssh}@{ip}",
|
||||
f'python3 -c \'from pathlib import Path; Path("{directory_ssh}{_new_name}")'
|
||||
f'.mkdir(mode=0o700, parents=True, exist_ok=True)\''])
|
||||
else:
|
||||
move(f"{directory}{entry_name}", f"{directory}{_new_name}")
|
||||
if not ssh_error:
|
||||
run(['ssh', '-i', f"{home}/.ssh/sshyp", '-p', port, f"{username_ssh}@{ip}",
|
||||
f'cd /lib/sshyp; python3 -c \'from sshync import delete; delete("{entry_name}", "remotely")\''])
|
||||
|
||||
|
||||
def edit(): # edits the contents of an entry
|
||||
_shm_folder, _shm_entry, _detail, _edit_line = None, None, None, None # set to avoid PEP8 warnings
|
||||
if not isfile(f"{directory}{entry_name}.gpg"):
|
||||
print(f"\n\u001b[38;5;9merror: entry (/{entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(2)
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + entry_name, _shm_folder, _shm_entry)
|
||||
if arguments[2] in ('username', '-u'):
|
||||
_detail, _edit_line = str(input('username: ')), 1
|
||||
elif arguments[2] in ('password', '-p'):
|
||||
_detail, _edit_line = str(input('password: ')), 0
|
||||
elif arguments[2] in ('url', '-l'):
|
||||
_detail, _edit_line = str(input('url: ')), 2
|
||||
if arguments[2] in ('note', '-n'):
|
||||
_edit_line = 2
|
||||
_new_lines = optimized_edit(edit_note(_shm_folder, _shm_entry,
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines()), None, -1)
|
||||
else:
|
||||
_new_lines = optimized_edit(open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), _detail, _edit_line)
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_new_lines)
|
||||
remove(f"{directory}{entry_name}.gpg")
|
||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
encrypt(directory + entry_name, _shm_folder, _shm_entry, gpg_id)
|
||||
|
||||
|
||||
def gen(): # generates a password for a new or an existing entry
|
||||
_username, _url, _notes = None, None, None # set to avoid PEP8 warnings
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
if arg_count == 3 and arguments[2] in ('update', '-u'): # gen update
|
||||
if not isfile(f"{directory}{entry_name}.gpg"):
|
||||
print(f"\n\u001b[38;5;9merror: entry (/{entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(2)
|
||||
determine_decrypt(directory + entry_name, _shm_folder, _shm_entry)
|
||||
_new_lines = optimized_edit(open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), pass_gen(), 0)
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w').writelines(_new_lines)
|
||||
remove(f"{directory}{entry_name}.gpg")
|
||||
elif isfile(f"{directory}{entry_name}.gpg"): # gen
|
||||
print(f"\n\u001b[38;5;9merror: entry (/{entry_name}) already exists\u001b[0m\n")
|
||||
s_exit(3)
|
||||
else:
|
||||
_username = str(input('username: '))
|
||||
_password = pass_gen()
|
||||
_url = str(input('url: '))
|
||||
_add_note = input('add a note to this entry? (y/N) ')
|
||||
if _add_note.lower() == 'y':
|
||||
run([editor, f"{tmp_dir}{_shm_folder}/{_shm_entry}-n"])
|
||||
_notes = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}-n", 'r').read()
|
||||
else:
|
||||
_notes = ''
|
||||
open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'w')\
|
||||
.writelines(optimized_edit([_password, _username, _url, _notes], None, -1))
|
||||
print('\n\u001b[1mentry preview:\u001b[0m')
|
||||
entry_reader(f"{tmp_dir}{_shm_folder}/{_shm_entry}")
|
||||
encrypt(directory + entry_name, _shm_folder, _shm_entry, gpg_id)
|
||||
|
||||
|
||||
def copy_data(): # copies a specified field of an entry to the clipboard
|
||||
from subprocess import Popen
|
||||
if not isfile(f"{directory}{entry_name}.gpg"):
|
||||
print(f"\n\u001b[38;5;9merror: entry (/{entry_name}) does not exist\u001b[0m\n")
|
||||
s_exit(2)
|
||||
_shm_folder, _shm_entry = shm_gen()
|
||||
determine_decrypt(directory + entry_name, _shm_folder, _shm_entry)
|
||||
_copy_line, _index = open(f"{tmp_dir}{_shm_folder}/{_shm_entry}", 'r').readlines(), 0
|
||||
if arguments[2] in ('username', '-u'):
|
||||
_index = 1
|
||||
elif arguments[2] in ('password', '-p'):
|
||||
_index = 0
|
||||
elif arguments[2] in ('url', '-l'):
|
||||
_index = 2
|
||||
elif arguments[2] in ('note', '-n'):
|
||||
_index = 3
|
||||
if 'WAYLAND_DISPLAY' in environ: # Wayland clipboard detection
|
||||
run(['wl-copy', _copy_line[_index].rstrip()])
|
||||
Popen('sleep 30; wl-copy -c', shell=True)
|
||||
elif uname()[0] == 'Haiku': # Haiku clipboard detection
|
||||
run(['clipboard', '-c', _copy_line[_index].rstrip()])
|
||||
Popen('sleep 30; clipboard -r', shell=True)
|
||||
elif exists("/data/data/com.termux"): # Termux (Android) clipboard detection
|
||||
run(['termux-clipboard-set', _copy_line[_index].rstrip()])
|
||||
Popen("sleep 30; termux-clipboard-set ''", shell=True)
|
||||
else: # X11 clipboard detection
|
||||
run(['xclip', '-sel', 'c'], stdin=Popen(['echo', '-n', _copy_line[_index].rstrip()], stdout=PIPE).stdout)
|
||||
Popen("sleep 30; echo -n '' | xclip -sel c", shell=True)
|
||||
rmtree(f"{tmp_dir}{_shm_folder}")
|
||||
|
||||
|
||||
def remove_data(): # deletes an entry from the server and flags it for local deletion on sync
|
||||
determine_decrypt(f"{home}/.config/sshyp/lock.gpg", None, None)
|
||||
if not ssh_error:
|
||||
run(['ssh', '-i', f"{home}/.ssh/sshyp", '-p', port, f"{username_ssh}@{ip}",
|
||||
f'cd /lib/sshyp; python3 -c \'from sshync import delete; delete("{entry_name}", "remotely")\''])
|
||||
else:
|
||||
offline_delete(entry_name, 'locally')
|
||||
|
||||
|
||||
def extension_runner(): # checks extension config files for matches to argument, runs extensions
|
||||
from configparser import ConfigParser
|
||||
_output_com, _extension_dir = None, realpath(__file__).rsplit('/', 1)[0] + '/extensions/'
|
||||
if isdir(_extension_dir):
|
||||
for _extension in listdir(_extension_dir):
|
||||
_extension_config = ConfigParser()
|
||||
_extension_config.read(_extension_dir + _extension)
|
||||
_input_com = _extension_config.get('config', 'input').split()
|
||||
if _input_com == arguments[arg_start:]:
|
||||
_output_com = _extension_config.get('config', 'output').split()
|
||||
if arg_start == 1:
|
||||
_output_com.append(arguments[0])
|
||||
if _output_com is not None:
|
||||
run(_output_com)
|
||||
else:
|
||||
print_info()
|
||||
else:
|
||||
print_info()
|
||||
s_exit()
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
try:
|
||||
ssh_error, success_flag, sync_flag, silent_sync = False, False, False, False
|
||||
arg_start, device_type = None, None # set to avoid PEP8 warnings
|
||||
# retrieve typed argument
|
||||
arguments = argv[1:]
|
||||
arg_count = len(arguments)
|
||||
|
||||
if arg_count < 1 or (arg_count > 0 and arguments[0] != 'tweak'):
|
||||
if arg_count > 0 and arguments[0].startswith('/'):
|
||||
arg_start = 1
|
||||
entry_name = arguments[0].strip('/')
|
||||
else:
|
||||
arg_start = 0
|
||||
|
||||
# import saved userdata
|
||||
tmp_dir = f"{home}/.config/sshyp/tmp/"
|
||||
try:
|
||||
sshyp_data = open(f"{home}/.config/sshyp/sshyp-data").readlines()
|
||||
device_type = sshyp_data[0].rstrip()
|
||||
if device_type == 'client':
|
||||
directory = f"{home}/.local/share/sshyp/"
|
||||
gpg_id = sshyp_data[1].rstrip()
|
||||
editor = sshyp_data[2].rstrip()
|
||||
quick_unlock_enabled = sshyp_data[3].rstrip()
|
||||
if isfile(f"{home}/.config/sshyp/sshyp.sshync"):
|
||||
ssh_info = get_profile(f"{home}/.config/sshyp/sshyp.sshync")
|
||||
username_ssh = ssh_info[0].rstrip()
|
||||
ip = ssh_info[1].rstrip()
|
||||
port = ssh_info[2].rstrip()
|
||||
directory_ssh = str(ssh_info[4].rstrip())
|
||||
client_device_id = listdir(f"{home}/.config/sshyp/devices")[0].rstrip()
|
||||
ssh_error = int(open(f"{home}/.config/sshyp/ssh-error").read().rstrip())
|
||||
if ssh_error == 1:
|
||||
ssh_error = copy_id_check(port, username_ssh, ip, client_device_id)
|
||||
else:
|
||||
ssh_error = False
|
||||
else:
|
||||
ssh_error = True
|
||||
except (FileNotFoundError, IndexError):
|
||||
print('\n!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!')
|
||||
print("not all necessary configuration files are present - please run 'sshyp tweak'")
|
||||
print('!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n')
|
||||
s_exit(1)
|
||||
else:
|
||||
tweak()
|
||||
s_exit()
|
||||
|
||||
# run function based on arguments
|
||||
if device_type == 'client':
|
||||
if arg_count < 1:
|
||||
entry_list_gen()
|
||||
|
||||
elif arg_count == 3 and arg_start == 1:
|
||||
if arguments[1] == 'copy':
|
||||
if arguments[2] in ('username', '-u', 'password', '-p', 'url', '-l', 'note', '-n'):
|
||||
try:
|
||||
success_flag = 1
|
||||
copy_data()
|
||||
except IndexError:
|
||||
print(f"\n\u001b[38;5;9merror: field does not exist in entry\u001b[0m\n")
|
||||
s_exit(2)
|
||||
elif arguments[1] == 'add':
|
||||
if arguments[2] in ('note', '-n', 'password', '-p'):
|
||||
success_flag, sync_flag = True, True
|
||||
add_entry()
|
||||
elif arguments[2] in ('folder', '-f'):
|
||||
success_flag = 1
|
||||
add_folder()
|
||||
elif arguments[1] == 'edit':
|
||||
if arguments[2] in ('rename', 'relocate', '-r'):
|
||||
success_flag, sync_flag, silent_sync = True, True, True
|
||||
rename()
|
||||
elif arguments[2] in ('username', '-u', 'password', '-p', 'url', '-l', 'note', '-n'):
|
||||
success_flag, sync_flag = True, True
|
||||
edit()
|
||||
elif arguments[1] == 'gen' and arguments[2] in ('update', '-u'):
|
||||
success_flag, sync_flag = True, True
|
||||
gen()
|
||||
|
||||
elif arg_count == 2 and arg_start == 1:
|
||||
if arguments[1] == 'gen':
|
||||
success_flag, sync_flag = True, True
|
||||
gen()
|
||||
elif arguments[1] == 'shear':
|
||||
success_flag, sync_flag = True, True
|
||||
remove_data()
|
||||
|
||||
elif arg_count == 1 and arg_start == 1:
|
||||
success_flag = True
|
||||
read_shortcut()
|
||||
|
||||
else: # server arguments
|
||||
if arg_count < 1:
|
||||
arguments.append('help')
|
||||
print_info()
|
||||
elif arg_count > 1 and arguments[0] == 'whitelist':
|
||||
if arguments[1] in ('list', '-l'):
|
||||
success_flag = True
|
||||
whitelist_list()
|
||||
elif arguments[1] in ('add', 'del'):
|
||||
success_flag = True
|
||||
whitelist_manage()
|
||||
elif arguments[1] == 'setup':
|
||||
success_flag = True
|
||||
whitelist_setup()
|
||||
|
||||
if arg_count > 0 and success_flag == 0 and arguments[0] != 'sync':
|
||||
if device_type == 'client' and arguments[0] not in ('help', '-h', 'version', '-v', 'license'):
|
||||
extension_runner()
|
||||
else:
|
||||
print_info()
|
||||
elif (not ssh_error and sync_flag) or (arg_count > 0 and arguments[0] == 'sync'):
|
||||
sync()
|
||||
|
||||
except KeyboardInterrupt:
|
||||
print('\n')
|
||||
+322
-109
@@ -1,125 +1,338 @@
|
||||
#!/bin/bash
|
||||
#!/bin/sh
|
||||
|
||||
# This script packages sshyp (from source) for various Linux environments.
|
||||
|
||||
# NOTE It is recommended to instead use the latest officially packaged and tagged release.
|
||||
# NOTE If using Arch, it is recommended to install from the AUR or from the PKGBUILD attatched to the latest official release.
|
||||
# NOTE As of release fr4, sshync will become a separate package and thus a dependency for sshyp. sshync is automatically installed with the PKGBUILD version.
|
||||
|
||||
echo -e '\nOptions (please enter the number only):'
|
||||
echo -e '\nDistribution Packages:\n\n1. Debian\n2. Termux\n3. Generic (used for PKGBUILD/APKBUILD)'
|
||||
echo -e '\nBuild Scripts:\n\n4. Alpine Linux (APKBUILD)\n5. Arch Linux (PKGBUILD, also builds local generic package)'
|
||||
echo -e '\nOther:\n\n6. All (generates all distribution packages and build scripts)\n'
|
||||
read -n 1 -r -p "Distribution: " distro
|
||||
|
||||
echo -e '\n\nThe value entered in this field will only affect the version reported to the package manager. The latest source is used regardless.\n'
|
||||
read -r -p "Version number: " version
|
||||
|
||||
echo -e '\nThe value entered in this field will only affect the revision number for build scripts.\n'
|
||||
read -r -p "Revision number: " revision
|
||||
|
||||
if [ "$distro" == "4" ] || [ "$distro" == "5" ] || [ "$distro" == "6" ]; then
|
||||
echo -e '\nOptions (please enter the number only):'
|
||||
echo -e '\n1. GitHub Release Tag\n2. Local\n'
|
||||
read -r -p "Source (for build scripts): " source
|
||||
|
||||
if [ "$source" == "1" ]; then
|
||||
source='https://github.com/rwinkhart/sshyp/releases/download/v$pkgver/sshyp-$pkgver.tar.xz'
|
||||
else
|
||||
source=local://sshyp-"$version".tar.xz
|
||||
fi
|
||||
version=$(sed -n '1{p;q}' share/doc/sshyp/changelog | cut -c8-)
|
||||
if [ -z "$2" ]; then
|
||||
revision=1
|
||||
else
|
||||
revision="$2"
|
||||
fi
|
||||
|
||||
mkdir -p packages
|
||||
|
||||
if [ "$distro" == "1" ] || [ "$distro" == "6" ]; then
|
||||
echo -e '\nPackaging for Debian...\n'
|
||||
mkdir -p packages/debiantemp/sshyp_"$version"-"$revision"_all/{DEBIAN,usr}
|
||||
mkdir -p packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1
|
||||
echo "Package: sshyp
|
||||
Version: $version
|
||||
Section: utils
|
||||
Architecture: all
|
||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
Description: A light-weight, self-hosted, synchronized password manager
|
||||
Depends: python3, gnupg, openssh-client, nano, xclip, wl-clipboard
|
||||
Priority: optional
|
||||
Installed-Size: 35
|
||||
" > packages/debiantemp/sshyp_"$version"-"$revision"_all/DEBIAN/control
|
||||
cp -r bin packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/
|
||||
cp -r share packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/
|
||||
cp extra/manpage packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||
gzip packages/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||
dpkg-deb --build --root-owner-group packages/debiantemp/sshyp_"$version"-"$revision"_all/
|
||||
mv packages/debiantemp/sshyp_"$version"-"$revision"_all.deb packages/
|
||||
rm -rf packages/debiantemp
|
||||
echo -e "\nDebian packaging complete.\n"
|
||||
fi
|
||||
|
||||
if [ "$distro" == "2" ] || [ "$distro" == "6" ]; then
|
||||
echo -e '\nPackaging for Termux...\n'
|
||||
mkdir -p packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/{data,DEBIAN}
|
||||
mkdir -p packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1
|
||||
echo "Package: sshyp
|
||||
Version: $version
|
||||
Section: utils
|
||||
Architecture: all
|
||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
Description: A light-weight, self-hosted, synchronized password manager
|
||||
Depends: python, gnupg, openssh, nano, termux-api, termux-am
|
||||
Priority: optional
|
||||
Installed-Size: 35
|
||||
" > packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/DEBIAN/control
|
||||
cp -r bin packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
|
||||
cp -r share packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
|
||||
cp extra/manpage packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||
gzip packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||
dpkg-deb --build --root-owner-group packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux/
|
||||
mv packages/termuxtemp/sshyp_"$version"-"$revision"_all_termux.deb packages/
|
||||
rm -rf packages/termuxtemp
|
||||
echo -e "\nTermux packaging complete.\n"
|
||||
fi
|
||||
|
||||
if [ "$distro" == "3" ] || [ "$distro" == "5" ] || [ "$distro" == "6" ]; then
|
||||
echo -e '\nPackaging as generic...\n'
|
||||
mkdir -p packages/archtemp/usr
|
||||
cp -r bin packages/archtemp/usr/
|
||||
cp -r share packages/archtemp/usr/
|
||||
mkdir -p packages/archtemp/usr/share/man/man1
|
||||
cp extra/manpage packages/archtemp/usr/share/man/man1/sshyp.1
|
||||
gzip packages/archtemp/usr/share/man/man1/sshyp.1
|
||||
tar -C packages/archtemp -cvf packages/sshyp-"$version".tar.xz usr/
|
||||
rm -rf packages/archtemp
|
||||
sha512="$(sha512sum packages/sshyp-"$version".tar.xz | awk '{print $1;}')"
|
||||
echo -e "\nsha512 sum:\n$sha512"
|
||||
echo -e "\nGeneric packaging complete.\n"
|
||||
fi
|
||||
|
||||
if [ "$distro" == "5" ] || [ "$distro" == "6" ]; then
|
||||
echo -e '\nGenerating PKGBUILD...'
|
||||
echo "# Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
_create_generic() {
|
||||
printf '\npackaging as generic...\n'
|
||||
mkdir -p output/generictemp/usr/bin \
|
||||
output/generictemp/usr/lib/sshyp/extensions \
|
||||
output/generictemp/usr/share/man/man1 \
|
||||
output/generictemp/usr/share/bash-completion/completions \
|
||||
output/generictemp/usr/share/zsh/functions/Completion/Unix
|
||||
cp -r lib/. output/generictemp/usr/lib/sshyp/
|
||||
ln -s /usr/lib/sshyp/sshyp.py output/generictemp/usr/bin/sshyp
|
||||
cp -r share output/generictemp/usr/
|
||||
cp extra/completion.bash output/generictemp/usr/share/bash-completion/completions/sshyp
|
||||
cp extra/completion.zsh output/generictemp/usr/share/zsh/functions/Completion/Unix/_sshyp
|
||||
cp extra/manpage output/generictemp/usr/share/man/man1/sshyp.1
|
||||
gzip output/generictemp/usr/share/man/man1/sshyp.1
|
||||
XZ_OPT=-e6 tar -C output/generictemp -cvJf output/GENERIC-sshyp-"$version".tar.xz usr/
|
||||
rm -rf output/generictemp
|
||||
sha512="$(sha512sum output/GENERIC-sshyp-"$version".tar.xz | awk '{print $1;}')"
|
||||
printf '\ngeneric packaging complete\n\n'
|
||||
} &&
|
||||
|
||||
_create_pkgbuild() {
|
||||
local source='https://github.com/rwinkhart/sshyp/releases/download/v$pkgver/GENERIC-sshyp-$pkgver.tar.xz'
|
||||
printf '\ngenerating PKGBUILD...\n'
|
||||
printf "# Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
pkgname=sshyp
|
||||
pkgver="$version"
|
||||
pkgrel="$revision"
|
||||
pkgdesc='A light-weight, self-hosted, synchronized password manager'
|
||||
url='https://github.com/rwinkhart/sshyp'
|
||||
arch=('any')
|
||||
license=('GPL3')
|
||||
depends=(python gnupg openssh nano xclip wl-clipboard)
|
||||
|
||||
license=('GPL-3.0-only')
|
||||
depends=(python gnupg openssh xclip wl-clipboard)
|
||||
optdepends=('bash-completion: bash completion support')
|
||||
source=(\""$source"\")
|
||||
sha512sums=('"$sha512"')
|
||||
|
||||
package() {
|
||||
|
||||
tar xf sshyp-"\"\$pkgver\"".tar.xz -C "\"\${pkgdir}\""
|
||||
|
||||
tar xf GENERIC-sshyp-"\"\$pkgver\"".tar.xz -C "\"\${pkgdir}\""
|
||||
}
|
||||
" > packages/PKGBUILD
|
||||
echo -e "\nPKGBUILD generated.\n"
|
||||
fi
|
||||
" > output/PKGBUILD
|
||||
printf '\nPKGBUILD generated\n\n'
|
||||
} &&
|
||||
|
||||
if [ "$distro" == "4" ]; then
|
||||
echo -e '\nThis packaging format is not yet supported, but will be in the near future!\n'
|
||||
fi
|
||||
_create_apkbuild() {
|
||||
local source='https://github.com/rwinkhart/sshyp/releases/download/v$pkgver/GENERIC-sshyp-$pkgver.tar.xz'
|
||||
printf '\ngenerating APKBUILD...\n'
|
||||
printf "# Maintainer: Randall Winkhart <idgr@tutanota.com>
|
||||
pkgname=sshyp
|
||||
pkgver="$version"
|
||||
pkgrel="$((revision-1))"
|
||||
pkgdesc='A light-weight, self-hosted, synchronized password manager'
|
||||
options=!check
|
||||
url='https://github.com/rwinkhart/sshyp'
|
||||
arch='noarch'
|
||||
license='GPL-3.0-only'
|
||||
depends='python3 gnupg openssh xclip wl-clipboard'
|
||||
source=\""$source"\"
|
||||
|
||||
package() {
|
||||
mkdir -p "\"\$pkgdir\""
|
||||
mkdir -p "\"\$srcdir/usr/share/zsh/site-functions"\"
|
||||
mv "\"\$srcdir/usr/share/zsh/functions/Completion/Unix/_sshyp"\" "\"\$srcdir/usr/share/zsh/site-functions/_sshyp"\"
|
||||
rm -rf "\"\$srcdir/usr/share/zsh/functions"\"
|
||||
cp -r "\"\$srcdir/usr/"\" "\"\$pkgdir\""
|
||||
}
|
||||
|
||||
sha512sums=\"
|
||||
"$sha512' 'GENERIC-sshyp-\"\$pkgver\".tar.xz"
|
||||
\"
|
||||
" > output/APKBUILD
|
||||
printf '\nAPKBUILD generated\n\n'
|
||||
} &&
|
||||
|
||||
_create_hpkg() {
|
||||
printf '\npackaging for Haiku...\n'
|
||||
mkdir -p output/haikutemp/bin \
|
||||
output/haikutemp/lib/sshyp/extensions \
|
||||
output/haikutemp/documentation/packages/sshyp \
|
||||
output/haikutemp/documentation/man/man1 \
|
||||
output/haikutemp/data/bash-completion/completions \
|
||||
output/haikutemp/data/zsh/site-functions
|
||||
printf "name sshyp
|
||||
version "$version"-"$revision"
|
||||
architecture any
|
||||
summary \"A light-weight, self-hosted, synchronized password manager\"
|
||||
description \"sshyp is the only password-store compatible CLI password manager available for Haiku - it is also available on Linux/Android (via Termux) so that you can sync your entries across all of your devices.\"
|
||||
packager \"Randall Winkhart <idgr at tutanota dot com>\"
|
||||
vendor \"Randall Winkhart\"
|
||||
licenses {
|
||||
\"GNU GPL v3\"
|
||||
}
|
||||
copyrights {
|
||||
\"2021-2023 Randall Winkhart\"
|
||||
}
|
||||
provides {
|
||||
sshyp = "$version"
|
||||
cmd:sshyp
|
||||
}
|
||||
requires {
|
||||
gnupg
|
||||
openssh
|
||||
python310
|
||||
}
|
||||
urls {
|
||||
\"https://github.com/rwinkhart/sshyp\"
|
||||
}
|
||||
" > output/haikutemp/.PackageInfo
|
||||
cp -r lib/. output/haikutemp/lib/sshyp/
|
||||
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshync.py
|
||||
sed -i '1 s/.*/#!\/bin\/env\ python3.10/' output/haikutemp/lib/sshyp/sshyp.py
|
||||
ln -s /system/lib/sshyp/sshyp.py output/haikutemp/bin/sshyp
|
||||
cp -r share/doc/sshyp/. output/haikutemp/documentation/packages/sshyp/
|
||||
cp -r share/licenses/sshyp/. output/haikutemp/documentation/packages/sshyp/
|
||||
cp extra/completion.bash output/haikutemp/data/bash-completion/completions/sshyp
|
||||
cp extra/completion.zsh output/haikutemp/data/zsh/site-functions/_sshyp
|
||||
cp extra/manpage output/haikutemp/documentation/man/man1/sshyp.1
|
||||
gzip output/haikutemp/documentation/man/man1/sshyp.1
|
||||
cd output/haikutemp
|
||||
package create -b HAIKU-sshyp-"$version"-"$revision"_all.hpkg
|
||||
package add HAIKU-sshyp-"$version"-"$revision"_all.hpkg bin lib documentation data
|
||||
cd ../..
|
||||
mv output/haikutemp/HAIKU-sshyp-"$version"-"$revision"_all.hpkg output/
|
||||
rm -rf output/haikutemp
|
||||
printf '\nHaiku packaging complete\n\n'
|
||||
} &&
|
||||
|
||||
_create_deb() {
|
||||
printf '\npackaging for Debian/Ubuntu...\n'
|
||||
mkdir -p output/debiantemp/sshyp_"$version"-"$revision"_all/DEBIAN \
|
||||
output/debiantemp/sshyp_"$version"-"$revision"_all/usr/lib/sshyp/extensions \
|
||||
output/debiantemp/sshyp_"$version"-"$revision"_all/usr/bin \
|
||||
output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1 \
|
||||
output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/bash-completion/completions \
|
||||
output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/zsh/functions/Completion/Unix
|
||||
printf "Package: sshyp
|
||||
Version: $version
|
||||
Section: utils
|
||||
Architecture: all
|
||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
Description: A light-weight, self-hosted, synchronized password manager
|
||||
Depends: python3, gnupg, openssh-client, xclip, wl-clipboard
|
||||
Suggests: bash-completion
|
||||
Priority: optional
|
||||
Installed-Size: 14584
|
||||
" > output/debiantemp/sshyp_"$version"-"$revision"_all/DEBIAN/control
|
||||
cp -r lib/. output/debiantemp/sshyp_"$version"-"$revision"_all/usr/lib/sshyp/
|
||||
ln -s /usr/lib/sshyp/sshyp.py output/debiantemp/sshyp_"$version"-"$revision"_all/usr/bin/sshyp
|
||||
cp -r share output/debiantemp/sshyp_"$version"-"$revision"_all/usr/
|
||||
cp extra/completion.bash output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/bash-completion/completions/sshyp
|
||||
cp extra/completion.zsh output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/zsh/functions/Completion/Unix/_sshyp
|
||||
cp extra/manpage output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||
gzip output/debiantemp/sshyp_"$version"-"$revision"_all/usr/share/man/man1/sshyp.1
|
||||
dpkg-deb --build --root-owner-group output/debiantemp/sshyp_"$version"-"$revision"_all/
|
||||
mv output/debiantemp/sshyp_"$version"-"$revision"_all.deb output/DEBIAN-sshyp_"$version"-"$revision"_all.deb
|
||||
rm -rf output/debiantemp
|
||||
printf '\nDebian/Ubuntu packaging complete\n\n'
|
||||
} &&
|
||||
|
||||
_create_termux() {
|
||||
printf '\npackaging for Termux...\n'
|
||||
mkdir -p output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/DEBIAN \
|
||||
output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/lib/sshyp/extensions \
|
||||
output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/bin \
|
||||
output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1 \
|
||||
output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/bash-completion/completions \
|
||||
output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/zsh/functions/Completion/Unix
|
||||
printf "Package: sshyp
|
||||
Version: $version
|
||||
Section: utils
|
||||
Architecture: all
|
||||
Maintainer: Randall Winkhart <idgr at tutanota dot com>
|
||||
Description: A light-weight, self-hosted, synchronized password manager
|
||||
Depends: python, gnupg, openssh, termux-api, termux-am
|
||||
Suggests: bash-completion
|
||||
Priority: optional
|
||||
Installed-Size: 14584
|
||||
" > output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/DEBIAN/control
|
||||
cp -r lib/. output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/lib/sshyp/
|
||||
ln -s /data/data/com.termux/files/usr/lib/sshyp/sshyp.py output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/bin/sshyp
|
||||
cp -r share output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/
|
||||
cp extra/completion.bash output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/bash-completion/completions/sshyp
|
||||
cp extra/completion.zsh output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/zsh/functions/Completion/Unix/_sshyp
|
||||
cp extra/manpage output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||
gzip output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/data/data/com.termux/files/usr/share/man/man1/sshyp.1
|
||||
dpkg-deb --build --root-owner-group output/termuxtemp/sshyp_"$version"-"$revision"_all_termux/
|
||||
mv output/termuxtemp/sshyp_"$version"-"$revision"_all_termux.deb output/TERMUX-sshyp_"$version"-"$revision"_all_termux.deb
|
||||
rm -rf output/termuxtemp
|
||||
printf '\nTermux packaging complete\n\n'
|
||||
} &&
|
||||
|
||||
_create_rpm() {
|
||||
printf '\npackaging for Fedora...\n'
|
||||
rm -rf ~/rpmbuild
|
||||
rpmdev-setuptree
|
||||
cp output/GENERIC-sshyp-"$version".tar.xz ~/rpmbuild/SOURCES
|
||||
printf "Name: sshyp
|
||||
Version: "$version"
|
||||
Release: "$revision"
|
||||
Summary: A light-weight, self-hosted, synchronized password manager
|
||||
BuildArch: noarch
|
||||
License: GPL-3.0-only
|
||||
URL: https://github.com/rwinkhart/sshyp
|
||||
Source0: GENERIC-sshyp-"$version".tar.xz
|
||||
Requires: python gnupg openssh-clients wl-clipboard
|
||||
Recommends: bash-completion
|
||||
%description
|
||||
sshyp is a password-store compatible CLI password manager available for UNIX(-like) systems - its primary goal is to make syncing passwords and notes across devices as easy as possible via CLI.
|
||||
%install
|
||||
tar xf %{_sourcedir}/GENERIC-sshyp-"$version".tar.xz -C %{_sourcedir}
|
||||
cp -r %{_sourcedir}/usr %{buildroot}
|
||||
%files
|
||||
/usr/bin/sshyp
|
||||
/usr/lib/sshyp/sshyp.py
|
||||
/usr/lib/sshyp/sshync.py
|
||||
/usr/share/bash-completion/completions/sshyp
|
||||
/usr/share/zsh/functions/Completion/Unix/_sshyp
|
||||
%license /usr/share/licenses/sshyp/license
|
||||
%doc
|
||||
/usr/share/doc/sshyp/changelog
|
||||
/usr/share/man/man1/sshyp.1.gz
|
||||
" > ~/rpmbuild/SPECS/sshyp.spec
|
||||
rpmbuild -bb ~/rpmbuild/SPECS/sshyp.spec
|
||||
mv ~/rpmbuild/RPMS/noarch/sshyp-"$version"-"$revision".noarch.rpm output/FEDORA-sshyp-"$version"-"$revision".noarch.rpm
|
||||
rm -rf ~/rpmbuild
|
||||
printf '\nFedora packaging complete\n\n'
|
||||
} &&
|
||||
|
||||
_create_freebsd_pkg() {
|
||||
printf '\npackaging for FreeBSD...\n'
|
||||
mkdir -p output/freebsdtemp/usr/lib/sshyp/extensions \
|
||||
output/freebsdtemp/usr/bin \
|
||||
output/freebsdtemp/usr/share/man/man1 \
|
||||
output/freebsdtemp/usr/local/share/bash-completion/completions \
|
||||
output/freebsdtemp/usr/local/share/zsh/site-functions
|
||||
printf "name: sshyp
|
||||
version: \""$version"\"
|
||||
abi = \"FreeBSD:13:*\";
|
||||
arch = \"freebsd:13:*\";
|
||||
origin: security/sshyp
|
||||
comment: \"a password manager\"
|
||||
desc: \"a light-weight, self-hosted, synchronized password manager\"
|
||||
maintainer: <idgr at tutanota dot com>
|
||||
www: https://github.com/rwinkhart/sshyp
|
||||
prefix: /
|
||||
\"deps\" : {
|
||||
\"python\" : {
|
||||
\"origin\" : \"lang/python\"
|
||||
},
|
||||
\"gnupg\" : {
|
||||
\"origin\" : \"security/gnupg\"
|
||||
},
|
||||
\"xclip\" : {
|
||||
\"origin\" : \"x11/xclip\"
|
||||
},
|
||||
\"wl-clipboard\" : {
|
||||
\"origin\" : \"x11/wl-clipboard\"
|
||||
},
|
||||
},
|
||||
" > output/freebsdtemp/+MANIFEST
|
||||
printf "/usr/bin/sshyp
|
||||
/usr/lib/sshyp/sshync.py
|
||||
/usr/lib/sshyp/sshyp.py
|
||||
/usr/local/share/bash-completion/completions/sshyp
|
||||
/usr/local/share/zsh/site-functions/_sshyp
|
||||
/usr/share/doc/sshyp/changelog
|
||||
/usr/share/licenses/sshyp/license
|
||||
/usr/share/man/man1/sshyp.1.gz
|
||||
" > output/freebsdtemp/plist
|
||||
cp -r lib/. output/freebsdtemp/usr/lib/sshyp/
|
||||
ln -s /usr/lib/sshyp/sshyp.py output/freebsdtemp/usr/bin/sshyp
|
||||
cp -r share output/freebsdtemp/usr/
|
||||
cp extra/completion.bash output/freebsdtemp/usr/local/share/bash-completion/completions/sshyp
|
||||
cp extra/completion.zsh output/freebsdtemp/usr/local/share/zsh/site-functions/_sshyp
|
||||
cp extra/manpage output/freebsdtemp/usr/share/man/man1/sshyp.1
|
||||
gzip output/freebsdtemp/usr/share/man/man1/sshyp.1
|
||||
pkg create -m output/freebsdtemp/ -r output/freebsdtemp/ -p output/freebsdtemp/plist -o output/
|
||||
mv output/sshyp-"$version".pkg output/FREEBSD-sshyp-"$version"-"$revision".pkg
|
||||
rm -rf output/freebsdtemp
|
||||
printf '\nFreeBSD packaging complete\n\n'
|
||||
} &&
|
||||
|
||||
case "$1" in
|
||||
generic)
|
||||
_create_generic
|
||||
;;
|
||||
pkgbuild)
|
||||
_create_generic
|
||||
_create_pkgbuild
|
||||
;;
|
||||
apkbuild)
|
||||
_create_generic
|
||||
_create_apkbuild
|
||||
;;
|
||||
haiku)
|
||||
_create_hpkg
|
||||
;;
|
||||
debian)
|
||||
_create_deb
|
||||
;;
|
||||
termux)
|
||||
_create_termux
|
||||
;;
|
||||
fedora)
|
||||
_create_generic
|
||||
_create_rpm
|
||||
;;
|
||||
freebsd)
|
||||
_create_freebsd_pkg
|
||||
;;
|
||||
buildable-arch)
|
||||
_create_generic
|
||||
_create_pkgbuild
|
||||
_create_apkbuild
|
||||
case "$(pacman -Q dpkg)" in
|
||||
dpkg*)
|
||||
_create_deb
|
||||
_create_termux
|
||||
;;
|
||||
esac
|
||||
case "$(pacman -Q freebsd-pkg)" in
|
||||
freebsd-pkg*)
|
||||
_create_freebsd_pkg
|
||||
;;
|
||||
esac
|
||||
;;
|
||||
*)
|
||||
printf '\nusage: package.sh [target] <revision>\n\ntargets:\n mainline: pkgbuild apkbuild haiku fedora debian\n experimental: freebsd termux\n other: buildable-arch\n\n'
|
||||
;;
|
||||
esac
|
||||
|
||||
+11
-47
@@ -1,60 +1,24 @@
|
||||
sshyp 2022.02.16.fr4
|
||||
sshyp v1.4.1
|
||||
|
||||
The High-Tech Shears Update
|
||||
the argumentative agronomist update - patch one
|
||||
|
||||
This release adds in a major feature: multi-client deletion (details below)
|
||||
this release improves sshyp's shell completions by adding zsh support and significantly optimizing and improving Bash support
|
||||
|
||||
Note: This release requires the configuration ("sshyp tweak") to be re-done, as a device name now must be set (for multi-client deletion).
|
||||
user-facing features:
|
||||
|
||||
Features:
|
||||
- zsh completion support
|
||||
^ ensure modern completions are enabled in your ~/.zshrc
|
||||
|
||||
- added multi-client deletion
|
||||
^ this means that when an entry is deleted from one client (and thus the server), if another client that has a copy of the deleted entry tries to sync, instead of re-uploading the deleted entry, it will now also have its entry deleted.
|
||||
^ the current implementation requires a new Python script in addition to sshyp and sshync
|
||||
fixes/optimizations:
|
||||
|
||||
Changes:
|
||||
- Bash completions are now much faster due to the use of recursive globbing
|
||||
- Bash completions have been modified to be functionally similar to the new zsh completions
|
||||
|
||||
- fixed an issue where sshyp would use the wrong SSH key when trying to delete entries from or create folders on the server
|
||||
^ this is a fix that was recently applied to sshync - turns out I made the same mistake in sshyp
|
||||
- deleting folders should now work properly with "sshyp shear" if the directory is entered with a following "/"
|
||||
other notable changes:
|
||||
|
||||
&&
|
||||
|
||||
Planned for next major update (fr5, The sshyp Doing a Split Update):
|
||||
|
||||
sshyp:
|
||||
** sshyp has recieved a major visual overhaul
|
||||
^ this includes the new file list and thematic text art
|
||||
|
||||
sshync:
|
||||
** sshync has been split into a separate package and now has standalone functionality as a backup/syncing utility
|
||||
^ more details will be available in the sshync repo, once it is created
|
||||
|
||||
&&
|
||||
|
||||
Planned for next, next major update (fr6, The Farmer Shearing the sshyp Update):
|
||||
|
||||
** when syncing, a check is made to see if any folders are not on all devices - if the check comes back true, it is corrected (in sshyp)
|
||||
** imporove password generator to guarantee more secure results
|
||||
** enforce permissions on the server-side
|
||||
** allow for copying entire notes (not just first line)
|
||||
** ability to pass entries as arguments for more functions
|
||||
|
||||
&&
|
||||
|
||||
Backlog:
|
||||
|
||||
** create separate gui frontend targetting mobile and desktop Linux
|
||||
** auto-completion on tab (currently unsure of best way to make this work)
|
||||
- some official packages now use more space-efficient compression
|
||||
|
||||
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
|
||||
|
||||
The full history of changes to "sshyp" can be found on the following page:
|
||||
https://raw.githubusercontent.com/rwinkhart/sshyp/main/extra/changelog-total
|
||||
|
||||
Legend:
|
||||
|
||||
** = feature/change not yet finished/implemented
|
||||
- = feature/change implemented and pushed upstream
|
||||
^ = note regarding the above feature/change
|
||||
&& = visual separater for patch notes for different planned major version releases
|
||||
|
||||
Executable → Regular
+5
-6
@@ -1,10 +1,9 @@
|
||||
sshyp is a FOSS password manager that takes advantage of rsync
|
||||
Copyright (C) 2021 Randall Winkhart idgr@tutanota.com
|
||||
sshyp is a FOSS password manager that uses an sftp-based syncing back-end.
|
||||
Copyright (C) 2021-2023 Randall Winkhart idgr@tutanota.com
|
||||
|
||||
This program is free software: you can redistribute it and/or modify
|
||||
it under the terms of the GNU General Public License as published by
|
||||
the Free Software Foundation, either version 3 of the License, or
|
||||
(at your option) any later version.
|
||||
it under the terms of version 3 (only) of the GNU General Public License
|
||||
as published by the Free Software Foundation.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
@@ -12,4 +11,4 @@
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
Reference in New Issue
Block a user