fix(seo-data): re-assert store dir 0700, chmod lock, drop dead import
This commit is contained in:
@@ -25,6 +25,8 @@ has "list shows a property" "$LIST" 'sc-domain:a.com'
|
|||||||
hasnt "list redacts refresh tokens" "$LIST" 'RT_AAA'
|
hasnt "list redacts refresh tokens" "$LIST" 'RT_AAA'
|
||||||
PERM="$(stat -c '%a' "$STORE")"
|
PERM="$(stat -c '%a' "$STORE")"
|
||||||
[ "$PERM" = "600" ] && ok "store file is 0600" || no "store file 0600" "got $PERM"
|
[ "$PERM" = "600" ] && ok "store file is 0600" || no "store file 0600" "got $PERM"
|
||||||
|
DPERM="$(stat -c '%a' "$(dirname "$STORE")")"
|
||||||
|
[ "$DPERM" = "700" ] && ok "store dir is 0700" || no "store dir 0700" "got $DPERM"
|
||||||
rm -rf "$TMP"
|
rm -rf "$TMP"
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env python3
|
#!/usr/bin/env python3
|
||||||
"""Label-keyed OAuth refresh-token store. Atomic writes under an fcntl lock.
|
"""Label-keyed OAuth refresh-token store. Atomic writes under an fcntl lock.
|
||||||
No third-party deps — must run without the venv (used by the offline test path)."""
|
No third-party deps — must run without the venv (used by the offline test path)."""
|
||||||
import argparse, fcntl, json, os, sys, tempfile
|
import argparse, fcntl, json, os, tempfile
|
||||||
from datetime import datetime, timezone
|
from datetime import datetime, timezone
|
||||||
|
|
||||||
def load(path):
|
def load(path):
|
||||||
@@ -22,9 +22,12 @@ def get_refresh_token(path, label):
|
|||||||
return load(path).get("accounts", {}).get(label, {}).get("refresh_token")
|
return load(path).get("accounts", {}).get(label, {}).get("refresh_token")
|
||||||
|
|
||||||
def save_account(path, label, refresh_token, scopes, properties):
|
def save_account(path, label, refresh_token, scopes, properties):
|
||||||
os.makedirs(os.path.dirname(path), mode=0o700, exist_ok=True)
|
dirpath = os.path.dirname(path) or "."
|
||||||
|
os.makedirs(dirpath, mode=0o700, exist_ok=True)
|
||||||
|
os.chmod(dirpath, 0o700) # re-assert invariant (makedirs no-ops if dir exists)
|
||||||
lock_path = path + ".lock"
|
lock_path = path + ".lock"
|
||||||
with open(lock_path, "w") as lock:
|
with open(lock_path, "w") as lock:
|
||||||
|
os.chmod(lock_path, 0o600) # defense-in-depth (empty flock handle, never holds token)
|
||||||
fcntl.flock(lock, fcntl.LOCK_EX) # serialize concurrent connects
|
fcntl.flock(lock, fcntl.LOCK_EX) # serialize concurrent connects
|
||||||
data = load(path)
|
data = load(path)
|
||||||
data.setdefault("version", 1)
|
data.setdefault("version", 1)
|
||||||
@@ -35,7 +38,7 @@ def save_account(path, label, refresh_token, scopes, properties):
|
|||||||
"granted_at": datetime.now(timezone.utc).isoformat(),
|
"granted_at": datetime.now(timezone.utc).isoformat(),
|
||||||
"properties": properties,
|
"properties": properties,
|
||||||
}
|
}
|
||||||
fd, tmp = tempfile.mkstemp(dir=os.path.dirname(path), suffix=".tmp")
|
fd, tmp = tempfile.mkstemp(dir=dirpath, suffix=".tmp")
|
||||||
try:
|
try:
|
||||||
with os.fdopen(fd, "w", encoding="utf-8") as f:
|
with os.fdopen(fd, "w", encoding="utf-8") as f:
|
||||||
json.dump(data, f, indent=2)
|
json.dump(data, f, indent=2)
|
||||||
|
|||||||
Reference in New Issue
Block a user