| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent 7a7c9fd commit 91ffb8e
2 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -93,6 +93,8 @@ Only one of ``private_token``, ``oauth_token`` or ``job_token`` should be | |||
| 93 | 93 | defined. If neither are defined an anonymous request will be sent to the Gitlab | |
| 94 | 94 | server, with very limited permissions. | |
| 95 | 95 | ||
| 96 | + We recommend that you use `Credential helpers`_ to securely store your tokens. | ||
| 97 | + | ||
| 96 | 98 | .. list-table:: GitLab server options | |
| 97 | 99 | :header-rows: 1 | |
| 98 | 100 | ||
@@ -119,22 +121,50 @@ server, with very limited permissions. | |||
| 119 | 121 | * - ``http_password`` | |
| 120 | 122 | - Password for optional HTTP authentication | |
| 121 | 123 | ||
| 122 | - For all settings, which contain secrets (``http_password``, | ||
| 124 | + | ||
| 125 | + Credential helpers | ||
| 126 | + ------------------ | ||
| 127 | + | ||
| 128 | + For all configuration options that contain secrets (``http_password``, | ||
| 123 | 129 | ``personal_token``, ``oauth_token``, ``job_token``), you can specify | |
| 124 | - a helper program to retrieve the secret indicated by ``helper:`` | ||
| 125 | - prefix. You can only specify a path to a program without any | ||
| 126 | - parameters. You may use ``~`` for expanding your homedir in helper | ||
| 127 | - program's path. It is expected, that the program prints the secret | ||
| 128 | - to standard output. | ||
| 130 | + a helper program to retrieve the secret indicated by a ``helper:`` | ||
| 131 | + prefix. This allows you to fetch values from a local keyring store | ||
| 132 | + or cloud-hosted vaults such as Bitwarden. Environment variables are | ||
| 133 | + expanded if they exist and ``~`` expands to your home directory. | ||
| 134 | + | ||
| 135 | + It is expected that the helper program prints the secret to standard output. | ||
| 136 | + To use shell features such as piping to retrieve the value, you will need | ||
| 137 | + to use a wrapper script; see below. | ||
| 129 | 138 | ||
| 130 | 139 | Example for a `keyring <https://github.com/jaraco/keyring>`_ helper: | |
| 131 | 140 | ||
| 132 | - .. code-block:: bash | ||
| 141 | + .. code-block:: ini | ||
| 133 | 142 | ||
| 134 | - #!/bin/bash | ||
| 135 | - keyring get Service Username | ||
| 143 | + [global] | ||
| 144 | + default = somewhere | ||
| 145 | + ssl_verify = true | ||
| 146 | + timeout = 5 | ||
| 147 | + | ||
| 148 | + [somewhere] | ||
| 149 | + url = http://somewhe.re | ||
| 150 | + private_token = helper: keyring get Service Username | ||
| 151 | + timeout = 1 | ||
| 152 | + | ||
| 153 | + Example for a `pass <https://www.passwordstore.org>`_ helper with a wrapper script: | ||
| 154 | + | ||
| 155 | + .. code-block:: ini | ||
| 156 | + | ||
| 157 | + [global] | ||
| 158 | + default = somewhere | ||
| 159 | + ssl_verify = true | ||
| 160 | + timeout = 5 | ||
| 161 | + | ||
| 162 | + [somewhere] | ||
| 163 | + url = http://somewhe.re | ||
| 164 | + private_token = helper: /path/to/helper.sh | ||
| 165 | + timeout = 1 | ||
| 136 | 166 | ||
| 137 | - Example for a `pass <https://www.passwordstore.org>`_ helper: | ||
| 167 | + In `/path/to/helper.sh`: | ||
| 138 | 168 | ||
| 139 | 169 | .. code-block:: bash | |
| 140 | 170 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -17,9 +17,10 @@ | |||
| 17 | 17 | ||
| 18 | 18 | import os | |
| 19 | 19 | import configparser | |
| 20 | + import shlex | ||
| 20 | 21 | import subprocess | |
| 21 | 22 | from typing import List, Optional, Union | |
| 22 | - from os.path import expanduser | ||
| 23 | + from os.path import expanduser, expandvars | ||
| 23 | 24 | ||
| 24 | 25 | from gitlab.const import USER_AGENT | |
| 25 | 26 | ||
@@ -56,6 +57,10 @@ class GitlabConfigMissingError(ConfigError): | |||
| 56 | 57 | pass | |
| 57 | 58 | ||
| 58 | 59 | ||
| 60 | + class GitlabConfigHelperError(ConfigError): | ||
| 61 | + pass | ||
| 62 | + | ||
| 63 | + | ||
| 59 | 64 | class GitlabConfigParser(object): | |
| 60 | 65 | def __init__( | |
| 61 | 66 | self, gitlab_id: Optional[str] = None, config_files: Optional[List[str]] = None | |
@@ -202,13 +207,29 @@ def __init__( | |||
| 202 | 207 | pass | |
| 203 | 208 | ||
| 204 | 209 | def _get_values_from_helper(self): | |
| 205 | - """Update attributes, which may get values from an external helper program""" | ||
| 210 | + """Update attributes that may get values from an external helper program""" | ||
| 206 | 211 | for attr in HELPER_ATTRIBUTES: | |
| 207 | 212 | value = getattr(self, attr) | |
| 208 | 213 | if not isinstance(value, str): | |
| 209 | 214 | continue | |
| 210 | 215 | ||
| 211 | - if value.lower().strip().startswith(HELPER_PREFIX): | ||
| 212 | - helper = expanduser(value[len(HELPER_PREFIX) :].strip()) | ||
| 213 | - value = subprocess.check_output([helper]).decode("utf-8").strip() | ||
| 214 | - setattr(self, attr, value) | ||
| 216 | + if not value.lower().strip().startswith(HELPER_PREFIX): | ||
| 217 | + continue | ||
| 218 | + | ||
| 219 | + helper = value[len(HELPER_PREFIX) :].strip() | ||
| 220 | + commmand = [expanduser(expandvars(token)) for token in shlex.split(helper)] | ||
| 221 | + | ||
| 222 | + try: | ||
| 223 | + value = ( | ||
| 224 | + subprocess.check_output(commmand, stderr=subprocess.PIPE) | ||
| 225 | + .decode("utf-8") | ||
| 226 | + .strip() | ||
| 227 | + ) | ||
| 228 | + except subprocess.CalledProcessError as e: | ||
| 229 | + stderr = e.stderr.decode().strip() | ||
| 230 | + raise GitlabConfigHelperError( | ||
| 231 | + f"Failed to read {attr} value from helper " | ||
| 232 | + f"for {self.gitlab_id}:\n{stderr}" | ||
| 233 | + ) from e | ||
| 234 | + | ||
| 235 | + setattr(self, attr, value) | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments