joao/internal/op-client/cli.go

140 lines
3.4 KiB
Go
Raw Normal View History

2022-11-16 08:17:07 +00:00
// Copyright © 2022 Roberto Hidalgo <joao@un.rob.mx>
2022-12-31 06:14:08 +00:00
// SPDX-License-Identifier: Apache-2.0
2022-12-14 05:41:03 +00:00
package opclient
2022-11-16 08:17:07 +00:00
import (
"bytes"
"encoding/json"
"fmt"
"os"
"os/exec"
2022-12-14 05:41:03 +00:00
"strings"
2022-11-16 08:17:07 +00:00
op "github.com/1Password/connect-sdk-go/onepassword"
2022-12-14 05:41:03 +00:00
"github.com/alessio/shellescape"
"github.com/sirupsen/logrus"
2022-11-16 08:17:07 +00:00
)
2022-12-18 18:16:46 +00:00
type CLI struct {
DryRun bool // Won't write to 1Password
}
2022-11-16 08:17:07 +00:00
2022-12-14 05:41:03 +00:00
func invoke(vault string, args ...string) (bytes.Buffer, error) {
if vault != "" {
args = append([]string{"--vault", shellescape.Quote(vault)}, args...)
}
2022-12-17 05:40:43 +00:00
argString := ""
for _, arg := range args {
parts := strings.Split(arg, "]=")
if strings.HasSuffix(parts[0], "[password") {
parts[1] = "*****"
argString += fmt.Sprintf("%s]=%v", parts[0], parts[1])
} else {
argString += " " + arg
}
}
logrus.Debugf("invoking op with args: %s", argString)
2022-12-14 05:41:03 +00:00
cmd := exec.Command("op", args...)
2022-11-16 08:17:07 +00:00
cmd.Env = os.Environ()
var stdout bytes.Buffer
cmd.Stdout = &stdout
var stderr bytes.Buffer
cmd.Stderr = &stderr
if err := cmd.Run(); err != nil {
2022-12-20 05:49:37 +00:00
return stderr, fmt.Errorf("op exited with %s:\n%s", err, stderr.Bytes())
2022-11-16 08:17:07 +00:00
}
if cmd.ProcessState.ExitCode() > 0 {
2022-12-14 05:41:03 +00:00
return stderr, fmt.Errorf("op exited with %d: %s", cmd.ProcessState.ExitCode(), stderr.Bytes())
}
return stdout, nil
}
func (b *CLI) Get(vault, name string) (*op.Item, error) {
stdout, err := invoke(vault, "item", "--format", "json", "get", name)
if err != nil {
return nil, err
2022-11-16 08:17:07 +00:00
}
var item *op.Item
if err := json.Unmarshal(stdout.Bytes(), &item); err != nil {
return nil, err
}
return item, nil
}
2022-12-18 18:16:46 +00:00
func (b *CLI) Create(item *op.Item) error {
2022-12-14 05:41:03 +00:00
logrus.Infof("Creating new item: %s/%s", item.Vault.ID, item.Title)
2022-12-18 18:16:46 +00:00
cmd := exec.Command("op", "--vault", shellescape.Quote(item.Vault.ID), "item", "create") // nolint: gosec
2022-12-14 05:41:03 +00:00
itemJSON, err := json.Marshal(item)
if err != nil {
return fmt.Errorf("could not serialize op item into json: %w", err)
}
cmd.Stdin = bytes.NewBuffer(itemJSON)
cmd.Env = os.Environ()
var stdout bytes.Buffer
cmd.Stdout = &stdout
var stderr bytes.Buffer
cmd.Stderr = &stderr
2022-12-18 18:16:46 +00:00
if b.DryRun {
logrus.Warnf("dry-run: Would have invoked %v", cmd.Args)
return nil
}
2022-12-14 05:41:03 +00:00
if err := cmd.Run(); err != nil {
return fmt.Errorf("could not create item: %w", err)
}
if cmd.ProcessState.ExitCode() > 0 {
return fmt.Errorf("op exited with %d: %s", cmd.ProcessState.ExitCode(), stderr.Bytes())
}
logrus.Infof("Item %s/%s created", item.Vault.ID, item.Title)
return nil
}
2022-12-18 18:16:46 +00:00
func (b *CLI) Update(item *op.Item, remote *op.Item) error {
args := []string{"item", "edit", item.Title, "--"}
2022-12-17 05:40:43 +00:00
localKeys := map[string]int{}
2022-12-14 05:41:03 +00:00
for _, field := range item.Fields {
2022-12-17 05:40:43 +00:00
kind := ""
if field.Type == "CONCEALED" {
kind = "password"
} else {
2022-12-14 05:41:03 +00:00
kind = "text"
}
2022-12-17 05:40:43 +00:00
keyName := keyForField(field)
key := fmt.Sprintf("%s[%s]", keyName, kind)
2022-12-14 05:41:03 +00:00
args = append(args, fmt.Sprintf("%s=%s", key, field.Value))
2022-12-17 05:40:43 +00:00
localKeys[keyName] = 1
}
for _, field := range remote.Fields {
key := keyForField(field)
if _, exists := localKeys[key]; !exists {
logrus.Debugf("Deleting remote key %s", key)
args = append(args, key+"[delete]=")
}
2022-12-14 05:41:03 +00:00
}
2022-12-18 18:16:46 +00:00
if b.DryRun {
logrus.Warnf("dry-run: Would have invoked op %v", args)
return nil
}
stdout, err := invoke(item.Vault.ID, args...)
2022-12-14 05:41:03 +00:00
if err != nil {
logrus.Errorf("op stderr: %s", stdout.String())
return err
}
logrus.Infof("Item %s/%s updated", item.Vault.ID, item.Title)
2022-11-16 08:17:07 +00:00
return nil
}
func (b *CLI) List(vault, prefix string) ([]string, error) {
return nil, nil
}