diff options
Diffstat (limited to 'scripts/cmail-setup-finish.sh')
| -rwxr-xr-x | scripts/cmail-setup-finish.sh | 12 |
1 files changed, 10 insertions, 2 deletions
diff --git a/scripts/cmail-setup-finish.sh b/scripts/cmail-setup-finish.sh index 7f9d3fc..949023f 100755 --- a/scripts/cmail-setup-finish.sh +++ b/scripts/cmail-setup-finish.sh @@ -30,6 +30,15 @@ err() { printf 'error: %s\n' "$*" >&2; exit 1; } info() { printf '==> %s\n' "$*"; } ok() { printf ' %s\n' "$*"; } +# Decrypt $1 to $2 with 0600 from the moment of creation. gpg writes its output +# at the process umask (often 0644), so a bare decrypt leaves the plaintext +# world-readable until the chmod on the next line. The 0077 umask subshell closes +# that window; the chmod stays to tighten a looser file left by an earlier run. +decrypt_to_secure() { + ( umask 077; gpg --quiet --yes --decrypt --output "$2" "$1" ) + chmod 600 "$2" +} + # 1. Pre-reqs command -v protonmail-bridge >/dev/null 2>&1 \ || err "protonmail-bridge not found in PATH — install via archsetup first" @@ -49,8 +58,7 @@ cmailpass_enc="$HOME/.config/.cmailpass.gpg" # 2. Decrypt cmailpass info "decrypting $cmailpass_enc" cmailpass_plain="$HOME/.config/.cmailpass" -gpg --quiet --yes --decrypt --output "$cmailpass_plain" "$cmailpass_enc" -chmod 600 "$cmailpass_plain" +decrypt_to_secure "$cmailpass_enc" "$cmailpass_plain" ok "wrote $cmailpass_plain (mode 0600)" # 3. Bridge cert |
