aboutsummaryrefslogtreecommitdiff
path: root/scripts
diff options
context:
space:
mode:
Diffstat (limited to 'scripts')
-rwxr-xr-xscripts/cmail-setup-finish.sh12
1 files changed, 10 insertions, 2 deletions
diff --git a/scripts/cmail-setup-finish.sh b/scripts/cmail-setup-finish.sh
index 7f9d3fc..949023f 100755
--- a/scripts/cmail-setup-finish.sh
+++ b/scripts/cmail-setup-finish.sh
@@ -30,6 +30,15 @@ err() { printf 'error: %s\n' "$*" >&2; exit 1; }
info() { printf '==> %s\n' "$*"; }
ok() { printf ' %s\n' "$*"; }
+# Decrypt $1 to $2 with 0600 from the moment of creation. gpg writes its output
+# at the process umask (often 0644), so a bare decrypt leaves the plaintext
+# world-readable until the chmod on the next line. The 0077 umask subshell closes
+# that window; the chmod stays to tighten a looser file left by an earlier run.
+decrypt_to_secure() {
+ ( umask 077; gpg --quiet --yes --decrypt --output "$2" "$1" )
+ chmod 600 "$2"
+}
+
# 1. Pre-reqs
command -v protonmail-bridge >/dev/null 2>&1 \
|| err "protonmail-bridge not found in PATH — install via archsetup first"
@@ -49,8 +58,7 @@ cmailpass_enc="$HOME/.config/.cmailpass.gpg"
# 2. Decrypt cmailpass
info "decrypting $cmailpass_enc"
cmailpass_plain="$HOME/.config/.cmailpass"
-gpg --quiet --yes --decrypt --output "$cmailpass_plain" "$cmailpass_enc"
-chmod 600 "$cmailpass_plain"
+decrypt_to_secure "$cmailpass_enc" "$cmailpass_plain"
ok "wrote $cmailpass_plain (mode 0600)"
# 3. Bridge cert