forked from bitcoinafterlife/bal-server
- .gitignore: Add protection for .env, *.pem, *.key, private_key.pem, privkey.pem, ec.key, chiave_privata.key, and shell scripts bal-*.sh - make_release.sh: Remove hardcoded token 5cfa8c33e337ebaadb355c0ffa2d053d521ee43b Add loading from .env file with GITEA_API_TOKEN variable Add error handling if token is not set (prevents script from running without proper authentication) - .env.example: Add template file for Gitea API token setup (not committed to git, .gitignored) - generate_keys.sh: Add chmod 600 to protect private_key.pem permissions - contrib/download_and_install_bal.sh: Remove hardcoded xpub and fixed_fee. Make all settings required as arguments or environment variables (xpub, fixed_fee, willexecutor_url, email, info) Add proper error handling and usage instructions if required arguments are not provided - tests/secret_leakage_tests.rs: Add regression tests that: * Verify .gitignore protects .env, .pem, .key files * Verify no private key files are tracked in git (only public_key.pem is allowed) * Scan shell scripts for potential hardcoded tokens - All tests pass: cargo test (8 tests: 3 SQL injection + 2 panic regression + 3 secret leakage) - Build verified: cargo check (0 errors)
9 lines
335 B
Bash
9 lines
335 B
Bash
openssl pkey -in private_key.pem -pubout -out public_key.pem
|
|
chmod 600 private_key.pem
|
|
# Ensure private key is not accidentally committed to git
|
|
if grep -q "private_key.pem" .gitignore 2>/dev/null; then
|
|
echo "private_key.pem is already protected by .gitignore"
|
|
else
|
|
echo "WARNING: private_key.pem may not be in .gitignore!"
|
|
fi
|