This repository has been archived by the owner on Jan 13, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathenv.go
97 lines (77 loc) · 1.83 KB
/
env.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
package secrets
import (
"encoding/base64"
"errors"
"fmt"
"os"
"regexp"
"strings"
)
// implements env storage for secret config
type EnvSecretProvider struct {
GenericConfig
}
func NewEnvSecretProviderFromConfig(cfg GenericConfig) *EnvSecretProvider {
return &EnvSecretProvider{
GenericConfig: cfg,
}
}
var _ SecretStorage = &EnvSecretProvider{}
func (fp *EnvSecretProvider) SetSecret(name string, secret []byte) error {
if strings.Contains(name, "$") {
return errors.New("ENV secrets cannot contain $")
}
name = invalidNameChars.ReplaceAllString(name, "_")
var b []byte
if fp.Base64 {
b = make([]byte, fp.encoder().EncodedLen(len(secret)))
fp.encoder().Encode(b, secret)
} else {
b = make([]byte, len(secret))
copy(b, secret)
}
if err := os.Setenv(name, string(b)); err != nil {
return fmt.Errorf("setenv: %w", err)
}
return nil
}
var invalidNameChars = regexp.MustCompile(`[^\w\d-]`)
func (fp *EnvSecretProvider) GetSecret(name string) (secret []byte, err error) {
var b []byte
if strings.Contains(name, "$") {
b = []byte(os.ExpandEnv(name))
} else {
name = invalidNameChars.ReplaceAllString(name, "_")
b = []byte(os.Getenv(name))
}
_, present := os.LookupEnv(name)
if !present {
return nil, ErrNotFound
}
var result []byte
if fp.Base64 {
result = make([]byte, fp.encoder().DecodedLen(len(b)))
written, err := fp.encoder().Decode(result, b)
if err != nil {
return nil, fmt.Errorf("base64 decoding %q: %w", name, err)
}
result = result[:written]
return result, nil
}
return b, nil
}
func (fp *EnvSecretProvider) encoder() *base64.Encoding {
if fp.Base64URLEncoded {
if fp.Base64Raw {
return base64.RawURLEncoding
} else {
return base64.URLEncoding
}
} else { // std encoding
if fp.Base64Raw {
return base64.RawStdEncoding
} else {
return base64.StdEncoding
}
}
}