feat(notfiles): hexagonal architecture refactor with adapters, integration tests, and notsecrets cleanup
Some checks failed
Public Repo Readiness / Check Public Repo Readiness (push) Has been cancelled
Some checks failed
Public Repo Readiness / Check Public Repo Readiness (push) Has been cancelled
- Extract FileStore port and InMemoryFileStore/FileStoreImpl/Reporter adapters - Add Reporter trait to notcore with TerminalReporter and JsonReporter - Refactor linker, package, status modules to use FileStore port - Add integration test suite with dotfiles fixtures - Add cross-crate integration tests - Remove ssh_rsa identity/recipient (unsupported) - Add rustqual.toml, .sccignore, notfiles.toml config files - Update CLAUDE.md, README.md, AGENTS.md with current architecture
This commit is contained in:
@@ -10,9 +10,6 @@ pub use ssh_ed25519::SshEd25519Recipient;
|
||||
pub mod scrypt;
|
||||
pub use scrypt::ScryptRecipient;
|
||||
|
||||
pub mod ssh_rsa;
|
||||
pub use ssh_rsa::SshRsaRecipient;
|
||||
|
||||
/// Domain port: a recipient that can wrap a file key into a stanza.
|
||||
pub trait Recipient {
|
||||
fn wrap_file_key(&self, file_key: &FileKey) -> Result<Stanza, AgeError>;
|
||||
|
||||
@@ -1,38 +0,0 @@
|
||||
use crate::error::AgeError;
|
||||
use crate::identities::ssh_rsa::rsa_pubkey_fingerprint;
|
||||
use crate::identities::{FileKey, Stanza};
|
||||
use crate::recipients::Recipient;
|
||||
use base64::{Engine, engine::general_purpose::STANDARD_NO_PAD};
|
||||
use rsa::{Oaep, RsaPublicKey};
|
||||
use sha2::Sha256;
|
||||
|
||||
const TAG: &str = "ssh-rsa";
|
||||
|
||||
pub struct SshRsaRecipient {
|
||||
public_key: RsaPublicKey,
|
||||
}
|
||||
|
||||
impl SshRsaRecipient {
|
||||
pub fn from_public_key(public_key: RsaPublicKey) -> Self {
|
||||
Self { public_key }
|
||||
}
|
||||
}
|
||||
|
||||
impl Recipient for SshRsaRecipient {
|
||||
fn wrap_file_key(&self, file_key: &FileKey) -> Result<Stanza, AgeError> {
|
||||
use rand::rngs::OsRng;
|
||||
let padding = Oaep::new::<Sha256>();
|
||||
let wrapped = self
|
||||
.public_key
|
||||
.encrypt(&mut OsRng, padding, file_key.as_bytes())
|
||||
.map_err(|_| AgeError::CryptoError("RSA-OAEP encrypt failed".to_string()))?;
|
||||
|
||||
let fingerprint = rsa_pubkey_fingerprint(&self.public_key);
|
||||
|
||||
Ok(Stanza {
|
||||
tag: TAG.to_string(),
|
||||
args: vec![STANDARD_NO_PAD.encode(fingerprint)],
|
||||
body: wrapped,
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user