core/adapters/security.adapter.ts

core/adapters/security.adapter.ts is a file in Bane's Lab Build Scripts. 63 lines of code and 7 definitions.

import {
    GPGCONF_BINARY,
    GPG_BINARY,
    OPENPGP_HOME_PREFIX,
    VAULT_KEY_ENCODING,
} from "#configuration/constants/security.constants";
import { mkdtempSync, rmSync } from "node:fs";
import { Buffer } from "node:buffer";
import type { SignedText } from "#types/site.types";
import { execFileSync } from "node:child_process";
import { isRecord } from "#core/selectors/base.selector";
import { join } from "node:path";
import { signingFailed } from "#configuration/strings/site.strings";
import { tmpdir } from "node:os";

const withHome = function withHome<T>(work: (home: string) => T): T {
    const home = mkdtempSync(join(tmpdir(), OPENPGP_HOME_PREFIX));
    try {
        return work(home);
    } finally {
        execFileSync(GPGCONF_BINARY, ["--homedir", home, "--kill", "all"], { stdio: "ignore" });
        rmSync(home, { force: true, recursive: true });
    }
};

const gpgArguments = function gpgArguments(home: string, args: readonly string[]): string[] {
    return ["--homedir", home, "--batch", "--quiet", ...args];
};

const importKey = function importKey(home: string, key: Buffer | string): void {
    try {
        execFileSync(GPG_BINARY, gpgArguments(home, ["--import"]), { input: key, stdio: ["pipe", "ignore", "pipe"] });
    } catch (error: unknown) {
        throw new Error(signingFailed("import"), { cause: error });
    }
};

const gpgOutput = function gpgOutput(home: string, step: string, args: readonly string[], input: string): string {
    try {
        return execFileSync(GPG_BINARY, gpgArguments(home, args), { encoding: "utf8", input, stdio: "pipe" });
    } catch (error: unknown) {
        throw new Error(signingFailed(step), { cause: error });
    }
};

export const signText = function signText(encodedKey: string, text: string): SignedText {
    return withHome((home) => {
        importKey(home, Buffer.from(encodedKey, VAULT_KEY_ENCODING));
        return {
            publicKey: gpgOutput(home, "export", ["--armor", "--export"], ""),
            signed: gpgOutput(home, "clearsign", ["--clearsign"], text),
        };
    });
};

export const isSignedBy = function isSignedBy(publicKey: string, signed: string): boolean {
    return withHome((home) => {
        importKey(home, publicKey);
        try {
            execFileSync(GPG_BINARY, gpgArguments(home, ["--verify"]), { input: signed, stdio: ["pipe", "ignore", "ignore"] });
            return true;
        } catch (error: unknown) {
            if (isRecord(error) && typeof error["status"] === "number") {
                return false;
            }
            throw new Error(signingFailed("verify"), { cause: error });
        }
    });
};