mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-09 04:40:45 +08:00
Add decrypt-to-unlock local admin via sealed env box.
Replace auto-grant-on-env with AES-GCM box + passphrase unlock, rebuild fallback sessions after restart, and document seal script usage. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
922abaa89e
commit
c26dc68f77
10 changed files with 583 additions and 44 deletions
25
uds-auth/scripts/seal-local-admin.mjs
Normal file
25
uds-auth/scripts/seal-local-admin.mjs
Normal file
|
|
@ -0,0 +1,25 @@
|
|||
#!/usr/bin/env node
|
||||
/**
|
||||
* Generate UDS_AUTH_LOCAL_ADMIN_BOX for local decrypt-to-unlock admin.
|
||||
*
|
||||
* Usage:
|
||||
* node scripts/seal-local-admin.mjs "your-passphrase-here"
|
||||
*
|
||||
* Then set the printed env on the Harness process (keep the passphrase offline).
|
||||
*/
|
||||
import { sealLocalAdminBox, LOCAL_ADMIN_BOX_ENV } from '../lib/local-admin.js'
|
||||
|
||||
const passphrase = process.argv[2]
|
||||
if (!passphrase) {
|
||||
console.error('Usage: node scripts/seal-local-admin.mjs "<passphrase>"')
|
||||
process.exit(1)
|
||||
}
|
||||
|
||||
try {
|
||||
const box = sealLocalAdminBox(passphrase)
|
||||
console.log(`# Keep the passphrase secret. Only the box goes into the process env.`)
|
||||
console.log(`${LOCAL_ADMIN_BOX_ENV}=${box}`)
|
||||
} catch (err) {
|
||||
console.error(err.message || err)
|
||||
process.exit(1)
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue