ps: store master key in macOS native keychain, part 1

This commit is contained in:
Vladimir Krivosheev
2016-08-05 19:24:25 +02:00
parent 12b7f3b4bd
commit 6109235646
11 changed files with 35 additions and 19 deletions
@@ -13,7 +13,7 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package com.intellij.ide.passwordSafe.masterKey
package com.intellij.ide.passwordSafe
import com.intellij.ide.passwordSafe.impl.PasswordSafeProvider
import com.intellij.ide.passwordSafe.impl.providers.masterKey.windows.WindowsCryptUtils
@@ -13,7 +13,7 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.jetbrains.keychain
package com.intellij.ide.passwordSafe
import com.intellij.openapi.util.SystemInfo
import com.sun.jna.Pointer
@@ -52,8 +52,8 @@ interface OSXKeychainLibrary : com.sun.jna.Library {
fun findGenericPassword(serviceName: ByteArray, accountName: String): String? {
val accountNameBytes = accountName.toByteArray()
val passwordSize = IntArray(1);
val passwordData = arrayOf<Pointer?>(null);
val passwordSize = IntArray(1)
val passwordData = arrayOf<Pointer?>(null)
checkForError("find", LIBRARY.SecKeychainFindGenericPassword(null, serviceName.size, serviceName, accountNameBytes.size, accountNameBytes, passwordSize, passwordData))
val pointer = passwordData[0] ?: return null
@@ -89,10 +89,10 @@ interface OSXKeychainLibrary : com.sun.jna.Library {
fun checkForError(message: String, code: Int) {
if (code != 0 && code != /* errSecItemNotFound, always returned from find it seems */-25300) {
val translated = LIBRARY.SecCopyErrorMessageString(code, null);
val translated = LIBRARY.SecCopyErrorMessageString(code, null)
val builder = StringBuilder(message).append(": ")
if (translated == null) {
builder.append(code);
builder.append(code)
}
else {
val buf = CharArray(LIBRARY.CFStringGetLength(translated).toInt())
@@ -15,12 +15,12 @@
*/
package com.intellij.ide.passwordSafe.impl
import com.intellij.ide.passwordSafe.FilePasswordSafeProvider
import com.intellij.ide.passwordSafe.LOG
import com.intellij.ide.passwordSafe.PasswordSafe
import com.intellij.ide.passwordSafe.PasswordSafeSettingsListener
import com.intellij.ide.passwordSafe.config.PasswordSafeSettings
import com.intellij.ide.passwordSafe.config.PasswordSafeSettings.ProviderType
import com.intellij.ide.passwordSafe.masterKey.FilePasswordSafeProvider
import com.intellij.ide.passwordSafe.masterKey.LOG
import com.intellij.openapi.application.ApplicationManager
import com.intellij.openapi.components.SettingsSavingComponent
@@ -13,7 +13,7 @@
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package com.intellij.ide.passwordSafe.masterKey
package com.intellij.ide.passwordSafe
import com.intellij.ide.ApplicationLoadListener
import com.intellij.ide.passwordSafe.config.PasswordSafeSettings
@@ -130,6 +130,7 @@ internal class PasswordDatabaseConvertor : ApplicationLoadListener {
val oldDb = ServiceManager.getService(PasswordDatabase::class.java)
// old db contains at least one test key - skip it
if (oldDb.myDatabase.size > 1) {
@Suppress("DEPRECATION")
val newDb = convertOldDb(ServiceManager.getService<PasswordDatabase>(PasswordDatabase::class.java))
if (newDb != null && newDb.isNotEmpty()) {
FilePasswordSafeProvider(newDb).save()
@@ -15,7 +15,7 @@
*/
package com.intellij.util
import com.intellij.ide.passwordSafe.masterKey.LOG
import com.intellij.openapi.diagnostic.Logger
import com.intellij.openapi.util.io.FileUtil
import com.intellij.openapi.vfs.LocalFileSystem
import com.intellij.openapi.vfs.VfsUtil
@@ -29,6 +29,7 @@ import java.nio.file.attribute.BasicFileAttributes
import java.nio.file.attribute.FileTime
import java.util.*
fun Path.exists() = Files.exists(this)
fun Path.createDirectories(): Path = Files.createDirectories(this)
@@ -212,4 +213,6 @@ inline fun <R> Path.directoryStreamIfExists(noinline filter: ((path: Path) -> Bo
catch (ignored: NoSuchFileException) {
}
return null
}
}
private val LOG = Logger.getInstance("#com.intellij.openapi.util.io.FileUtil")
@@ -15,7 +15,6 @@
*/
package com.intellij.ide.passwordSafe
import com.intellij.ide.passwordSafe.masterKey.FilePasswordSafeProvider
import com.intellij.testFramework.RuleChain
import com.intellij.testFramework.TemporaryDirectory
import org.assertj.core.api.Assertions.assertThat
@@ -16,8 +16,6 @@
package com.intellij.ide.passwordSafe
import com.intellij.ide.passwordSafe.impl.providers.masterKey.PasswordDatabase
import com.intellij.ide.passwordSafe.masterKey.FilePasswordSafeProvider
import com.intellij.ide.passwordSafe.masterKey.convertOldDb
import com.intellij.openapi.util.JDOMUtil
import com.intellij.testFramework.ApplicationRule
import com.intellij.testFramework.runInEdtAndWait
@@ -28,7 +28,6 @@
<orderEntry type="module" module-name="projectModel-impl" />
<orderEntry type="library" name="JSch" level="project" />
<orderEntry type="library" name="KotlinJavaRuntime" level="project" />
<orderEntry type="library" name="jna" level="project" />
<orderEntry type="library" scope="RUNTIME" name="Log4J" level="project" />
<orderEntry type="module-library">
<library name="jackson">
@@ -18,6 +18,7 @@ package org.jetbrains.settingsRepository
import com.intellij.configurationStore.StateStorageManagerImpl
import com.intellij.configurationStore.StreamProvider
import com.intellij.ide.ApplicationLoadListener
import com.intellij.ide.passwordSafe.isOSXCredentialsStoreSupported
import com.intellij.openapi.application.Application
import com.intellij.openapi.application.ApplicationManager
import com.intellij.openapi.application.PathManager
@@ -36,7 +37,6 @@ import com.intellij.util.move
import org.jetbrains.keychain.CredentialsStore
import org.jetbrains.keychain.FileCredentialsStore
import org.jetbrains.keychain.OsXCredentialsStore
import org.jetbrains.keychain.isOSXCredentialsStoreSupported
import org.jetbrains.settingsRepository.git.GitRepositoryManager
import org.jetbrains.settingsRepository.git.GitRepositoryService
import org.jetbrains.settingsRepository.git.processChildren
@@ -1,5 +1,5 @@
/*
* Copyright 2000-2015 JetBrains s.r.o.
* Copyright 2000-2016 JetBrains s.r.o.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -15,6 +15,7 @@
*/
package org.jetbrains.settingsRepository.git
import com.intellij.ide.passwordSafe.isOSXCredentialsStoreSupported
import com.intellij.openapi.ui.MessageDialogBuilder
import com.intellij.openapi.ui.Messages
import com.intellij.openapi.util.NotNullLazyValue
@@ -26,7 +27,6 @@ import org.eclipse.jgit.transport.URIish
import org.jetbrains.keychain.Credentials
import org.jetbrains.keychain.CredentialsStore
import org.jetbrains.keychain.isFulfilled
import org.jetbrains.keychain.isOSXCredentialsStoreSupported
import org.jetbrains.settingsRepository.LOG
import org.jetbrains.settingsRepository.nullize
import org.jetbrains.settingsRepository.showAuthenticationForm
@@ -1,5 +1,21 @@
/*
* Copyright 2000-2016 JetBrains s.r.o.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.jetbrains.keychain
import com.intellij.ide.passwordSafe.OSXKeychainLibrary
import com.intellij.openapi.util.PasswordUtil
import gnu.trove.THashMap
@@ -51,7 +67,7 @@ class OsXCredentialsStore(serviceName: String) : CredentialsStore {
*/
override fun save(host: String?, credentials: Credentials, sshKeyFile: String?) {
val accountName: String = sshKeyFile ?: host!!
var oldCredentials = accountToCredentials.put(accountName, credentials)
val oldCredentials = accountToCredentials.put(accountName, credentials)
if (credentials.equals(oldCredentials)) {
return
}