#!/bin/bash # gitea-admin-wrapper.sh — reads the ESO-mounted gitea-admin token at exec time # and prefixes it as a transient env var to the underlying tool. # # M22 Phase 9: token mounted at /run/agent/secrets/gitea-admin/token (read-only, # tmpfs, mode 0400). The token NEVER enters the wrapper's parent shell — only # the exec'd tool's environment via `exec env VAR=value cmd`. The brief # presence in /proc//environ of the tool process is the accepted # floor (per spec/secrets-runtime.md SR-DISP-7 / H-SECRET-4). set -euo pipefail TOKEN_FILE="/run/agent/secrets/gitea-admin/token" # git-credential-helper subcommand: read token and emit git credential format. # Git invokes us as `gitea-admin-wrapper.sh git-credential-helper get` and # expects key=value lines on stdout terminated by a blank line. git_credential_helper() { if [[ ! -r "$TOKEN_FILE" ]]; then echo "gitea-admin-wrapper: token file not readable at $TOKEN_FILE" >&2 exit 1 fi local base_url="${GITEA_BASE_URL:-https://gitea.oreillyit.nz}" local host host=$(echo "$base_url" | sed 's|https\?://||') # Trailing blank line per git credential-helper protocol. printf 'protocol=https\nhost=%s\nusername=git\npassword=%s\n\n' "$host" "$(cat "$TOKEN_FILE")" exit 0 } case "${1:-}" in git-credential-helper) git_credential_helper ;; *) if [[ ! -r "$TOKEN_FILE" ]]; then echo "gitea-admin-wrapper: token file not readable at $TOKEN_FILE" >&2 exit 1 fi # `exec env VAR=...` keeps the secret out of the wrapper's parent shell # — it lands only in the exec'd tool's /proc//environ. NEVER use # `export VAR=` here, which would leak the secret to the wrapper's # ancestors (H-SECRET-4 violation). exec env GITEA_ADMIN_TOKEN="$(cat "$TOKEN_FILE")" "$@" ;; esac