#!/bin/bash # gitea-admin-wrapper.sh — reads the agent-staged gitea-admin token at exec # time and prefixes it as a transient env var to the underlying tool. # # M22 Phase 9 staging pattern: init.sh runs as root and `install`s a 0600 # agent-owned copy of the ESO-mounted token into $HOME/.config/gitea-admin/ # token. This wrapper reads the staged copy, not the ESO mount path, so # the `cat` succeeds under the agent UID. The brief presence of the token # in /proc//environ of the exec'd tool is the accepted floor # (per H-SECRET-4 / SR-DISP-7); the wrapper's parent shell never sees it. set -euo pipefail TOKEN_FILE="$HOME/.config/gitea-admin/token" # git-credential-helper subcommand: read token and emit git credential format. # Git invokes us as `gitea-admin-wrapper.sh git-credential-helper get` and # expects key=value lines on stdout terminated by a blank line. git_credential_helper() { if [[ ! -r "$TOKEN_FILE" ]]; then echo "gitea-admin-wrapper: staged token not readable at $TOKEN_FILE" >&2 echo "gitea-admin-wrapper: did init.sh run? (it stages the token from the ESO mount)" >&2 exit 1 fi local base_url="${GITEA_BASE_URL:-https://gitea.oreillyit.nz}" local host host=$(echo "$base_url" | sed 's|https\?://||') # Trailing blank line per git credential-helper protocol. printf 'protocol=https\nhost=%s\nusername=git\npassword=%s\n\n' "$host" "$(cat "$TOKEN_FILE")" exit 0 } case "${1:-}" in git-credential-helper) git_credential_helper ;; *) if [[ ! -r "$TOKEN_FILE" ]]; then echo "gitea-admin-wrapper: staged token not readable at $TOKEN_FILE" >&2 echo "gitea-admin-wrapper: did init.sh run? (it stages the token from the ESO mount)" >&2 exit 1 fi # `exec env VAR=...` keeps the secret out of the wrapper's parent shell # — it lands only in the exec'd tool's /proc//environ. NEVER use # `export VAR=` here, which would leak the secret to the wrapper's # ancestors (H-SECRET-4 violation). exec env GITEA_ADMIN_TOKEN="$(cat "$TOKEN_FILE")" "$@" ;; esac