1 5cdf5adc 2022-05-08 op #!/usr/bin/env perl
3 5cdf5adc 2022-05-08 op # Copyright (c) 2022 Omar Polo <op@omarpolo.com>
5 5cdf5adc 2022-05-08 op # Permission to use, copy, modify, and distribute this software for any
6 5cdf5adc 2022-05-08 op # purpose with or without fee is hereby granted, provided that the above
7 5cdf5adc 2022-05-08 op # copyright notice and this permission notice appear in all copies.
9 5cdf5adc 2022-05-08 op # THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10 5cdf5adc 2022-05-08 op # WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11 5cdf5adc 2022-05-08 op # MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12 5cdf5adc 2022-05-08 op # ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13 5cdf5adc 2022-05-08 op # WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14 5cdf5adc 2022-05-08 op # ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15 5cdf5adc 2022-05-08 op # OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 5cdf5adc 2022-05-08 op use open ":std", ":encoding(UTF-8)";
23 5cdf5adc 2022-05-08 op use Getopt::Long qw(:config bundling require_order);
24 5cdf5adc 2022-05-08 op use Pod::Usage;
25 5cdf5adc 2022-05-08 op use File::Basename;
26 5cdf5adc 2022-05-08 op use File::Find;
28 50c751f3 2022-06-29 op my $store = $ENV{'PLASS_STORE'} // $ENV{'HOME'}.'/.password-store';
30 50c751f3 2022-06-29 op my $got = $ENV{'PLASS_GOT'} // 'got';
31 50c751f3 2022-06-29 op my $tog = $ENV{'PLASS_TOG'} // 'tog';
33 50c751f3 2022-06-29 op my $gpg = $ENV{'PLASS_GPG'} // 'gpg2';
34 5cdf5adc 2022-05-08 op my @gpg_flags = qw(--quiet --compress-algo=none --no-encrypt-to);
36 50c751f3 2022-06-29 op my $default_chars = $ENV{'PLASS_CHARS'} // '!-~';
37 5cdf5adc 2022-05-08 op my $default_length = $ENV{'PLASS_LENGTH'};
38 5cdf5adc 2022-05-08 op if (!defined($default_length) || $default_length lt 0) {
39 5cdf5adc 2022-05-08 op $default_length = 32;
43 5cdf5adc 2022-05-08 op "h|?" => sub { pod2usage(0) },
44 5cdf5adc 2022-05-08 op ) or pod2usage(1);
46 06fecd01 2022-06-29 op my $cmd = shift // 'find';
48 5cdf5adc 2022-05-08 op my %subcmd = (
49 5cdf5adc 2022-05-08 op cat => [\&cmd_cat, "entries..."],
50 5cdf5adc 2022-05-08 op find => [\&cmd_find, "[pattern]"],
51 43642ec1 2022-06-29 op gen => [\&cmd_gen, "[-nq] [-c chars] [-l length] entry"],
52 43642ec1 2022-06-29 op got => [\&cmd_got, "args ..."],
53 5cdf5adc 2022-05-08 op mv => [\&cmd_mv, "from to"],
54 6a455fdf 2022-06-29 op rm => [\&cmd_rm, "entries..."],
55 afdbc7b0 2022-06-29 op tee => [\&cmd_tee, "[-q] entry"],
56 43642ec1 2022-06-29 op tog => [\&cmd_tog, "args ..."],
58 5cdf5adc 2022-05-08 op pod2usage(1) unless defined $subcmd{$cmd};
59 5cdf5adc 2022-05-08 op my ($fn, $usage) = @{$subcmd{$cmd}};
68 5cdf5adc 2022-05-08 op my $prog = basename $0;
69 5cdf5adc 2022-05-08 op say STDERR "Usage: $prog $cmd $usage";
73 5cdf5adc 2022-05-08 op sub name2file {
74 5cdf5adc 2022-05-08 op my $f = shift;
75 5cdf5adc 2022-05-08 op $f .= ".gpg" unless $f =~ m,\.gpg$,;
79 5cdf5adc 2022-05-08 op # tr -cd -- $chars < /dev/random | dd bs=$len count=1 status=none
81 5cdf5adc 2022-05-08 op my ($chars, $length) = @_;
82 5cdf5adc 2022-05-08 op my $pass = "";
84 5cdf5adc 2022-05-08 op open(my $fh, '<:raw', '/dev/random')
85 5cdf5adc 2022-05-08 op or die "can't open /dev/random: $!";
86 5cdf5adc 2022-05-08 op my $l = $length;
87 5cdf5adc 2022-05-08 op while ($l gt 0) {
88 5cdf5adc 2022-05-08 op read($fh, my $t, $length * 4)
89 5cdf5adc 2022-05-08 op or die "failed to read /dev/random: $!";
90 5cdf5adc 2022-05-08 op $t =~ s/[^$chars]//g;
91 5cdf5adc 2022-05-08 op $l -= length($t);
96 5cdf5adc 2022-05-08 op return substr($pass, 0, $length);
99 5cdf5adc 2022-05-08 op sub readpass {
100 5cdf5adc 2022-05-08 op # todo some stty black magic to avoid echo
101 5cdf5adc 2022-05-08 op print shift if -t;
102 5cdf5adc 2022-05-08 op my $pass = <>;
103 5cdf5adc 2022-05-08 op die "failed to read stdin: $!" unless defined($pass);
105 5cdf5adc 2022-05-08 op return $pass;
109 1f89d66a 2022-06-29 op my $dir = shift;
110 1f89d66a 2022-06-29 op my $parent = dirname $dir;
111 1f89d66a 2022-06-29 op mkdirs($parent) unless -d $parent || $parent eq '/';
112 1f89d66a 2022-06-29 op mkdir $dir or die "mkdir $dir: $!"
113 1f89d66a 2022-06-29 op unless -d $dir;
116 5cdf5adc 2022-05-08 op sub writepass {
117 5cdf5adc 2022-05-08 op my ($file, $pass) = @_;
119 1f89d66a 2022-06-29 op mkdirs(dirname $file);
121 5cdf5adc 2022-05-08 op my @args = ($gpg, @gpg_flags, '-e', '-r', recipient(),
122 5cdf5adc 2022-05-08 op '-o', $file);
123 5cdf5adc 2022-05-08 op open my $fh, '|-', @args;
124 5cdf5adc 2022-05-08 op say $fh "$pass";
128 5cdf5adc 2022-05-08 op sub recipient {
129 5cdf5adc 2022-05-08 op open my $fh, '<', "$store/.gpg-id"
130 5cdf5adc 2022-05-08 op or die "can't open recipient file";
131 5cdf5adc 2022-05-08 op my $r = <$fh>;
137 5cdf5adc 2022-05-08 op sub passfind {
138 5cdf5adc 2022-05-08 op my $pattern = shift;
142 5cdf5adc 2022-05-08 op wanted => sub {
143 5cdf5adc 2022-05-08 op if (m,/.git$, || m,/.got$,) {
144 5cdf5adc 2022-05-08 op $File::Find::prune = 1;
148 5cdf5adc 2022-05-08 op return if defined($pattern) && ! m/$pattern/;
149 5cdf5adc 2022-05-08 op return unless -f && m,.gpg$,;
151 5cdf5adc 2022-05-08 op s,^$store/*,,;
153 5cdf5adc 2022-05-08 op push @entries, $_;
155 5cdf5adc 2022-05-08 op no_chdir => 1,
156 5cdf5adc 2022-05-08 op follow_fast => 1,
157 5cdf5adc 2022-05-08 op }, ($store));
158 5cdf5adc 2022-05-08 op return sort(@entries);
162 87197963 2022-06-29 op # discard stdout
163 5cdf5adc 2022-05-08 op open my $fh, '-|', ($got, @_);
168 5cdf5adc 2022-05-08 op sub got_add {
169 f96edc25 2022-06-29 op return got 'add', '-I', shift;
173 f96edc25 2022-06-29 op got 'remove', '-f', shift
178 afdbc7b0 2022-06-29 op my $pid = fork;
179 afdbc7b0 2022-06-29 op die "failed to fork: $!" unless defined $pid;
181 afdbc7b0 2022-06-29 op if ($pid ne 0) {
183 afdbc7b0 2022-06-29 op die "failed to commit changes" if $?;
187 afdbc7b0 2022-06-29 op open (STDOUT, ">&", \*STDERR)
188 afdbc7b0 2022-06-29 op or die "can't redirect stdout to stderr";
189 afdbc7b0 2022-06-29 op exec ($got, 'commit', '-m', shift)
190 afdbc7b0 2022-06-29 op or die "failed to exec $got: $!";
196 5cdf5adc 2022-05-08 op sub cmd_cat {
197 5cdf5adc 2022-05-08 op GetOptions('h|?' => \&usage) or usage;
198 5cdf5adc 2022-05-08 op usage unless @ARGV;
200 5cdf5adc 2022-05-08 op while (@ARGV) {
201 5cdf5adc 2022-05-08 op my $file = name2file(shift @ARGV);
202 5cdf5adc 2022-05-08 op system ($gpg, @gpg_flags, '-d', $file);
203 5cdf5adc 2022-05-08 op die "failed to exec $gpg: $!" if $? == -1;
207 5cdf5adc 2022-05-08 op sub cmd_find {
208 5cdf5adc 2022-05-08 op GetOptions('h|?' => \&usage) or usage;
209 5cdf5adc 2022-05-08 op usage if @ARGV gt 1;
211 5cdf5adc 2022-05-08 op map { say $_ } passfind(shift @ARGV);
214 5cdf5adc 2022-05-08 op sub cmd_gen {
215 5cdf5adc 2022-05-08 op my $chars = $default_chars;
216 5cdf5adc 2022-05-08 op my $length = $default_length;
221 5cdf5adc 2022-05-08 op 'c=s' => sub { $chars = $_[1] },
222 5cdf5adc 2022-05-08 op 'h|?' => \&usage,
223 5cdf5adc 2022-05-08 op 'l=i' => sub { $length = $_[1] },
224 9d75d6d8 2022-06-29 op 'n' => \$nop,
227 5cdf5adc 2022-05-08 op usage if @ARGV ne 1;
229 5cdf5adc 2022-05-08 op my $name = shift @ARGV;
230 5cdf5adc 2022-05-08 op my $file = name2file $name;
231 bd71caf6 2022-06-29 op my $renamed = -f $file;
233 5cdf5adc 2022-05-08 op my $pass = gen($chars, $length);
235 9d75d6d8 2022-06-29 op unless ($nop) {
236 9d75d6d8 2022-06-29 op writepass($file, $pass);
237 9d75d6d8 2022-06-29 op got_add $file;
238 bd71caf6 2022-06-29 op got_ci($renamed ? "update $name" : "+$name");
240 9d75d6d8 2022-06-29 op say $pass unless $q;
243 5cdf5adc 2022-05-08 op sub cmd_got {
244 5cdf5adc 2022-05-08 op exec $got, @ARGV;
247 5cdf5adc 2022-05-08 op # TODO: handle moving directories?
249 5cdf5adc 2022-05-08 op GetOptions('h|?' => \&usage) or usage;
250 5cdf5adc 2022-05-08 op usage if @ARGV ne 2;
252 5cdf5adc 2022-05-08 op my $a = shift @ARGV;
253 5cdf5adc 2022-05-08 op my $b = shift @ARGV;
255 5cdf5adc 2022-05-08 op my $pa = name2file $a;
256 5cdf5adc 2022-05-08 op my $pb = name2file $b;
258 5cdf5adc 2022-05-08 op die "source password doesn't exist" unless -f $pa;
259 5cdf5adc 2022-05-08 op die "target password exists" if -f $pb;
261 5cdf5adc 2022-05-08 op rename $pa, $pb or die "can't rename $a to $b: $!";
264 bd71caf6 2022-06-29 op got_add $pb or die "can't add $pb\n";
265 5cdf5adc 2022-05-08 op got_ci "mv $a $b";
269 5cdf5adc 2022-05-08 op GetOptions('h|?' => \&usage) or usage;
270 6a455fdf 2022-06-29 op usage unless @ARGV;
272 6a455fdf 2022-06-29 op while (@ARGV) {
273 6a455fdf 2022-06-29 op my $name = shift @ARGV;
274 6a455fdf 2022-06-29 op my $file = name2file $name;
276 6a455fdf 2022-06-29 op got_rm $file;
277 6a455fdf 2022-06-29 op got_ci "-$name";
281 afdbc7b0 2022-06-29 op sub cmd_tee {
284 afdbc7b0 2022-06-29 op 'h|?' => \&usage,
287 5cdf5adc 2022-05-08 op usage if @ARGV ne 1;
289 5cdf5adc 2022-05-08 op my $name = shift @ARGV;
290 5cdf5adc 2022-05-08 op my $file = name2file $name;
292 d69b7902 2022-05-15 op my $pass = readpass "Enter the password: ";
293 d69b7902 2022-05-15 op writepass($file, $pass);
295 5cdf5adc 2022-05-08 op got_add $file;
296 afdbc7b0 2022-06-29 op got_ci (-f $file ? "update $name" : "+$name");
297 b2653662 2022-06-29 op say $pass unless $q;
300 afdbc7b0 2022-06-29 op sub cmd_tog {
301 afdbc7b0 2022-06-29 op exec $tog, @ARGV;
308 5cdf5adc 2022-05-08 op B<plass> - manage passwords
310 5cdf5adc 2022-05-08 op =head1 SYNOPSIS
312 5cdf5adc 2022-05-08 op B<plass> I<command> [-h] [arg ...]
314 bd71caf6 2022-06-29 op Valid subcommands are: cat, find, gen, got, mv, rm, tee, tog.
316 06fecd01 2022-06-29 op If no I<command> is given, B<find> is assumed.
318 5cdf5adc 2022-05-08 op =head1 DESCRIPTION
320 5cdf5adc 2022-05-08 op B<plass> is a simple password manager. It manages passwords stored in
321 5cdf5adc 2022-05-08 op a directory tree rooted at I<~/.password-store> (or I<$PLASS_STORE>),
322 5cdf5adc 2022-05-08 op where every password is a single file encrypted with gpg2(1).
324 5cdf5adc 2022-05-08 op Passwords entries can be referenced using the path relative to the
325 5cdf5adc 2022-05-08 op store directory. The extension ".gpg" is optional.
327 5cdf5adc 2022-05-08 op The whole store is supposed to be managed by the got(1) version
328 5cdf5adc 2022-05-08 op control system.
330 5cdf5adc 2022-05-08 op The commands for B<plass> are as follows:
334 5cdf5adc 2022-05-08 op =item B<cat> I<entries ...>
336 5cdf5adc 2022-05-08 op Decrypt and print the passwords of the given I<entries>.
338 5cdf5adc 2022-05-08 op =item B<find> [I<pattern>]
340 5cdf5adc 2022-05-08 op Print one per line all the entries of the store, optionally filtered
341 5cdf5adc 2022-05-08 op by the given I<pattern>.
343 9d75d6d8 2022-06-29 op =item B<gen> [B<-nq>] [B<-c> I<chars>] [B<-l> I<length>] I<entry>
345 5cdf5adc 2022-05-08 op Generate and persist a password for the given I<entry> in the store.
346 5cdf5adc 2022-05-08 op B<-c> can be used to control the characters allowed in the password
347 5bbf948d 2022-05-15 op (by default I<!-~> i.e. all the printable ASCII character) and B<-l>
348 5bbf948d 2022-05-15 op the length (32 by default.)
350 9d75d6d8 2022-06-29 op Unless B<-q> is provided, plass prints the generated password.
352 9d75d6d8 2022-06-29 op If the B<-n> option is given, plass won't persist the password.
354 5cdf5adc 2022-05-08 op =item B<got> I<arguments ...>
356 5cdf5adc 2022-05-08 op Execute got(1) in the password store directory with the given
357 5cdf5adc 2022-05-08 op I<arguments>.
359 5cdf5adc 2022-05-08 op =item B<mv> I<from> I<to>
361 5cdf5adc 2022-05-08 op Rename a password entry, doesn't work with directories. I<from> must
362 5cdf5adc 2022-05-08 op exist and I<to> mustn't.
364 6a455fdf 2022-06-29 op =item B<rm> I<entries...>
366 5cdf5adc 2022-05-08 op Remove the password I<entry> from the store.
368 afdbc7b0 2022-06-29 op =item B<tee> [B<-q>] I<entry>
370 afdbc7b0 2022-06-29 op Prompt for a password, persist it in the store under the given
371 afdbc7b0 2022-06-29 op I<entry> name and then print it again to standard output.
373 5cdf5adc 2022-05-08 op =item B<tog> I<arguments ...>
375 5cdf5adc 2022-05-08 op Execute tog(1) in the password store directory with the given
376 5cdf5adc 2022-05-08 op I<arguments>.
380 5cdf5adc 2022-05-08 op =head1 CREATING A PASSWORD STORE
382 5cdf5adc 2022-05-08 op A password store is just a normal got(1) repository with a worktree
383 5cdf5adc 2022-05-08 op checked out in I<~/.password-store> (or I<$PLASS_STORE>). The only
384 5cdf5adc 2022-05-08 op restriction is that a file called I<.gpg-id> must exist in the root of
385 5cdf5adc 2022-05-08 op the work tree for most B<plass> commands to work.
387 5cdf5adc 2022-05-08 op For example, a got repository and password store can be created as
390 5cdf5adc 2022-05-08 op $ mkdir .password-store
391 5cdf5adc 2022-05-08 op $ cd .password-store
392 5cdf5adc 2022-05-08 op $ echo foo@example.com > .gpg-id
394 5cdf5adc 2022-05-08 op $ got init pass.git
395 621d6d63 2022-06-29 op $ got import -r pass.git -m 'initial import' ~/.password-store
396 5cdf5adc 2022-05-08 op $ cd ~/.password-store
397 621d6d63 2022-06-29 op $ got checkout -E ~/git/pass.git .
399 5cdf5adc 2022-05-08 op See got(1) for more information.
401 5cdf5adc 2022-05-08 op Otherwise, if a repository already exists, a password-store can be
402 5cdf5adc 2022-05-08 op checked out more simply as:
404 5cdf5adc 2022-05-08 op $ got checkout ~/git/pass.git ~/.password-store
406 5cdf5adc 2022-05-08 op To migrate from pass(1), just delete I<~/.password-store> and checkout
407 ed056c14 2022-06-29 op it again using got(1).
409 9944b08b 2022-05-08 op =head1 ENVIRONMENT
413 9944b08b 2022-05-08 op =item PLASS_CHARS
415 9944b08b 2022-05-08 op Default range of characters to use to generate passwords.
417 9944b08b 2022-05-08 op =item PLASS_GOT
419 9944b08b 2022-05-08 op Path to the got(1) executable.
421 9944b08b 2022-05-08 op =item PLASS_GPG
423 9944b08b 2022-05-08 op Path to the gpg2(1) executable.
425 9944b08b 2022-05-08 op =item PLASS_LENGTH
427 9944b08b 2022-05-08 op Default length for the passwords generated.
429 9944b08b 2022-05-08 op =item PLASS_STORE
431 9944b08b 2022-05-08 op Path to the password-store directory tree. I<~/.password-store> by
434 9944b08b 2022-05-08 op =item PLASS_TOG
436 9944b08b 2022-05-08 op Path to the tog(1) executable.
444 9944b08b 2022-05-08 op =item I<~/.password-store>
446 9944b08b 2022-05-08 op Password store used by default.
448 9944b08b 2022-05-08 op =item I<~/.password-store/.gpg-id>
450 9944b08b 2022-05-08 op File containing the gpg recipient used to encrypt the passwords.
454 5cdf5adc 2022-05-08 op =head1 ACKNOWLEDGEMENTS
456 5cdf5adc 2022-05-08 op B<plass> was heavily influenced by pass(1) in the design, but it's a
457 5cdf5adc 2022-05-08 op complete different implementation with different tools involved.
459 5cdf5adc 2022-05-08 op =head1 AUTHORS
461 5cdf5adc 2022-05-08 op The B<plass> utility was written by Omar Polo <I<op@omarpolo.com>>.
463 5cdf5adc 2022-05-08 op =head1 CAVEATS
465 5cdf5adc 2022-05-08 op B<plass> B<find> output format isn't designed to handle files with
466 5cdf5adc 2022-05-08 op newlines in them. Use find(1) B<-print0> or similar if it's a
469 5cdf5adc 2022-05-08 op There isn't a B<init> sub-command, the store initialisation must be
470 5cdf5adc 2022-05-08 op performed manually.