Add MrTerm Web: self-hosted browser version (Docker Compose) with user accounts, per-user vaults encrypted by the login password, the desktop UI over WebSocket, SFTP upload/download over HTTP; share backend channels between Android and web (src/core/backend.js)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
+10
-7
@@ -1,6 +1,7 @@
|
||||
// Persistenter Vault: Hosts, Keys, Snippets, Forwards, Settings.
|
||||
// Wird mit Electron safeStorage (DPAPI unter Windows, libsecret/kwallet unter Linux) verschlüsselt.
|
||||
const { app, safeStorage } = require('electron');
|
||||
// Im Web-Server gibt es kein Electron: dort übergibt der Aufrufer Verzeichnis und Verschlüsselung (opts)
|
||||
const electron = (() => { try { const e = require('electron'); return typeof e === 'object' ? e : {}; } catch { return {}; } })();
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
const crypto = require('crypto');
|
||||
@@ -57,8 +58,10 @@ function unbox(key, b) {
|
||||
}
|
||||
|
||||
class Store {
|
||||
constructor() {
|
||||
this.dir = app.getPath('userData');
|
||||
// opts: { dir, crypto } – crypto hat die Schnittstelle von Electrons safeStorage
|
||||
constructor(opts = {}) {
|
||||
this.dir = opts.dir || electron.app.getPath('userData');
|
||||
this.crypto = opts.crypto || electron.safeStorage;
|
||||
this.file = path.join(this.dir, 'vault.dat');
|
||||
this.data = structuredClone(DEFAULTS);
|
||||
this.encrypted = false;
|
||||
@@ -97,9 +100,9 @@ class Store {
|
||||
|
||||
canEncrypt() {
|
||||
try {
|
||||
if (!safeStorage.isEncryptionAvailable()) return false;
|
||||
if (!this.crypto.isEncryptionAvailable()) return false;
|
||||
// Unter Linux ohne Keyring fällt Electron auf "basic_text" zurück – das ist keine echte Verschlüsselung.
|
||||
if (process.platform === 'linux' && safeStorage.getSelectedStorageBackend?.() === 'basic_text') return false;
|
||||
if (process.platform === 'linux' && this.crypto.getSelectedStorageBackend?.() === 'basic_text') return false;
|
||||
return true;
|
||||
} catch { return false; }
|
||||
}
|
||||
@@ -110,7 +113,7 @@ class Store {
|
||||
const raw = fs.readFileSync(this.file);
|
||||
let json;
|
||||
if (raw.slice(0, 4).toString() === 'ENC1') {
|
||||
json = safeStorage.decryptString(raw.slice(4));
|
||||
json = this.crypto.decryptString(raw.slice(4));
|
||||
this.encrypted = true;
|
||||
} else {
|
||||
json = raw.toString('utf8');
|
||||
@@ -136,7 +139,7 @@ class Store {
|
||||
}
|
||||
const tmp = this.file + '.tmp';
|
||||
if (this.canEncrypt()) {
|
||||
fs.writeFileSync(tmp, Buffer.concat([Buffer.from('ENC1'), safeStorage.encryptString(json)]));
|
||||
fs.writeFileSync(tmp, Buffer.concat([Buffer.from('ENC1'), this.crypto.encryptString(json)]));
|
||||
this.encrypted = true;
|
||||
} else {
|
||||
fs.writeFileSync(tmp, json, { mode: 0o600 });
|
||||
|
||||
Reference in New Issue
Block a user