summaryrefslogtreecommitdiff
path: root/internal/client/ui/auth
diff options
context:
space:
mode:
authorKyren223 <Kyren223@proton.me>2025-01-07 19:02:14 +0200
committerKyren223 <Kyren223@proton.me>2025-01-07 19:02:14 +0200
commit4e2ca64319f17867ac63a8d1283a67e2f1c4daba (patch)
treeb4f2f1157dd5b590e33018f9e527ce767c0ed95e /internal/client/ui/auth
parent4c2672b4970613f9db072231ed4ac07845e431d7 (diff)
Fixed all high and medium security issues from gosec
Diffstat (limited to 'internal/client/ui/auth')
-rw-r--r--internal/client/ui/auth/auth.go6
1 files changed, 3 insertions, 3 deletions
diff --git a/internal/client/ui/auth/auth.go b/internal/client/ui/auth/auth.go
index d4c4d2f..5e44962 100644
--- a/internal/client/ui/auth/auth.go
+++ b/internal/client/ui/auth/auth.go
@@ -427,13 +427,13 @@ func (m *Model) Signup() tea.Cmd {
}
privateKeyFilepath := expandPath(m.fields[privateKeyField].Input.Value())
- err := os.MkdirAll(filepath.Dir(privateKeyFilepath), 0o755)
+ err := os.MkdirAll(filepath.Dir(privateKeyFilepath), 0o750)
if err != nil {
m.fields[privateKeyField].Input.Err = errors.Unwrap(err)
assert.NotNil(errors.Unwrap(err), "there should always be an error to unwrap", "err", err)
return nil
}
- file, err := os.OpenFile(privateKeyFilepath, os.O_WRONLY|os.O_CREATE|os.O_EXCL, 0o600)
+ file, err := os.OpenFile(privateKeyFilepath, os.O_WRONLY|os.O_CREATE|os.O_EXCL, 0o600) // #nosec 304
if errors.Is(err, os.ErrExist) {
info, e := os.Stat(privateKeyFilepath)
assert.NoError(e, "if file exists it should be fine to stat it")
@@ -485,7 +485,7 @@ func (m *Model) Signup() tea.Cmd {
func (m *Model) signin() tea.Cmd {
privateKeyFilepath := expandPath(m.fields[privateKeyField].Input.Value())
- file, err := os.ReadFile(privateKeyFilepath)
+ file, err := os.ReadFile(privateKeyFilepath) // #nosec 304
if errors.Is(err, os.ErrNotExist) {
content := fmt.Sprintf("File '%s' doesn't exist.\nDo you want to sign-up instead?", privateKeyFilepath)
m.popup = createPopup(content, []string{"sign-up"}, []string{"cancel"})