zephyr-agent
Version:
Zephyr plugin agent
152 lines (151 loc) • 6.84 kB
JavaScript
;
var __webpack_require__ = {};
(()=>{
__webpack_require__.d = (exports1, getters, values)=>{
var define = (defs, kind)=>{
for(var key in defs)if (__webpack_require__.o(defs, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {
enumerable: true,
[kind]: defs[key]
});
};
define(getters, "get");
define(values, "value");
};
})();
(()=>{
__webpack_require__.o = (obj, prop)=>Object.prototype.hasOwnProperty.call(obj, prop);
})();
(()=>{
__webpack_require__.r = (exports1)=>{
if ("u" > typeof Symbol && Symbol.toStringTag) Object.defineProperty(exports1, Symbol.toStringTag, {
value: 'Module'
});
Object.defineProperty(exports1, '__esModule', {
value: true
});
};
})();
var __webpack_exports__ = {};
__webpack_require__.r(__webpack_exports__);
__webpack_require__.d(__webpack_exports__, {
PARTIAL_ASSET_LOCK_STALE_MS: ()=>PARTIAL_ASSET_LOCK_STALE_MS,
StorageKeys: ()=>storage_keys_StorageKeys,
ZE_LOCKS_PATH: ()=>ZE_LOCKS_PATH,
ZE_PATH: ()=>ZE_PATH,
ZE_SESSION_LOCK: ()=>ZE_SESSION_LOCK,
ZE_STORAGE_PATH: ()=>ZE_STORAGE_PATH,
ensurePrivateFilePermissions: ()=>ensurePrivateFilePermissions,
ensurePrivateStoragePermissions: ()=>ensurePrivateStoragePermissions
});
const external_node_fs_namespaceObject = require("node:fs");
const external_node_os_namespaceObject = require("node:os");
const external_node_path_namespaceObject = require("node:path");
const proper_lockfile2_namespaceObject = require("@bybrave/proper-lockfile2");
const redaction_js_namespaceObject = require("../security/redaction.js");
const ZE_PATH = external_node_path_namespaceObject.resolve(external_node_os_namespaceObject.homedir(), '.zephyr');
const ZE_STORAGE_PATH = external_node_path_namespaceObject.resolve(ZE_PATH, 'storage');
const ZE_LOCKS_PATH = external_node_path_namespaceObject.resolve(ZE_PATH, 'locks');
const ZE_SESSION_LOCK = external_node_path_namespaceObject.resolve(ZE_PATH, 'session');
const PARTIAL_ASSET_LOCK_STALE_MS = 30000;
const LEGACY_PARTIAL_ASSET_LOCK_TARGET = /^partial-assets-[a-f0-9]{64}$/;
function ensurePrivateFilePermissions(filePath) {
if ('win32' === process.platform) return;
const stat = external_node_fs_namespaceObject.lstatSync(filePath);
if (!stat.isFile()) throw new TypeError(`Refusing to apply private file permissions to ${filePath}`);
external_node_fs_namespaceObject.chmodSync(filePath, 384);
}
function secureExistingPrivateFile(filePath) {
try {
ensurePrivateFilePermissions(filePath);
} catch (error) {
if ('ENOENT' !== error.code) throw error;
}
}
function ensurePrivateStoragePermissions(zephyrPath = ZE_PATH, storagePath = ZE_STORAGE_PATH, sessionPath = ZE_SESSION_LOCK, locksPath = external_node_path_namespaceObject.resolve(zephyrPath, 'locks')) {
external_node_fs_namespaceObject.mkdirSync(zephyrPath, {
recursive: true,
mode: 448
});
external_node_fs_namespaceObject.mkdirSync(storagePath, {
recursive: true,
mode: 448
});
external_node_fs_namespaceObject.mkdirSync(locksPath, {
recursive: true,
mode: 448
});
for (const entry of external_node_fs_namespaceObject.readdirSync(storagePath, {
withFileTypes: true
})){
if (!entry.isFile() || !LEGACY_PARTIAL_ASSET_LOCK_TARGET.test(entry.name)) continue;
const targetPath = external_node_path_namespaceObject.join(storagePath, entry.name);
let release;
try {
release = (0, proper_lockfile2_namespaceObject.lockSync)(targetPath, {
realpath: false,
retries: 0,
stale: PARTIAL_ASSET_LOCK_STALE_MS
});
if (0 === external_node_fs_namespaceObject.statSync(targetPath).size) external_node_fs_namespaceObject.rmSync(targetPath, {
force: true
});
} catch (error) {
const code = error.code;
if ('ENOENT' !== code && 'ELOCKED' !== code) throw error;
} finally{
release?.();
}
}
if ('win32' === process.platform) return;
external_node_fs_namespaceObject.chmodSync(zephyrPath, 448);
external_node_fs_namespaceObject.chmodSync(storagePath, 448);
external_node_fs_namespaceObject.chmodSync(locksPath, 448);
for (const privateDirectory of [
storagePath,
locksPath
])for (const entry of external_node_fs_namespaceObject.readdirSync(privateDirectory, {
withFileTypes: true
}))if (entry.isFile()) secureExistingPrivateFile(external_node_path_namespaceObject.join(privateDirectory, entry.name));
secureExistingPrivateFile(sessionPath);
}
try {
ensurePrivateStoragePermissions();
} catch (error) {
console.error('error', "Could not secure ~/.zephyr storage. Please check your permissions.", (0, redaction_js_namespaceObject.redactString)(error instanceof Error ? error.message : String(error)));
}
var storage_keys_StorageKeys = /*#__PURE__*/ function(StorageKeys) {
StorageKeys["ze_app_partial_asset_map"] = "ze_app_partial_asset_map";
StorageKeys["ze_app_config_token"] = "ze-application-configuration";
StorageKeys["ze_auth_token"] = "ze-auth-token";
StorageKeys["ze_secret_token"] = "ZE_SECRET_TOKEN";
StorageKeys["ze_fs_cache"] = "ze-fs-cache";
StorageKeys["ze_hash_cache"] = "ze-hash-cache";
StorageKeys["ze_app_deploy_result"] = "ze-app-deploy-result";
StorageKeys["ze_ci_auth_token"] = "ze-ci-auth-token";
StorageKeys["ze_server_token"] = "ZE_SERVER_TOKEN";
StorageKeys["ze_ci_token"] = "ZE_CI_TOKEN";
StorageKeys["ze_user_email"] = "ZE_USER_EMAIL";
return StorageKeys;
}({});
exports.PARTIAL_ASSET_LOCK_STALE_MS = __webpack_exports__.PARTIAL_ASSET_LOCK_STALE_MS;
exports.StorageKeys = __webpack_exports__.StorageKeys;
exports.ZE_LOCKS_PATH = __webpack_exports__.ZE_LOCKS_PATH;
exports.ZE_PATH = __webpack_exports__.ZE_PATH;
exports.ZE_SESSION_LOCK = __webpack_exports__.ZE_SESSION_LOCK;
exports.ZE_STORAGE_PATH = __webpack_exports__.ZE_STORAGE_PATH;
exports.ensurePrivateFilePermissions = __webpack_exports__.ensurePrivateFilePermissions;
exports.ensurePrivateStoragePermissions = __webpack_exports__.ensurePrivateStoragePermissions;
for(var __rspack_i in __webpack_exports__)if (-1 === [
"PARTIAL_ASSET_LOCK_STALE_MS",
"StorageKeys",
"ZE_LOCKS_PATH",
"ZE_PATH",
"ZE_SESSION_LOCK",
"ZE_STORAGE_PATH",
"ensurePrivateFilePermissions",
"ensurePrivateStoragePermissions"
].indexOf(__rspack_i)) exports[__rspack_i] = __webpack_exports__[__rspack_i];
Object.defineProperty(exports, '__esModule', {
value: true
});
//# sourceMappingURL=storage-keys.js.map