zephyr-agent
Version:
Zephyr plugin agent
94 lines (93 loc) • 4.63 kB
JavaScript
import "node:module";
import { lockSync } from "@bybrave/proper-lockfile2";
import { redactString } from "../security/redaction.mjs";
import * as __rspack_external_node_fs_1b05aee1 from "node:fs";
import * as __rspack_external_node_os_4f3c9d58 from "node:os";
import * as __rspack_external_node_path_806ed179 from "node:path";
const ZE_PATH = __rspack_external_node_path_806ed179.resolve(__rspack_external_node_os_4f3c9d58.homedir(), '.zephyr');
const ZE_STORAGE_PATH = __rspack_external_node_path_806ed179.resolve(ZE_PATH, 'storage');
const ZE_LOCKS_PATH = __rspack_external_node_path_806ed179.resolve(ZE_PATH, 'locks');
const ZE_SESSION_LOCK = __rspack_external_node_path_806ed179.resolve(ZE_PATH, 'session');
const PARTIAL_ASSET_LOCK_STALE_MS = 30000;
const LEGACY_PARTIAL_ASSET_LOCK_TARGET = /^partial-assets-[a-f0-9]{64}$/;
function ensurePrivateFilePermissions(filePath) {
if ('win32' === process.platform) return;
const stat = __rspack_external_node_fs_1b05aee1.lstatSync(filePath);
if (!stat.isFile()) throw new TypeError(`Refusing to apply private file permissions to ${filePath}`);
__rspack_external_node_fs_1b05aee1.chmodSync(filePath, 384);
}
function secureExistingPrivateFile(filePath) {
try {
ensurePrivateFilePermissions(filePath);
} catch (error) {
if ('ENOENT' !== error.code) throw error;
}
}
function ensurePrivateStoragePermissions(zephyrPath = ZE_PATH, storagePath = ZE_STORAGE_PATH, sessionPath = ZE_SESSION_LOCK, locksPath = __rspack_external_node_path_806ed179.resolve(zephyrPath, 'locks')) {
__rspack_external_node_fs_1b05aee1.mkdirSync(zephyrPath, {
recursive: true,
mode: 448
});
__rspack_external_node_fs_1b05aee1.mkdirSync(storagePath, {
recursive: true,
mode: 448
});
__rspack_external_node_fs_1b05aee1.mkdirSync(locksPath, {
recursive: true,
mode: 448
});
for (const entry of __rspack_external_node_fs_1b05aee1.readdirSync(storagePath, {
withFileTypes: true
})){
if (!entry.isFile() || !LEGACY_PARTIAL_ASSET_LOCK_TARGET.test(entry.name)) continue;
const targetPath = __rspack_external_node_path_806ed179.join(storagePath, entry.name);
let release;
try {
release = lockSync(targetPath, {
realpath: false,
retries: 0,
stale: PARTIAL_ASSET_LOCK_STALE_MS
});
if (0 === __rspack_external_node_fs_1b05aee1.statSync(targetPath).size) __rspack_external_node_fs_1b05aee1.rmSync(targetPath, {
force: true
});
} catch (error) {
const code = error.code;
if ('ENOENT' !== code && 'ELOCKED' !== code) throw error;
} finally{
release?.();
}
}
if ('win32' === process.platform) return;
__rspack_external_node_fs_1b05aee1.chmodSync(zephyrPath, 448);
__rspack_external_node_fs_1b05aee1.chmodSync(storagePath, 448);
__rspack_external_node_fs_1b05aee1.chmodSync(locksPath, 448);
for (const privateDirectory of [
storagePath,
locksPath
])for (const entry of __rspack_external_node_fs_1b05aee1.readdirSync(privateDirectory, {
withFileTypes: true
}))if (entry.isFile()) secureExistingPrivateFile(__rspack_external_node_path_806ed179.join(privateDirectory, entry.name));
secureExistingPrivateFile(sessionPath);
}
try {
ensurePrivateStoragePermissions();
} catch (error) {
console.error('error', "Could not secure ~/.zephyr storage. Please check your permissions.", redactString(error instanceof Error ? error.message : String(error)));
}
var storage_keys_StorageKeys = /*#__PURE__*/ function(StorageKeys) {
StorageKeys["ze_app_partial_asset_map"] = "ze_app_partial_asset_map";
StorageKeys["ze_app_config_token"] = "ze-application-configuration";
StorageKeys["ze_auth_token"] = "ze-auth-token";
StorageKeys["ze_secret_token"] = "ZE_SECRET_TOKEN";
StorageKeys["ze_fs_cache"] = "ze-fs-cache";
StorageKeys["ze_hash_cache"] = "ze-hash-cache";
StorageKeys["ze_app_deploy_result"] = "ze-app-deploy-result";
StorageKeys["ze_ci_auth_token"] = "ze-ci-auth-token";
StorageKeys["ze_server_token"] = "ZE_SERVER_TOKEN";
StorageKeys["ze_ci_token"] = "ZE_CI_TOKEN";
StorageKeys["ze_user_email"] = "ZE_USER_EMAIL";
return StorageKeys;
}({});
export { PARTIAL_ASSET_LOCK_STALE_MS, ZE_LOCKS_PATH, ZE_PATH, ZE_SESSION_LOCK, ZE_STORAGE_PATH, ensurePrivateFilePermissions, ensurePrivateStoragePermissions, storage_keys_StorageKeys as StorageKeys };
//# sourceMappingURL=storage-keys.mjs.map