aboutsummaryrefslogtreecommitdiff
path: root/scripts
diff options
context:
space:
mode:
Diffstat (limited to 'scripts')
-rwxr-xr-xscripts/bokftui-bw74
-rwxr-xr-xscripts/bokftui-sudo21
2 files changed, 74 insertions, 21 deletions
diff --git a/scripts/bokftui-bw b/scripts/bokftui-bw
new file mode 100755
index 0000000..284828f
--- /dev/null
+++ b/scripts/bokftui-bw
@@ -0,0 +1,74 @@
+#!/bin/sh
+# Start bokftui with a credential fetched from a Bitwarden/Vaultwarden item.
+# Runs entirely as the invoking user — no root, no sudo.
+#
+# BOKF_BW_ITEM item name (default: bokf)
+# BOKF_BW_FIELD custom field that holds the secret (default: the password)
+# BOKF_BW_KIND password (default) exports BOKFD_PASSWORD;
+# token exports BOKFD_TOKEN
+#
+# Works with the official Bitwarden CLI (bw) or with rbw. With bw the session
+# key is cached in ~/.cache/bokf/bw-session (mode 0600) so the master password
+# is only asked when the session expires or after a logout.
+set -eu
+
+item="${BOKF_BW_ITEM:-bokf}"
+field="${BOKF_BW_FIELD:-}"
+kind="${BOKF_BW_KIND:-password}"
+BOKFTUI="${BOKFTUI:-bokftui}"
+
+if command -v rbw >/dev/null 2>&1; then
+ if ! rbw unlocked >/dev/null 2>&1; then
+ rbw unlock
+ fi
+ if [ -n "$field" ]; then
+ secret=$(rbw get --field "$field" "$item")
+ else
+ secret=$(rbw get "$item")
+ fi
+elif command -v bw >/dev/null 2>&1; then
+ umask 077
+ cache="${XDG_CACHE_HOME:-$HOME/.cache}/bokf/bw-session"
+ if [ -f "$cache" ]; then
+ BW_SESSION=$(cat "$cache")
+ export BW_SESSION
+ fi
+ if ! bw status 2>/dev/null | jq -e '.status == "unlocked"' >/dev/null 2>&1
+ then
+ mkdir -p "$(dirname "$cache")"
+ BW_SESSION=$(bw unlock --raw)
+ export BW_SESSION
+ printf '%s\n' "$BW_SESSION" > "$cache"
+ fi
+ if [ -n "$field" ]; then
+ secret=$(bw get item "$item" | jq -r --arg f "$field" \
+ '.fields[]? | select(.name == $f) | .value' | head -n 1)
+ else
+ secret=$(bw get password "$item")
+ fi
+else
+ echo "bokftui-bw: install rbw or the Bitwarden CLI (bw)" >&2
+ exit 1
+fi
+
+if [ -z "$secret" ] || [ "$secret" = "null" ]; then
+ echo "bokftui-bw: no secret named '$field' in item '$item'" >&2
+ exit 1
+fi
+
+case "$kind" in
+ token)
+ BOKFD_TOKEN="$secret"
+ export BOKFD_TOKEN
+ ;;
+ password)
+ BOKFD_PASSWORD="$secret"
+ export BOKFD_PASSWORD
+ ;;
+ *)
+ echo "bokftui-bw: BOKF_BW_KIND must be password or token" >&2
+ exit 1
+ ;;
+esac
+
+exec "$BOKFTUI" "$@"
diff --git a/scripts/bokftui-sudo b/scripts/bokftui-sudo
deleted file mode 100755
index fc300ae..0000000
--- a/scripts/bokftui-sudo
+++ /dev/null
@@ -1,21 +0,0 @@
-#!/bin/sh
-# Start bokftui with a credential from a root-only file, unlocked with sudo.
-# Looks for /etc/bokf/tui-token (preferred) then /etc/bokf/tui-password.
-# The server and user are remembered by bokftui itself in
-# ~/.config/bokf/tui.conf.
-set -eu
-
-sudo -v
-
-if token=$(sudo cat /etc/bokf/tui-token 2>/dev/null) && [ -n "$token" ]; then
- BOKFD_TOKEN="$token"
- export BOKFD_TOKEN
-elif pass=$(sudo cat /etc/bokf/tui-password 2>/dev/null) && [ -n "$pass" ]; then
- BOKFD_PASSWORD="$pass"
- export BOKFD_PASSWORD
-else
- echo "bokftui-sudo: no /etc/bokf/tui-token or /etc/bokf/tui-password" >&2
- exit 1
-fi
-
-exec bokftui "$@"