#!/bin/sh set -eu ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) if [ "$#" -ne 2 ]; then echo "Usage: $0 ENV_FILE GOOGLE_OAUTH_CLIENT_JSON" >&2 exit 1 fi env_file=$1 client_file=$2 if [ ! -f "$client_file" ]; then echo "Google OAuth client JSON does not exist: $client_file" >&2 exit 1 fi case "$(stat -c '%a' "$client_file")" in 400|600) ;; *) echo "Google OAuth client JSON contains a client secret and must have mode 0400 or 0600." >&2 exit 1 ;; esac base_url=$( awk -F= ' $1 == "WNH_BASE_URL" { print substr($0, index($0, "=") + 1) exit } ' "$env_file" ) if [ -z "$base_url" ]; then echo "WNH_BASE_URL is missing from the selected environment." >&2 exit 1 fi callback_url=${base_url%/}/auth/google/callback if ! jq --exit-status --arg callback "$callback_url" ' .web as $web | ($web | type == "object") and ($web.client_id | type == "string" and length > 0 and test("^[^\r\n]+$")) and ($web.client_secret | type == "string" and length > 0 and test("^[^\r\n]+$")) and ($web.redirect_uris | type == "array") and any($web.redirect_uris[]; . == $callback) ' "$client_file" >/dev/null; then echo "Google OAuth JSON is incomplete or does not contain the exact callback: $callback_url" >&2 exit 1 fi values_file=$(mktemp "${TMPDIR:-/tmp}/wnh-google-oauth-values.XXXXXX") trap 'rm -f "$values_file"' EXIT HUP INT TERM chmod 600 "$values_file" jq --raw-output ' .web | "GOOGLE_OAUTH_CLIENT_ID=\(.client_id)", "GOOGLE_OAUTH_CLIENT_SECRET=\(.client_secret)" ' "$client_file" >"$values_file" "$ROOT/scripts/set-env-values.sh" "$env_file" "$values_file" >/dev/null echo "Google OAuth client imported without printing its ID or secret." echo "The downloaded JSON still contains the client secret; store or remove it deliberately."