who_need_help/scripts/import-google-oauth-client.sh

68 lines
1.8 KiB
Bash
Executable File

#!/bin/sh
set -eu
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
if [ "$#" -ne 2 ]; then
echo "Usage: $0 ENV_FILE GOOGLE_OAUTH_CLIENT_JSON" >&2
exit 1
fi
env_file=$1
client_file=$2
if [ ! -f "$client_file" ]; then
echo "Google OAuth client JSON does not exist: $client_file" >&2
exit 1
fi
case "$(stat -c '%a' "$client_file")" in
400|600) ;;
*)
echo "Google OAuth client JSON contains a client secret and must have mode 0400 or 0600." >&2
exit 1
;;
esac
base_url=$(
awk -F= '
$1 == "WNH_BASE_URL" {
print substr($0, index($0, "=") + 1)
exit
}
' "$env_file"
)
if [ -z "$base_url" ]; then
echo "WNH_BASE_URL is missing from the selected environment." >&2
exit 1
fi
callback_url=${base_url%/}/auth/google/callback
if ! jq --exit-status --arg callback "$callback_url" '
.web as $web
| ($web | type == "object")
and ($web.client_id | type == "string" and length > 0 and test("^[^\r\n]+$"))
and ($web.client_secret | type == "string" and length > 0 and test("^[^\r\n]+$"))
and ($web.redirect_uris | type == "array")
and any($web.redirect_uris[]; . == $callback)
' "$client_file" >/dev/null; then
echo "Google OAuth JSON is incomplete or does not contain the exact callback: $callback_url" >&2
exit 1
fi
values_file=$(mktemp "${TMPDIR:-/tmp}/wnh-google-oauth-values.XXXXXX")
trap 'rm -f "$values_file"' EXIT HUP INT TERM
chmod 600 "$values_file"
jq --raw-output '
.web
| "GOOGLE_OAUTH_CLIENT_ID=\(.client_id)",
"GOOGLE_OAUTH_CLIENT_SECRET=\(.client_secret)"
' "$client_file" >"$values_file"
"$ROOT/scripts/set-env-values.sh" "$env_file" "$values_file" >/dev/null
echo "Google OAuth client imported without printing its ID or secret."
echo "The downloaded JSON still contains the client secret; store or remove it deliberately."