feat: session encryption
-- Allows user-customization of encryption
This commit is contained in:
@@ -121,6 +121,27 @@ This is applied after the default config so user options will override any defau
|
|||||||
Further, the `user.lua` file is ignored by git and
|
Further, the `user.lua` file is ignored by git and
|
||||||
will not impact your ability to pull updates.
|
will not impact your ability to pull updates.
|
||||||
|
|
||||||
|
### Session Encryption
|
||||||
|
|
||||||
|
The default configuration attempts to use my personal encryption keys.
|
||||||
|
|
||||||
|
If the keyfile cannot be found, encryption is disabled.
|
||||||
|
|
||||||
|
You can customize this by adding (above the `return{}` table):
|
||||||
|
|
||||||
|
```lua
|
||||||
|
MYKEY = "/path/to/keyfile.txt" -- Path to the keyfile
|
||||||
|
MYPUBKEY = "age1q80h5jsp9d48kggf9kra82xkgyaqdnehqenm003ftapem9re7ytqp9hr6h"
|
||||||
|
|
||||||
|
return {
|
||||||
|
-- Etc..
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
These global variables will be detected and used to apply the encryption.
|
||||||
|
|
||||||
|
As with the default configuration, if the keyfile is not found, encryption is disabled.
|
||||||
|
|
||||||
## Screenshots
|
## Screenshots
|
||||||
|
|
||||||

|

|
||||||
|
|||||||
@@ -0,0 +1,43 @@
|
|||||||
|
-- ╭─────────────────────────────────────────────────────────╮
|
||||||
|
-- │ ENCRYPTION │
|
||||||
|
-- ╰─────────────────────────────────────────────────────────╯
|
||||||
|
|
||||||
|
local M = {}
|
||||||
|
|
||||||
|
-- Set the keyfile
|
||||||
|
local key = WEZTERM.home_dir .. "/.config/.private/key.txt"
|
||||||
|
local pubkey = "age1q80h5jsp9d48kggf9kra82xkgyaqdnehqenm003ftapem9re7ytqp9hr6h"
|
||||||
|
|
||||||
|
if MYKEY then
|
||||||
|
key = MYKEY
|
||||||
|
elseif MYOS == "win" then
|
||||||
|
key = WEZTERM.home_dir .. "\\.config\\.private\\key.txt"
|
||||||
|
end
|
||||||
|
|
||||||
|
if MYPUBKEY then
|
||||||
|
pubkey = MYPUBKEY
|
||||||
|
else
|
||||||
|
end
|
||||||
|
|
||||||
|
---@function Check if a file exists
|
||||||
|
---@param file string The file path to check
|
||||||
|
---@return boolean exists True if the file exists, false otherwise
|
||||||
|
local function file_exists(file)
|
||||||
|
local f = io.open(file, "r")
|
||||||
|
if f then
|
||||||
|
f:close()
|
||||||
|
return true
|
||||||
|
end
|
||||||
|
return false
|
||||||
|
end
|
||||||
|
|
||||||
|
if file_exists(key) then
|
||||||
|
RESURRECT.set_encryption({
|
||||||
|
enable = true,
|
||||||
|
method = "age", -- "age" is the default encryption method, but you can also specify "rage" or "gpg"
|
||||||
|
private_key = key, -- if using "gpg", you can omit this
|
||||||
|
public_key = pubkey,
|
||||||
|
})
|
||||||
|
end
|
||||||
|
|
||||||
|
return M
|
||||||
@@ -27,7 +27,12 @@ end
|
|||||||
|
|
||||||
-- If USERCONFIG is true, merge userconfig into opts
|
-- If USERCONFIG is true, merge userconfig into opts
|
||||||
if USERCONFIG then
|
if USERCONFIG then
|
||||||
merge_into_opts("user")
|
for k, v in pairs(require("user")) do
|
||||||
|
opts[k] = v
|
||||||
|
end
|
||||||
|
else
|
||||||
|
MYKEY = nil
|
||||||
|
MYPUBKEY = nil
|
||||||
end
|
end
|
||||||
|
|
||||||
-- Return config options table
|
-- Return config options table
|
||||||
|
|||||||
@@ -7,30 +7,6 @@ local M = {}
|
|||||||
-- Load Resurrect plugin
|
-- Load Resurrect plugin
|
||||||
RESURRECT = WEZTERM.plugin.require("https://github.com/MLFlexer/resurrect.wezterm")
|
RESURRECT = WEZTERM.plugin.require("https://github.com/MLFlexer/resurrect.wezterm")
|
||||||
|
|
||||||
-- Set the keyfile
|
|
||||||
local key = WEZTERM.home_dir .. "/.config/.private/key.txt"
|
|
||||||
|
|
||||||
---@function Check if a file exists
|
|
||||||
---@param file string The file path to check
|
|
||||||
---@return boolean exists True if the file exists, false otherwise
|
|
||||||
local function file_exists(file)
|
|
||||||
local f = io.open(file, "r")
|
|
||||||
if f then
|
|
||||||
f:close()
|
|
||||||
return true
|
|
||||||
end
|
|
||||||
return false
|
|
||||||
end
|
|
||||||
|
|
||||||
if file_exists(key) then
|
|
||||||
RESURRECT.set_encryption({
|
|
||||||
enable = true,
|
|
||||||
method = "age", -- "age" is the default encryption method, but you can also specify "rage" or "gpg"
|
|
||||||
private_key = key, -- if using "gpg", you can omit this
|
|
||||||
public_key = "age1q80h5jsp9d48kggf9kra82xkgyaqdnehqenm003ftapem9re7ytqp9hr6h",
|
|
||||||
})
|
|
||||||
end
|
|
||||||
|
|
||||||
-- Set the periodic save interval
|
-- Set the periodic save interval
|
||||||
RESURRECT.periodic_save({ interval_seconds = 60, save_workspaces = true, save_windows = true })
|
RESURRECT.periodic_save({ interval_seconds = 60, save_workspaces = true, save_windows = true })
|
||||||
|
|
||||||
|
|||||||
@@ -32,6 +32,9 @@ USERCONFIG = pcall(require, "user")
|
|||||||
-- Load plugins
|
-- Load plugins
|
||||||
require("plugs")
|
require("plugs")
|
||||||
|
|
||||||
|
-- Encrypt Sessions
|
||||||
|
require("encryption")
|
||||||
|
|
||||||
--------- Update Plugins ----------
|
--------- Update Plugins ----------
|
||||||
---Running this may cause slowdowns
|
---Running this may cause slowdowns
|
||||||
-----------------------------------
|
-----------------------------------
|
||||||
|
|||||||
Reference in New Issue
Block a user