Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
121 changes: 121 additions & 0 deletions cmd/ende/init_cmd.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,121 @@
package main

import (
"fmt"
"net/url"
"os/user"
"regexp"
"strings"

"github.com/kuma/ende/internal/keyring"
"github.com/spf13/cobra"
)

var initNameSanitizer = regexp.MustCompile(`[^A-Za-z0-9._:@-]+`)

func newInitCommand() *cobra.Command {
var name string
var keyserverURL string
cmd := &cobra.Command{
Use: "init",
Short: "Set up Ende for first-time use",
RunE: func(cmd *cobra.Command, args []string) error {
if strings.TrimSpace(name) == "" {
name = defaultInitName()
}
name = sanitizeInitName(name)
if name == "" {
return fmt.Errorf("--name is required")
}
if strings.TrimSpace(keyserverURL) != "" {
if _, err := url.ParseRequestURI(keyserverURL); err != nil {
return fmt.Errorf("invalid --keyserver URL: %w", err)
}
}

share, created, err := ensureInitKey(name)
if err != nil {
return err
}
if err := ensureDefaultSigner(name); err != nil {
return err
}

out := cmd.OutOrStdout()
if created {
fmt.Fprintf(out, "created local key %s\n", name)
} else {
fmt.Fprintf(out, "using existing local key %s\n", name)
}
fmt.Fprintln(out, "")
fmt.Fprintln(out, "Your share code:")
fmt.Fprintf(out, "%s\n", share)
fmt.Fprintln(out, "")
fmt.Fprintln(out, "Next steps:")
fmt.Fprintln(out, "1. Send this share code to a peer, or publish the public profile through your team's keyserver.")
fmt.Fprintln(out, "2. Add a peer with `ende add-peer` when they send you their share code.")
fmt.Fprintf(out, "3. Send a secret with `ende send -t <peer>`.\n")
if strings.TrimSpace(keyserverURL) != "" {
fmt.Fprintln(out, "")
fmt.Fprintln(out, "Keyserver:")
fmt.Fprintf(out, "- publish this public profile to %s/v1/peers/%s\n", strings.TrimRight(keyserverURL, "/"), name)
fmt.Fprintf(out, "- peers can fetch your share code from %s/v1/share/%s\n", strings.TrimRight(keyserverURL, "/"), name)
fmt.Fprintln(out, "- the keyserver is a public directory; peers should still pin your key in their local keyring.")
}
return nil
},
}
cmd.Flags().StringVar(&name, "name", "", "local key id (defaults to the OS username)")
cmd.Flags().StringVar(&keyserverURL, "keyserver", "", "optional keyserver base URL for onboarding guidance")
return cmd
}

func ensureInitKey(name string) (share string, created bool, err error) {
store, err := keyring.Load()
if err != nil {
return "", false, err
}
if entry, ok := store.Key(name); ok {
share, err := tutorialShareFromEntry(entry)
return share, false, err
}
share, err = tutorialKeygen(name)
return share, true, err
}

func ensureDefaultSigner(name string) error {
store, err := keyring.Load()
if err != nil {
return err
}
if store.DefaultSigner() == name {
return nil
}
if err := store.SetDefaultSigner(name); err != nil {
return err
}
return store.Save()
}

func defaultInitName() string {
current, err := user.Current()
if err == nil {
if name := sanitizeInitName(current.Username); name != "" {
return name
}
}
return "me"
}

func sanitizeInitName(name string) string {
name = strings.TrimSpace(name)
if i := strings.LastIndexAny(name, `\/`); i >= 0 {
name = name[i+1:]
}
name = initNameSanitizer.ReplaceAllString(name, "-")
name = strings.Trim(name, "-")
if len(name) > 128 {
name = name[:128]
}
return name
}
100 changes: 100 additions & 0 deletions cmd/ende/init_cmd_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
package main

import (
"bytes"
"strings"
"testing"

"github.com/kuma/ende/internal/keyring"
)

func TestInitCommandCreatesLocalKeyAndPrintsShareCode(t *testing.T) {
t.Setenv("ENDE_CONFIG_DIR", t.TempDir())

cmd := newInitCommand()
var out bytes.Buffer
cmd.SetOut(&out)
cmd.SetArgs([]string{"--name", "alice"})

if err := cmd.Execute(); err != nil {
t.Fatalf("init command failed: %v", err)
}

got := out.String()
if !strings.Contains(got, "created local key alice") {
t.Fatalf("expected create message, got:\n%s", got)
}
if !strings.Contains(got, sharePrefix) {
t.Fatalf("expected share code, got:\n%s", got)
}

store, err := keyring.Load()
if err != nil {
t.Fatalf("load keyring: %v", err)
}
if _, ok := store.Key("alice"); !ok {
t.Fatal("expected alice key in keyring")
}
if store.DefaultSigner() != "alice" {
t.Fatalf("expected alice default signer, got %q", store.DefaultSigner())
}
}

func TestInitCommandReusesExistingLocalKey(t *testing.T) {
t.Setenv("ENDE_CONFIG_DIR", t.TempDir())

first := newInitCommand()
first.SetArgs([]string{"--name", "alice"})
if err := first.Execute(); err != nil {
t.Fatalf("first init failed: %v", err)
}

second := newInitCommand()
var out bytes.Buffer
second.SetOut(&out)
second.SetArgs([]string{"--name", "alice"})
if err := second.Execute(); err != nil {
t.Fatalf("second init failed: %v", err)
}
if !strings.Contains(out.String(), "using existing local key alice") {
t.Fatalf("expected reuse message, got:\n%s", out.String())
}
}

func TestInitCommandPrintsKeyserverGuidance(t *testing.T) {
t.Setenv("ENDE_CONFIG_DIR", t.TempDir())

cmd := newInitCommand()
var out bytes.Buffer
cmd.SetOut(&out)
cmd.SetArgs([]string{"--name", "alice", "--keyserver", "https://keys.example.com/"})

if err := cmd.Execute(); err != nil {
t.Fatalf("init command failed: %v", err)
}
got := out.String()
if !strings.Contains(got, "https://keys.example.com/v1/peers/alice") {
t.Fatalf("expected publish URL, got:\n%s", got)
}
if !strings.Contains(got, "https://keys.example.com/v1/share/alice") {
t.Fatalf("expected share URL, got:\n%s", got)
}
}

func TestInitCommandRejectsInvalidKeyserverURL(t *testing.T) {
t.Setenv("ENDE_CONFIG_DIR", t.TempDir())

cmd := newInitCommand()
cmd.SetArgs([]string{"--name", "alice", "--keyserver", "://bad"})

if err := cmd.Execute(); err == nil {
t.Fatal("expected invalid keyserver URL error")
}
}

func TestSanitizeInitName(t *testing.T) {
got := sanitizeInitName(`domain\Alice Smith!`)
if got != "Alice-Smith" {
t.Fatalf("unexpected sanitized name: %q", got)
}
}
Loading
Loading