mirror of
https://gitea.com/gitea/tea
synced 2026-08-05 00:12:57 +02:00
- Embed the minimal credstore subset used by tea (SecureStore, EncryptedFileStore, KeyringStore, FileStore) as modules/credstore so external SDK renames can no longer break the build - Keep the on-disk format fully compatible: AES-256-GCM values with the v1: prefix, credentials.json / credentials.json.enc paths, and the Token JSON field names are unchanged, verified by a ciphertext fixture generated with sdk-go v1.1.0 - Store the keyring master key under a tea-owned account name - Reuse the existing kernel-level filelock module instead of the upstream lockfile protocol, removing a stale-lock race - Cover roundtrip, keyring-unavailable fallback, and fixture decryption with tests using a mocked keyring - Remove github.com/go-signet/sdk-go and promote github.com/zalando/go-keyring to a direct dependency Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
9 lines
370 B
Go
9 lines
370 B
Go
// Copyright 2026 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
// Package credstore provides secure storage for OAuth tokens. Values are
|
|
// AES-256-GCM-encrypted into a JSON file while only the 32-byte master key
|
|
// lives in the OS keyring; when the keyring is unavailable the store falls
|
|
// back to plaintext file storage.
|
|
package credstore
|