Files
container/Sources/ContainerizationOCI/Client/KeychainWrapper.swift
T
+6 3407cc3f16 initial commit
Co-authored-by: Aditya Ramani <a_ramani@apple.com>
Co-authored-by: Agam Dua <agam_dua@apple.com>
Co-authored-by: Danny Canter <danny_canter@apple.com>
Co-authored-by: Dmitry Kovba <dkovba@apple.com>
Co-authored-by: Eric Ernst <eric_ernst@apple.com>
Co-authored-by: Evan Hazlett <ehazlett@apple.com>
Co-authored-by: Gilbert Song <gilbertsong@apple.com>
Co-authored-by: Hugh Bussell <hbussell@apple.com>
Co-authored-by: John Logan <john_logan@apple.com>
Co-authored-by: Kathryn Baldauf <k_baldauf@apple.com>
Co-authored-by: Madhu Venugopal <mvenugopal@apple.com>
Co-authored-by: Michael Crosby <michael_crosby@apple.com>
Co-authored-by: Sidhartha Mani <sidhartha_mani@apple.com>
Co-authored-by: Tanweer Noor <tnoor@apple.com>
Co-authored-by: Ximena Perez Diaz <xperez528@gmail.com>
Co-authored-by: Yibo Zhuang <yzhuang@apple.com>
2025-06-05 16:15:21 -07:00

87 lines
2.7 KiB
Swift

//===----------------------------------------------------------------------===//
// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// https://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//===----------------------------------------------------------------------===//
#if os(macOS)
import Foundation
import ContainerizationOS
public struct KeychainHelper: Sendable {
private let id: String
public init(id: String) {
self.id = id
}
public func lookup(domain: String) throws -> Authentication {
let kq = KeychainQuery()
guard try kq.exists(id: self.id, host: domain) else {
throw Self.Error.keyNotFound
}
guard let fetched = try kq.get(id: self.id, host: domain) else {
throw Self.Error.keyNotFound
}
return BasicAuthentication(
username: fetched.account,
password: fetched.data
)
}
public func delete(domain: String) throws {
let kq = KeychainQuery()
try kq.delete(id: self.id, host: domain)
}
public func save(domain: String, username: String, password: String) throws {
let kq = KeychainQuery()
try kq.save(id: self.id, host: domain, user: username, token: password)
}
public func credentialPrompt(domain: String) throws -> Authentication {
let username = try userPrompt(domain: domain)
let password = try passwordPrompt()
return BasicAuthentication(username: username, password: password)
}
public func userPrompt(domain: String) throws -> String {
print("Provide registry username \(domain): ", terminator: "")
guard let username = readLine() else {
throw Self.Error.invalidInput
}
return username
}
public func passwordPrompt() throws -> String {
print("Provide registry password: ", terminator: "")
let console = try Terminal.current
defer { console.tryReset() }
try console.disableEcho()
guard let password = readLine() else {
throw Self.Error.invalidInput
}
return password
}
}
extension KeychainHelper {
public enum Error: Swift.Error {
case keyNotFound
case invalidInput
}
}
#endif