Skip to content

Commit 6f00d54

Browse files
authored
Merge pull request #281 from github/fix-argon
fixing multiuser conditional argon secret backup
2 parents 6d17c01 + 8c91cee commit 6f00d54

File tree

3 files changed

+6
-7
lines changed

3 files changed

+6
-7
lines changed

share/github-backup-utils/ghe-backup-settings

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,7 @@ backup-secret "kredz.credz HMAC key" "kredz-credz-hmac" "secrets.kredz.credz-hma
8080
backup-secret "kredz.varz HMAC key" "kredz-varz-hmac" "secrets.kredz.varz-hmac-secret"
8181

8282
# Backup argon secrets for multiuser from ghes version 3.8 onwards
83-
if [ "$(version $GHE_REMOTE_VERSION)" -gt "$(version 3.7.0)" ]; then
83+
if ! [ "$(version $GHE_REMOTE_VERSION)" -lt "$(version 3.8.0)" ]; then
8484
backup-secret "management console argon2 secret" "manage-argon-secret" "secrets.manage-auth.argon-secret"
8585
fi
8686

test/test-ghe-backup.sh

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -133,19 +133,18 @@ begin_test "ghe-backup without password pepper"
133133
)
134134
end_test
135135

136-
begin_test "ghe-backup without management console argon2 secret for ghes lower than 3.8"
136+
# before the introduction of multiuser auth
137+
begin_test "ghe-backup management console does not backup argon secret"
137138
(
138139
set -e
139140

140-
git config -f "$GHE_REMOTE_DATA_USER_DIR/common/secrets.conf" secrets.manage-auth.argon-secret "fake pw"
141-
GHE_REMOTE_VERSION=3.7.0 ghe-backup
142-
141+
GHE_REMOTE_VERSION=3.7.0 ghe-backup -v | grep -q "management console argon2 secret not set" && exit 1
143142
[ ! -f "$GHE_DATA_DIR/current/manage-argon-secret" ]
144143
)
145144
end_test
146145

147146
# multiuser auth introduced in ghes version 3.8
148-
begin_test "ghe-backup management console argon2 secret"
147+
begin_test "ghe-backup management console backs up argon secret"
149148
(
150149
set -e
151150

test/testlib.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -448,7 +448,7 @@ verify_all_backedup_data() {
448448
[ "$(cat "$GHE_DATA_DIR/current/manage-password")" = "fake password hash data" ]
449449

450450
# verify manage-argon-secret file was backed up
451-
if [ "$(version $GHE_REMOTE_VERSION)" -gt "$(version 3.7.0)" ]; then
451+
if ! [ "$(version $GHE_REMOTE_VERSION)" -lt "$(version 3.8.0)" ]; then
452452
[ "$(cat "$GHE_DATA_DIR/current/manage-argon-secret")" = "fake argon2 secret" ]
453453
fi
454454

0 commit comments

Comments
 (0)