First cut at support for new PAM USS config entries for GitHub. - #2259
Closed
mfordkeeper wants to merge 27 commits into
Closed
First cut at support for new PAM USS config entries for GitHub.#2259mfordkeeper wants to merge 27 commits into
mfordkeeper wants to merge 27 commits into
Conversation
* Add gchat-app-setup for Google Chat Service Mode integration. Collect and store Google Chat/Pub/Sub credentials in a vault record and generate docker-compose, matching the Slack/Teams setup flow. * Require a file path for Google Chat service account JSON. Drop unreliable inline JSON paste at the gchat-app-setup prompt; service account keys are too large for single-line terminal input. * updated to latest annotations * addressed review comments * Validate GChat project ID against Pub/Sub paths and the service account. Reject full resource names whose project differs from GOOGLE_PROJECT_ID, require confirmation when the project override disagrees with the SA JSON, and drop unused _is_valid_subscription_id.
Every authentication branch in the entrypoint ended with an unconditional `sleep infinity`, so a container invoked with a one-shot command printed its result and then never exited. That made the image unusable from scripts, since the command's exit status never propagated, and there was no way to opt out. Only failing commands exited, and then only incidentally, via `set -e`. Replace the eight unconditional `sleep infinity` calls with a single lifecycle decision: stay resident only for service mode, for an invocation with no command, or when KEEPER_KEEP_ALIVE is set; otherwise exit with the wrapped command's status. Three further problems in the same lifecycle code: - The container ignored SIGTERM. Bash defers trap handlers while a foreground child runs, so `sleep infinity` kept the existing EXIT/INT/TERM trap from ever firing: `docker stop` waited out the full grace period and then SIGKILLed, leaving the KSM config monitor uncleaned. Idle via a backgrounded sleep and `wait`, with explicit TERM/INT handlers. - Command arguments were flattened into a single string and re-split by word splitting, so any argument containing spaces (record titles, notes, search queries) reached Commander as several arguments. Carry them in an array. - The KSM one-shot path no longer starts the perpetual config monitor. It uploads config.json once so refreshed device state persists, then exits. Fixes #2264
The view action previously emitted flattened Name/Value rows even in JSON format. It now emits the complete record contents in the same structure as the get command: raw decrypted record data for typed (v3+) records, and get-style field names (login, password, login_url, custom_fields, totp, attachments) for legacy records, plus revision metadata (version, revision, modified_by, client_modified_time). This allows raw history diffs between revisions. Table output is unchanged. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Contributor
Author
|
Replaced with #2295 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.