52 lines
1.4 KiB
Bash
Executable File
52 lines
1.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
umask 077
|
|
|
|
SCRIPT_DIR="$(CDPATH= cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)"
|
|
# shellcheck source=lib.sh
|
|
source "${SCRIPT_DIR}/lib.sh"
|
|
|
|
require_command git
|
|
|
|
if [[ "$#" -ne 2 ]]; then
|
|
printf 'Verwendung: %s AUSGABEDATEI ABSOLUTER_ASSET_ROOT\n' "$0" >&2
|
|
exit 2
|
|
fi
|
|
|
|
output="$1"
|
|
asset_root="$2"
|
|
|
|
output_parent="$(CDPATH= cd -- "$(dirname -- "${output}")" && pwd -P)" || {
|
|
printf 'Das Ausgabeverzeichnis muss bereits existieren.\n' >&2
|
|
exit 1
|
|
}
|
|
output="${output_parent}/$(basename -- "${output}")"
|
|
project_root="$(git -C "${TOOL_ROOT}" rev-parse --show-toplevel)"
|
|
project_root="$(CDPATH= cd -- "${project_root}" && pwd -P)"
|
|
case "${output}" in
|
|
"${project_root}"|"${project_root}"/*)
|
|
printf 'Die Secret-Datei darf nicht im Repository liegen.\n' >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
[[ "${asset_root}" == /* ]] || {
|
|
printf 'Asset-Root muss absolut sein.\n' >&2
|
|
exit 1
|
|
}
|
|
[[ ! -e "${output}" ]] || {
|
|
printf 'Ausgabedatei existiert bereits; sie wird nicht überschrieben.\n' >&2
|
|
exit 1
|
|
}
|
|
|
|
if command -v openssl >/dev/null 2>&1; then
|
|
token="$(openssl rand -base64 48 | tr -d '\n')"
|
|
else
|
|
printf 'openssl wird zur sicheren Token-Erzeugung benötigt.\n' >&2
|
|
exit 1
|
|
fi
|
|
|
|
printf 'PROJECTCAPTURE_BLOCKBENCH_TOKEN=%q\nPROJECTCAPTURE_ASSET_ROOT=%q\n' \
|
|
"${token}" "${asset_root}" > "${output}"
|
|
chmod 0600 "${output}"
|
|
printf 'Lokale Environment-Datei erstellt (Token wird nicht ausgegeben): %s\n' "${output}"
|