Skip to content

Save the setup key and config files with owner-only permissions - #279

Open
aharoitx wants to merge 1 commit into
bitpay:8.0.xfrom
aharoitx:fix/im191-setup-file-permissions
Open

aharoitx wants to merge 1 commit into
bitpay:8.0.xfrom
aharoitx:fix/im191-setup-file-permissions

Conversation

@aharoitx

@aharoitx aharoitx commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Summary

bitpay_setup.py saved two files with the default mode (usually 0644), so any local user could read them:

  • private_key.pem: the merchant's private key.
  • bitpay.config.json: the API tokens, and the private key too when the "plain text" option is used.

Both files are now saved with mode 0600 (only the owner can read and write).

Changes

  • New helper write_secret_file in src/bitpay/utils/secret_file.py. It creates the file with 0600 and runs chmod before and after writing. The mode given to os.open only applies to new files, so chmod also fixes files left by an older setup run.
  • bitpay_setup.py uses the helper for both files.
  • New unit tests in tests/unit/utils/test_secret_file.py.

On Windows, chmod only controls the read-only flag, so this change does nothing there. The tests skip on Windows.

Testing

  • black --check src/, mypy src/, mypy -p src: OK
  • pytest -m unit: 96 passed (93 existing + 3 new)
  • Manual: ran the setup with umask 022. Before: both files 0644. After: both 0600, also when the files already existed with 0644.
  • The client still loads the generated config and key (Client.create_client_by_config_file_path).

Jira: IM-191

The setup script wrote the private key file and the config file with
the default mode (usually 0644). Both could be read by any local user.
The config file holds the API tokens, and with the "plain text" option
it also holds the private key.

Both files are now written with mode 0600. If the file already exists
from an earlier run, its permissions are tightened too, since the mode
given to os.open only applies when a file is created.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants