#!/bin/bash
# load-key.sh -- source this, do not execute it; it exports PRIVATE_KEY.
# Already provided (CI secret, systemd credential, and so on).
if [ -n "${PRIVATE_KEY:-}" ]; then
return 0 2>/dev/null || exit 0
fi
# A password manager keeps the key off disk in the clear. Prefer this.
if command -v pass &> /dev/null; then
PRIVATE_KEY=$(pass show crypto/privacy-boost)
export PRIVATE_KEY
return 0 2>/dev/null || exit 0
fi
# Plaintext file fallback. Create it owner-only:
# mkdir -p ~/.privacy-boost && chmod 700 ~/.privacy-boost
# touch ~/.privacy-boost/key && chmod 600 ~/.privacy-boost/key
KEY_FILE="${HOME}/.privacy-boost/key"
if [ -f "$KEY_FILE" ]; then
# Refuse a group- or world-readable key file rather than silently using it.
PERMS=$(stat -f '%Lp' "$KEY_FILE" 2>/dev/null || stat -c '%a' "$KEY_FILE")
if [ "$PERMS" != "600" ]; then
echo "Refusing to read $KEY_FILE: mode $PERMS, want 600" >&2
return 1 2>/dev/null || exit 1
fi
PRIVATE_KEY=$(cat "$KEY_FILE")
export PRIVATE_KEY
return 0 2>/dev/null || exit 0
fi
echo "No key available. Run privacy-boost interactively to be prompted." >&2
return 1 2>/dev/null || exit 1