From adf349b846bedcdd94b180e5d0615d8179705c5a Mon Sep 17 00:00:00 2001 From: Oleg Vasilev Date: Wed, 5 Jun 2019 22:58:03 +0300 Subject: [PATCH] First code push --- .travis.yml | 8 +++++ CHANGELOG.md | 17 ++++++++++ README.md | 25 +++++++++++++++ src/gaspass/main.go | 61 ++++++++++++++++++++++++++++++++++++ src/main.go | 75 +++++++++++++++++++++++++++++++++++++++++++++ src/sometest.goo | 11 +++++++ 6 files changed, 197 insertions(+) create mode 100644 .travis.yml create mode 100644 CHANGELOG.md create mode 100644 README.md create mode 100644 src/gaspass/main.go create mode 100644 src/main.go create mode 100644 src/sometest.goo diff --git a/.travis.yml b/.travis.yml new file mode 100644 index 0000000..3e4dd66 --- /dev/null +++ b/.travis.yml @@ -0,0 +1,8 @@ +--- + +dist: xenial +language: go + +go: + - master + diff --git a/CHANGELOG.md b/CHANGELOG.md new file mode 100644 index 0000000..0812c8b --- /dev/null +++ b/CHANGELOG.md @@ -0,0 +1,17 @@ +# Changelog +All notable changes to this project will be documented in this file. + +The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), +and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). + +## [Unreleased] + +## [1.0.0] - 2017-06-20 +### Added + + + + + +[Unreleased]: https://github.com/olivierlacan/keep-a-changelog/compare/v1.0.0...HEAD +[1.0.0]: https://github.com/olivierlacan/keep-a-changelog/compare/v0.3.0...v1.0.0 \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 0000000..c94e9ac --- /dev/null +++ b/README.md @@ -0,0 +1,25 @@ +# gaspass +Store passwords without actually storing them + +## How does it work? +Ose one password for access all other passwords, but в отличии от does not store them on disk or in memory at all. +Gaspass is more a password generator than password manager or store tool. Every run you will get the password and this password will be the same if you use the same parameters like length, character set, resource and private key. +Work scheme is very similar to [lesspass](https://github.com/lesspass/lesspass), but uses modern [argon2id](https://en.wikipedia.org/wiki/Argon2) KDF (key derivation function) instead of PBKDF2-SHA1. + +## Is it secure? +Generally yes, but it depends on private key quality and "защиты ключа" + + + +## ToDo +[] Tests +[] SECURITY.md +[] Resource management +[] GUI + + + +Это шобы версии текстов основного файла + +Compare this version with version of localized file to make sure toy read an actual information. +README.md version 0 \ No newline at end of file diff --git a/src/gaspass/main.go b/src/gaspass/main.go new file mode 100644 index 0000000..cba8df1 --- /dev/null +++ b/src/gaspass/main.go @@ -0,0 +1,61 @@ +package gaspass + +import ( + "encoding/binary" + "error" + "golang.org/x/crypto/argon2" +) + +const ( + CharsLower string = "abcdefghijklmnopqrstuvwxyz" + CharsUpper string = "ABCDEFGHIJKLMNOPQRSTUVWXYZ" + CharsNumbers string = "0123456789" + // !#$%&'()*+,-./:;<=>?@[\]^_{|}~`" + CharsSpecials string = "\x21\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x3a\x3b\x3c\x3d\x3e\x3f\x40\x5b\x5c\x5d\x5e\x5f\x7b\x7c\x7d\x7e\x60\x22" +) + +const ( + argonMemory uint32 = 128 * 1024 // KiB + argonIters uint32 = 24 + argonThreads uint8 = 3 +) + +type Params struct { + PrivKey []byte + Salt []byte + Counter []byte // Actually it is a part of argon salt so let it be the same type + PassLength uint32 + UseLower bool + UseUpper bool + UseNumber bool + UseSpecials bool +} + +func (p *Params) GeneratePassword() (string, error) { + // TODO: Check PassLength <= MAX_UINT32/8 + + if !(g.UseLower && p.UseUpper && p.UseNumbers && p.UseSpecials) { + return nil, error.New("Use at least one character group.") // CHECK ERROR DECLARATION + } + if p.UseLower { + charSet += charsLower + } + if p.UseUpper { + charSet += charsUpper + } + if p.UseNumbers { + charSet += charsNumbers + } + if p.UseSpecials { + charSet += charsSpecials + } + + dkey := argon2.IDKey(p.PrivKey, append(p.Counter, p.Salt), argonIters, argonMemory, argonThreads, p.PassLength*8) + + password := "" + for cn := 0; cn < len(dkey); cn += 8 { + password += string(charSet[binary.BigEndian.Uint64(dkey[cn:cn+8])%uint64(len(charSet))]) + } + + return password, nil +} diff --git a/src/main.go b/src/main.go new file mode 100644 index 0000000..b6060e3 --- /dev/null +++ b/src/main.go @@ -0,0 +1,75 @@ +package main + +import ( + "fmt" + "github.com/KawaiDesu/gaspass/gaspass" + "github.com/chzyer/readline" + flags "github.com/jessevdk/go-flags" + "os" +) + +type Resource struct { + PassLen int + Serial int + Host string +} + +func checkOpts() bool { + return true +} + +func processFlags() { + _, err := flags.Parse(&opts) + if flags.WroteHelp(err) { + os.Exit(1) + } + +} + +var ( + opts struct { + CharsLower bool `short:"l" long:"lower" description:"Use lower-case characters for generating password"` + CharsUpper bool `short:"u" long:"upper" description:"Use upper-case characters for generating password"` + CharsNumbers bool `short:"n" long:"numeric" description:"Use numeric characters for generating password"` + CharsSpecials bool `short:"s" long:"specials" description:"Use speacial (punctuation) characters for generating password"` + Length int `short:"q" long:"quantity" default:"16" description:"Set number of characters in the password"` + Salt string `short:"r" long:"resource" description:"Resource name (url or some descriptive text) for which password will be generated"` + Counter string `short:"c" long:"counter" default:"0" description:"Serial number of the password for the same resource"` + ActionAdd bool `short:"A" long:"add" description:"Add resource record to the database"` + ActionRemove bool `short:"D" long:"delete" description:"Remove resource record from the database"` + ActionUseRes bool `short:"R" long:"use-resource" description:"Use existing resource"` + ActionList bool `short:"L" long:"list" description:"List resource records in the database"` + ActionBench bool `short:"B" long:"bench" description:"Run benchmark"` + } + + charSet string = "" +) + +func main() { + + processFlags() + + privKey, err := readline.Password("Enter your key:") + if err != nil { + println(err.Error()) + os.Exit(1) + } + + p := gaspass.Params{ + PrivKey: privKey, + Salt: []byte(opts.Salt), + Counter: []byte(opts.Counter), + PassLength: opts.Length, + UseLower: opts.CharsLower, + UseUpper: opts.CharsUpper, + UseNumber: opts.CharsNumbers, + UseSpecials: opts.CharsSpecials, + } + + resultPass, err := p.GeneratePassword() + if err != nil { + println(err.Error()) + os.Exit(1) + } + fmt.Println(resultPass) +} diff --git a/src/sometest.goo b/src/sometest.goo new file mode 100644 index 0000000..49315fe --- /dev/null +++ b/src/sometest.goo @@ -0,0 +1,11 @@ +package gaspass +/* +import "fmt" + +func ExampleGeneratePassword(){ + fmt.Println(GeneratePassword([]byte("asdfghjkl123"))) + // Output: + // `wPW`9'Ep$JH,@:7 + +} +*/ \ No newline at end of file