Documentation
¶
Overview ¶
Package securetemp resolves ctxcop's shared temp parent under a check that the current user controls it.
Index ¶
Constants ¶
const DirName = "ctxcop"
DirName is the shared parent under os.TempDir(). SessionEnd sweeps it for per-invocation subdirectories, so it has to stay a single known path.
Variables ¶
This section is empty.
Functions ¶
func Dir ¶
Dir returns a fresh per-invocation directory for redacted copies.
It prefers the shared parent so SessionEnd can sweep it, but falls back to an unpredictable directory directly under os.TempDir() when that parent fails validation. The fallback matters: callers treat an error here as "skip the redaction" and pass the ORIGINAL file through, so failing closed on a hostile parent would hand the agent the raw secret — strictly worse than the redirection #82 is about. The fallback name is random, so it can't be pre-planted.
func Parent ¶
Parent returns the validated shared parent, creating it if absent.
The redacted copies written beneath it are the plaintext-minus-secrets view of files the agent read, so a parent another user controls redirects them. os.MkdirAll would silently accept a pre-planted symlink; os.Mkdir plus an Lstat rejects one. (#82)
Types ¶
This section is empty.