fix(auth): atomically secure Windows lock creation
This commit is contained in:
@@ -72,20 +72,21 @@ func WriteCanonicalNewFile(path string, contents []byte, mode os.FileMode) error
|
||||
} else if !errors.Is(err, os.ErrNotExist) {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
file, err := os.OpenFile(path, os.O_WRONLY|os.O_CREATE|os.O_EXCL, mode)
|
||||
file, err := createCanonicalNewPrivateFile(path, mode)
|
||||
if err != nil {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
defer file.Close()
|
||||
if err := ProtectPrivateRegular(path); err != nil {
|
||||
_ = os.Remove(path)
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
if _, err := file.Write(contents); err != nil {
|
||||
_ = file.Close()
|
||||
_ = os.Remove(path)
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
if err := file.Sync(); err != nil {
|
||||
_ = file.Close()
|
||||
_ = os.Remove(path)
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
if err := file.Close(); err != nil {
|
||||
_ = os.Remove(path)
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user