fix(auth): atomically secure Windows lock creation
This commit is contained in:
@@ -41,6 +41,19 @@ func ProtectPrivateRegular(path string) error {
|
||||
return ValidatePrivateRegular(path)
|
||||
}
|
||||
|
||||
func createCanonicalNewPrivateFile(path string, mode os.FileMode) (*os.File, error) {
|
||||
file, err := os.OpenFile(path, os.O_WRONLY|os.O_CREATE|os.O_EXCL, mode)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if err := ProtectPrivateRegular(path); err != nil {
|
||||
_ = file.Close()
|
||||
_ = os.Remove(path)
|
||||
return nil, ErrUnsafeFile
|
||||
}
|
||||
return file, nil
|
||||
}
|
||||
|
||||
// ValidatePrivateRegular requires a canonical, single-link private regular file.
|
||||
func ValidatePrivateRegular(path string) error {
|
||||
if err := ValidateCanonicalPath(path); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user