Skip to main content

Code style: black

Secrethelper

Simple command line utility for handling secrets.

Important: USE AT YOUR OWN RISK!

Use Case 1

Some commands are needed frequently but they contain secrets. Examples:

  • oathtool -b --totp "PV3YEM43I22ISNWK" (based on a secret key create a time based one time password for 2FA)
  • git pull https://some.user%40host.org:foo-bar-password@git.myservice.com/reponame (git connection via https without being prompted for a password)

Obviously, it is insecure to store them unencrypted on your system (e.g. in your command history).

Solution: secrethelper reads a data file (secrets.toml) which contains encrypted versions of such commands, prompts for a password decrypts the relevant command, executes it and displays the result (and copies it into the clipboard). The actual secret is never shown.

Use Case 2

Some secrets (e. g.passwords) are important to memorize, but are needed only rarely. Thus, there are only few occations to practise them.

Solution: secrettrainer reads a data file (secrets.toml) which contains the (salted) hashes of such passwords. During a trainig session you are propted for some of them the correctness is determined by comparing the hashes.

Usage

secrethelper

  • secrethelper --help: Show help.
    • short version: -h
  • secrethelper --bootstrap-data: Create secrets.toml in suitable place. Example: ~/.local/share/secrethelper/ (depends on OS). The content is based on src/secrethelper/secrets-example.toml.
    • short version: -b
  • secrethelper --edit-data: Open secrets.toml in the default editor.
    • short version: -ed
  • secrethelper --edit-data [EDITOR]: Open secrets.toml in the specified editor.
    • short version: -ed [EDITOR]
    • example: --edit-data codium
  • secrethelper --encrypt: Prompt for password, then prompt for some arbitrary string. Disyplay the encrypted version of the string (also copied to the clipboard). This string can be pasted directly in secrets.toml
  • secrethelper --decrypt-and-execute [key]: Prompt for password, extract the encrypted command from secrets.toml, execute it and disyplay the result (also copied to the clipboard).
    • short version: -d [key]

secrettrainer

  • secrettrainer --help: Show help.
    • short version: -h
  • secrettrainer --create-training-data: Create training data: Prompt for password (salt), prompt for secret and display salted hash of the secret (also copied to clipboard). This string can be pasted directly in secrets.toml in section [training]. An empty string quits the process.
    • short version: -ctd
  • secrettrainer (no options/arguments): Create a suffled list of keys from section [training], prompt for password (used as salt for hash), prompt for secrets, compare hash display ✓ or ✗. Train 10 rounds. Empty string quits this process.

Installation and Preparation

In first terminal:

  • pip install pysecrethelper: Install the software.
  • secrethelper -b Bootstrap data file secrets.toml.
  • secrethelper -ed Open secrets.toml in default editor.

In another terminal:

  • secrethelper -e: Create and copy encrypted string → you can paste it into secret.toml in section [commands]. This is for use case 1 (see above).
  • secrethelper -ctd: Create hashes and copy salted hashes for training → you can paste it into secret.toml in section [training]. This is for use case 2 (see above).

Metadata

Release files for pysecrethelper 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pysecrethelper 0.1.1
File Size Uploaded
pysecrethelper-0.1.1.tar.gz 20.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pysecrethelper 0.1.1
File Interpreter ABI Platform
pysecrethelper-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 40.9 kB

Release files / pysecrethelper-0.1.1.tar.gz

Download URL pysecrethelper-0.1.1.tar.gz
Size 20.7 kB
Tags Source
SHA-256 checksum
How to use checksums
bd52c3f66d17c9307206e6013a6b17f875e22f6ed9507907f7207791caa3baaa
BLAKE2b-256 checksum
How to use checksums
0a225bccbfbec52a23caa0ca21a02952376ce128a1ade6a97c74a45c83ed92ec
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.4

Release files / pysecrethelper-0.1.1-py3-none-any.whl

Download URL pysecrethelper-0.1.1-py3-none-any.whl
Size 20.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d93b9932b221615890ecc4ccec871207f90d3bce78a50986c61174256ccc02db
BLAKE2b-256 checksum
How to use checksums
5779471b9026a832ebe729959398792059b691ed2eb487e5283cb472e96135ed
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.4

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page