Files
ngit-grasp/nix
DanConwayDev 002e6ab9f5 fix(config): secure persistent relay owner keys on load
Older ngit-grasp releases created .relay-owner.nsec with the process umask, leaving existing deployments at mode 0644 even after new key generation was fixed. Moving the secret out of argv would not repair that persistent local exposure.

Restrict an existing fallback key to mode 0600 before reading it and fail startup with the affected path when the permissions cannot be secured. Systemd credential source files remain untouched because their ownership and mode belong to the operator or secret manager.
2026-07-27 15:23:21 +01:00
..