Paste a secret, get a link, send it. The first person to open it and press
Reveal sees the secret; the link dies at that moment. The recipient needs a
browser and nothing else — no account, no client, no installed tooling.
The server cannot read what it stores. AES-256-GCM happens in the browser and
the key lives in the URL fragment, which browsers never transmit, so hushd
holds ciphertext and no key material. That is a property of where the key sits
rather than a promise about our conduct, which is why there is deliberately no
endpoint accepting a plaintext secret and no server-side-encryption fallback:
two guarantees behind one URL would be worse than one honest guarantee.
Three decisions carry the design:
* GET /s/{id} touches NO storage, not even to check existence. Slack, Teams,
WhatsApp, iMessage and Outlook Safe Links all fetch a URL before a human
sees it, so destroying on GET would destroy most secrets in transit and the
recipient's "already used" would be indistinguishable from interception.
Only POST /reveal consumes. Bot user-agent detection is an arms race;
removing the side effect from GET is not. Pinned by
TestGettingTheRevealPageNeverConsumesTheSecret.
* Destruction is one Redis GETDEL, which is atomic. GET-then-DEL has a window
where two simultaneous readers both win, and for a one-time secret that
window is the product. The store contract demands atomicity and the same
concurrency test runs against both implementations.
* Missing, already-revealed, expired and evicted are ONE indistinguishable
410. Separating them would confirm to a prober that a given link was real.
The secret id IS the capability, so secret.ID is a struct whose every
accidental path — %v, %s, String(), slog, json.Marshal — emits a redacted
handle or refuses, and the raw value needs an explicit Value(). The first
version tried to prevent leaks by implementing no String() at all; its own test
caught that Go's fmt prints unexported fields anyway, so forbidding the method
had removed the control rather than the leak.
Operationally: structured JSON on stdout in the fleet's wire format, which
Vector already collects with no annotation; six hush_* metrics on the chassis
registry with no id, IP or path in any label; five alert rules wired into
vmalert. The public Ingress enumerates /, /s/ and /api/ so /metrics, /healthz
and /readyz share the port but are unreachable from the internet — no
basic-auth middleware to maintain and get wrong.
Dependencies are vendored because go-chassis is private: the Woodpecker test
step and the in-cluster Kaniko build both run -mod=vendor with GOPROXY=off and
hold no git credential.
cmd/hush-mcp is a stdio MCP server doing the same client-side crypto locally,
so using hush from an agent preserves the same guarantee as using it from a
browser.
119 lines
3.8 KiB
Go
119 lines
3.8 KiB
Go
package redis
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"net"
|
|
"time"
|
|
|
|
"github.com/redis/go-redis/v9/internal/interfaces"
|
|
"github.com/redis/go-redis/v9/push"
|
|
)
|
|
|
|
// ErrInvalidCommand is returned when an invalid command is passed to ExecuteCommand.
|
|
var ErrInvalidCommand = errors.New("invalid command type")
|
|
|
|
// ErrInvalidPool is returned when the pool type is not supported.
|
|
var ErrInvalidPool = errors.New("invalid pool type")
|
|
|
|
// newClientAdapter creates a new client adapter for regular Redis clients.
|
|
func newClientAdapter(client *baseClient) interfaces.ClientInterface {
|
|
return &clientAdapter{client: client}
|
|
}
|
|
|
|
// clientAdapter adapts a Redis client to implement interfaces.ClientInterface.
|
|
type clientAdapter struct {
|
|
client *baseClient
|
|
}
|
|
|
|
// GetOptions returns the client options.
|
|
func (ca *clientAdapter) GetOptions() interfaces.OptionsInterface {
|
|
return &optionsAdapter{options: ca.client.opt}
|
|
}
|
|
|
|
// GetPushProcessor returns the client's push notification processor.
|
|
func (ca *clientAdapter) GetPushProcessor() interfaces.NotificationProcessor {
|
|
return &pushProcessorAdapter{processor: ca.client.pushProcessor}
|
|
}
|
|
|
|
// optionsAdapter adapts Redis options to implement interfaces.OptionsInterface.
|
|
type optionsAdapter struct {
|
|
options *Options
|
|
}
|
|
|
|
// GetReadTimeout returns the read timeout.
|
|
func (oa *optionsAdapter) GetReadTimeout() time.Duration {
|
|
return oa.options.ReadTimeout
|
|
}
|
|
|
|
// GetWriteTimeout returns the write timeout.
|
|
func (oa *optionsAdapter) GetWriteTimeout() time.Duration {
|
|
return oa.options.WriteTimeout
|
|
}
|
|
|
|
// GetNetwork returns the network type.
|
|
func (oa *optionsAdapter) GetNetwork() string {
|
|
return oa.options.Network
|
|
}
|
|
|
|
// GetAddr returns the connection address.
|
|
func (oa *optionsAdapter) GetAddr() string {
|
|
return oa.options.Addr
|
|
}
|
|
|
|
// GetNodeAddress returns the address of the Redis node as reported by the server.
|
|
// For cluster clients, this is the endpoint from CLUSTER SLOTS before any transformation.
|
|
// For standalone clients, this defaults to Addr.
|
|
func (oa *optionsAdapter) GetNodeAddress() string {
|
|
return oa.options.NodeAddress
|
|
}
|
|
|
|
// IsTLSEnabled returns true if TLS is enabled.
|
|
func (oa *optionsAdapter) IsTLSEnabled() bool {
|
|
return oa.options.TLSConfig != nil
|
|
}
|
|
|
|
// GetProtocol returns the protocol version.
|
|
func (oa *optionsAdapter) GetProtocol() int {
|
|
return oa.options.Protocol
|
|
}
|
|
|
|
// GetPoolSize returns the connection pool size.
|
|
func (oa *optionsAdapter) GetPoolSize() int {
|
|
return oa.options.PoolSize
|
|
}
|
|
|
|
// NewDialer returns a new dialer function for the connection.
|
|
func (oa *optionsAdapter) NewDialer() func(context.Context) (net.Conn, error) {
|
|
baseDialer := oa.options.NewDialer()
|
|
return func(ctx context.Context) (net.Conn, error) {
|
|
// Extract network and address from the options
|
|
network := oa.options.Network
|
|
addr := oa.options.Addr
|
|
return baseDialer(ctx, network, addr)
|
|
}
|
|
}
|
|
|
|
// pushProcessorAdapter adapts a push.NotificationProcessor to implement interfaces.NotificationProcessor.
|
|
type pushProcessorAdapter struct {
|
|
processor push.NotificationProcessor
|
|
}
|
|
|
|
// RegisterHandler registers a handler for a specific push notification name.
|
|
func (ppa *pushProcessorAdapter) RegisterHandler(pushNotificationName string, handler interface{}, protected bool) error {
|
|
if pushHandler, ok := handler.(push.NotificationHandler); ok {
|
|
return ppa.processor.RegisterHandler(pushNotificationName, pushHandler, protected)
|
|
}
|
|
return errors.New("handler must implement push.NotificationHandler")
|
|
}
|
|
|
|
// UnregisterHandler removes a handler for a specific push notification name.
|
|
func (ppa *pushProcessorAdapter) UnregisterHandler(pushNotificationName string) error {
|
|
return ppa.processor.UnregisterHandler(pushNotificationName)
|
|
}
|
|
|
|
// GetHandler returns the handler for a specific push notification name.
|
|
func (ppa *pushProcessorAdapter) GetHandler(pushNotificationName string) interface{} {
|
|
return ppa.processor.GetHandler(pushNotificationName)
|
|
}
|