-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathmigrate_keys.py
More file actions
96 lines (76 loc) 路 3.07 KB
/
Copy pathmigrate_keys.py
File metadata and controls
96 lines (76 loc) 路 3.07 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
"""Migrate API keys from the local 'API OpenRouter.txt' into the OS keyring.
Run once after pulling updates:
python migrate_keys.py
Reads credentials from the plaintext file, stores each via core.secure_store
(which writes sensitive keys to the OS credential vault), and redacts the
plaintext file to a template so secrets are no longer sitting on disk.
The plaintext file is already git-ignored, but this removes the at-rest secret.
Use SSE rotate/supersede keys upstream independently if you suspect exposure.
"""
import re
import sys
from pathlib import Path
from core.secure_store import secure_set
KEY_FILE = Path(__file__).parent / "API OpenRouter.txt"
# Maps human text search -> (store key). Key names must match _SENSITIVE_KEYS.
MAPPING = {
"PEXELS API": "pexels_api_key",
"PIXABAY API": "pixabay_api_key",
"OpenRouter (gratis)": None, # section header, not a key; handle its API Key line
}
def _find_key(text: str) -> str | None:
"""Return first token that looks like an API key."""
# Common API key formats.
patterns = [
r"\b(sk-or-v1-[A-Za-z0-9_-]+)\b", # OpenRouter
r"\b([A-Za-z0-9]{32})\b", # generic 32-char (Pexels the like)
r"\b(\d{8}-[A-Za-z0-9-]{20})\b", # Pixabay
r"\b(AIza[0-9A-Za-z_\-]{20,})\b", # Google
r"\b(sk-[A-Za-z0-9]{30,})\b", # OpenAI/others
]
for pat in patterns:
m = re.search(pat, text)
if m:
return m.group(1)
return None
def migrate() -> dict:
if not KEY_FILE.exists():
print(f"File tidak ditemukan: {KEY_FILE}")
return {}
raw = KEY_FILE.read_text(encoding="utf-8")
collected = {}
# Capture OpenRouter API key (first sk-or-v1 token).
or_key = _find_key(raw)
if or_key:
collected["openrouter_api_key"] = or_key
# Pexels & Pixabay (24-char + dash formats).
pex = re.search(r"PEXELS API\s*:\s*([A-Za-z0-9_-]+)", raw, re.IGNORECASE)
if pex:
collected["pexels_api_key"] = pex.group(1)
pix = re.search(r"PIXABAY API\s*:\s*([A-Za-z0-9_-]+)", raw, re.IGNORECASE)
if pix:
collected["pixabay_api_key"] = pix.group(1)
for key, value in collected.items():
secure_set(key, value)
print(f" stored -> {key}")
return collected
def redact(scheme: dict) -> None:
"""Replace secret values in the text file with placeholders."""
lines = KEY_FILE.read_text(encoding="utf-8").splitlines()
new_lines = []
for line in lines:
new = line
for secret in scheme.values():
if secret and secret in new:
new = new.replace(secret, "[REDACTED stored in OS keyring]")
new_lines.append(new)
KEY_FILE.write_text("\n".join(new_lines), encoding="utf-8")
print(f"\nRedacted {KEY_FILE.name} (raw secrets replaced with placeholders).")
if __name__ == "__main__":
migrated = migrate()
if migrated:
redact(migrated)
print("\nSelesai. Rotasi key di dashboard provider jika perlu.")
else:
print("Tidak ada key yang dikenali. Tidak ada perubahan.")
sys.exit(1)