Warn the user when a .venv file has weak permissions
Diff
1diff --git a/autoswitch_virtualenv.plugin.zsh b/autoswitch_virtualenv.plugin.zsh
2index ff5eb9d5d8292289c4919a1d21389c5c6780d808..437f27fa2aa2c5d158492abc72051fe4673bcea4 100644
3--- a/autoswitch_virtualenv.plugin.zsh
4+++ b/autoswitch_virtualenv.plugin.zsh
5@@ -27,10 +27,18 @@ function check_venv()
6 SWITCH_TO=""
7 8 if [[ -f ".venv" ]]; then
9- if [[ "$(stat -c %u .venv)" != "$(id -u)" ]]; then
10+ file_owner="$(stat -c %u .venv)"
11+ file_permissions="$(stat -c %a .venv)"
12+
13+ if [[ "$file_owner" != "$(id -u)" ]]; then
14 echo "AUTOSWITCH WARNING: Found a .venv file but it is not owned by the current user"
15 echo "This will not be activated to prevent potentially malicious actions"
16 echo "Change ownership of .venv to '$USER' to fix this"
17+ elif [[ "$file_permissions" != "600" ]]; then
18+ echo "AUTOSWITCH WARNING:"
19+ echo "Found a .venv file with weak permission settings ($file_permissions)."
20+ echo "You should change this to 600."
21+ echo "Run the following command to fix this: chmod 600 .venv"
22 else
23 SWITCH_TO="$(cat .venv)"
24 AUTOSWITCH_PROJECT="$PWD"