63d0a5e41440ea0cfc5ca5b77fa9f38bb3abf590

Author
Michael Aquilina <michaelaquilina@gmail.com>
Committer
Michael Aquilina <michaelaquilina@gmail.com>
Date

Message

Warn the user when a .venv file has weak permissions

Diff

 1diff --git a/autoswitch_virtualenv.plugin.zsh b/autoswitch_virtualenv.plugin.zsh
 2index ff5eb9d5d8292289c4919a1d21389c5c6780d808..437f27fa2aa2c5d158492abc72051fe4673bcea4 100644
 3--- a/autoswitch_virtualenv.plugin.zsh
 4+++ b/autoswitch_virtualenv.plugin.zsh
 5@@ -27,10 +27,18 @@ function check_venv()
 6         SWITCH_TO=""
 7 
 8         if [[ -f ".venv" ]]; then
 9-          if [[ "$(stat -c %u .venv)" != "$(id -u)" ]]; then
10+          file_owner="$(stat -c %u .venv)"
11+          file_permissions="$(stat -c %a .venv)"
12+
13+          if [[ "$file_owner" != "$(id -u)" ]]; then
14             echo "AUTOSWITCH WARNING: Found a .venv file but it is not owned by the current user"
15             echo "This will not be activated to prevent potentially malicious actions"
16             echo "Change ownership of .venv to '$USER' to fix this"
17+          elif [[ "$file_permissions" != "600" ]]; then
18+            echo "AUTOSWITCH WARNING:"
19+            echo "Found a .venv file with weak permission settings ($file_permissions)."
20+            echo "You should change this to 600."
21+            echo "Run the following command to fix this: chmod 600 .venv"
22           else
23             SWITCH_TO="$(cat .venv)"
24             AUTOSWITCH_PROJECT="$PWD"