security: hardening по результатам аудита безопасности
This commit is contained in:
@@ -3,6 +3,7 @@ package backup
|
||||
import (
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"encoding/hex"
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
@@ -52,7 +53,6 @@ func RunOnce(ctx context.Context, cfg *config.Config) error {
|
||||
)
|
||||
|
||||
now := time.Now()
|
||||
timestamp := now.UTC().Format("20060102-150405")
|
||||
pgDumpOpts := domainpgdump.Options{
|
||||
Host: cfg.PG.Host,
|
||||
Port: cfg.PG.Port,
|
||||
@@ -60,7 +60,7 @@ func RunOnce(ctx context.Context, cfg *config.Config) error {
|
||||
User: cfg.PG.User,
|
||||
Password: cfg.PG.Password,
|
||||
ExcludeTables: cfg.PG.ExcludeTables,
|
||||
Key: fmt.Sprintf("synapse-%s.dump.pqenc", timestamp),
|
||||
Key: ArtifactKey(now),
|
||||
}
|
||||
|
||||
if err := runner.Run(ctx, pgDumpOpts, recipients, sink, rand.Reader); err != nil {
|
||||
@@ -73,3 +73,22 @@ func RunOnce(ctx context.Context, cfg *config.Config) error {
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// ArtifactKey returns a backup file name that includes a UTC timestamp plus a
|
||||
// short random suffix so that two backups started in the same second do not
|
||||
// collide.
|
||||
func ArtifactKey(timestamp time.Time) string {
|
||||
var randomBytes [3]byte
|
||||
if _, err := rand.Read(randomBytes[:]); err != nil {
|
||||
return fmt.Sprintf(
|
||||
"synapse-%s-%09d.dump.pqenc",
|
||||
timestamp.UTC().Format("20060102-150405"),
|
||||
timestamp.Nanosecond(),
|
||||
)
|
||||
}
|
||||
return fmt.Sprintf(
|
||||
"synapse-%s-%s.dump.pqenc",
|
||||
timestamp.UTC().Format("20060102-150405"),
|
||||
hex.EncodeToString(randomBytes[:]),
|
||||
)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user