Repository navigation
feat: Add GitHub GPG key integration with JIT fetching - #95
Conversation
Implements GitHub public key fetching to enable encryption for GitHub users. This feature allows users to fetch and use GPG keys from any GitHub user's public profile, with support for just-in-time fetching during encryption. New Features: - Fetch GitHub user GPG keys via dedpaste keys --github <username> - Just-in-time key fetching when encrypting with --for github:username - Custom naming support with --github-name option - User verification with --verify flag - Full integration with enhanced interactive mode Implementation Details: - Created cli/githubUtils.ts with GitHub API integration - Updated keyManager.ts to store GitHub keys in ~/.dedpaste/github/ - Extended encryptionUtils.ts with JIT GitHub key fetching - Added GitHub type definitions and database schema - Updated CLI help text and examples - Full support in enhanced interactive mode Usage: dedpaste keys --github username dedpaste send --encrypt --for github:username --pgp The implementation follows the existing Keybase integration pattern and supports the github:username prefix for key resolution. Resolves #94 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
There was a problem hiding this comment.
Pull Request Overview
This PR implements GitHub GPG key integration, enabling users to fetch and encrypt content using public GPG keys from any GitHub user's profile. The feature includes just-in-time key fetching during encryption operations and full integration with the CLI's interactive mode.
Key Changes:
- Added GitHub as a new key source type alongside existing self, friend, PGP, and Keybase types
- Implemented automatic fetching of GPG keys when encrypting with
--for github:username - Extended interactive mode to include GitHub as an import source option
Reviewed Changes
Copilot reviewed 8 out of 9 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
src/types/index.ts |
Added github to key type unions and introduced GitHubUser and GitHubKeyInfo interfaces |
cli/githubUtils.ts |
New utility module for GitHub API integration, key fetching, and validation (224 lines) |
cli/keyManager.ts |
Added GitHub key directory constant, database schema migration, and storage functions |
cli/unifiedKeyManager.ts |
Integrated GitHub import case into unified key management system |
cli/encryptionUtils.ts |
Implemented JIT key fetching for github: prefixed recipients |
cli/index.ts |
Added CLI options and help text for GitHub key operations |
cli/index.js |
Compiled JavaScript output of TypeScript changes |
cli/enhancedInteractiveMode.ts |
Extended interactive mode UI with GitHub key support across all relevant flows |
| return true; | ||
| } else if (type === 'github' && db.keys.github[name]) { | ||
| // Remove the key file | ||
| const githubPath = typeof db.keys.github[name].path === 'string' ? db.keys.github[name].path : db.keys.github[name].path.public; |
There was a problem hiding this comment.
[nitpick] The path property access pattern is duplicated from the keybase block above. Consider extracting this into a helper function to reduce code duplication and improve maintainability. For example: getKeyPath(db.keys.github[name])
| } | ||
|
|
||
| // Sanitize username (GitHub usernames are alphanumeric + hyphens) | ||
| const sanitizedUsername = username.trim(); |
There was a problem hiding this comment.
The regex pattern for GitHub username validation should include a comment explaining the validation rules (alphanumeric characters and hyphens, cannot start or end with hyphen). This makes the code more maintainable and easier to understand.
| const sanitizedUsername = username.trim(); | |
| const sanitizedUsername = username.trim(); | |
| // Validate GitHub username: | |
| // - Only alphanumeric characters and hyphens are allowed | |
| // - Cannot start or end with a hyphen | |
| // - Cannot be empty |
| if (keyInfo.source === 'self') { | ||
| filename = exportPrivate ? 'dedpaste_private_key.pem' : 'dedpaste_public_key.pem'; | ||
| } else if (keyInfo.type === 'pgp' || keyInfo.type === 'keybase') { | ||
| } else if (keyInfo.type === 'pgp' || keyInfo.type === 'keybase' || keyInfo.type === 'github') { |
There was a problem hiding this comment.
[nitpick] This condition is checking multiple key types that all use .asc extension. Consider grouping these types into a constant array (e.g., PGP_BASED_KEY_TYPES) and using includes() to make the code more maintainable when adding future PGP-based key types.
|
closes #94 |
Version bump type: minor PR: #95 Title: feat: Add GitHub GPG key integration with JIT fetching
This commit fixes the TypeScript errors that were causing the release build to fail after merging PR #95 (GitHub GPG key integration). Changes: - Add missing 'github' and 'githubName' properties to KeysOptions interface - Fix type mismatch in githubUtils.ts by mapping PgpKeyInfo to GitHubKeyAddInfo - Map keyId to fingerprint (importPgpKey returns keyId, not fingerprint) - Convert email from 'string | null' to 'string | undefined' using nullish coalescing - Add 'github' to ImportOptions source type in unifiedKeyManager.ts Fixes build errors: - Property 'github' does not exist on type 'KeysOptions' (cli/index.ts:885-903) - Property 'githubName' does not exist on type 'KeysOptions' (cli/index.ts:897) - Property 'fingerprint' does not exist on type 'PgpKeyInfo' (cli/githubUtils.ts:177, 185) - Type 'string | null' is not assignable to type 'string | undefined' (cli/githubUtils.ts:186) - Argument of type 'PgpKeyInfo' is not assignable to parameter of type 'GitHubKeyAddInfo' (cli/githubUtils.ts:173) - Type '"github"' is not comparable to ImportOptions source types (cli/unifiedKeyManager.ts:664) Related to: #94 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
Summary
Implements GitHub public key fetching to enable encryption for GitHub users, as requested in issue #94. Users can now fetch and use GPG keys from any GitHub user's public profile, with support for just-in-time fetching during encryption.
Key Features
dedpaste keys --github <username>--for github:username--github-nameoption--verifyflagImplementation Details
New Files:
cli/githubUtils.ts- GitHub API integration (224 lines)https://github.com/{username}.gpgModified Files:
src/types/index.ts- GitHub types and database schemacli/keyManager.ts- GitHub key storage in~/.dedpaste/github/cli/encryptionUtils.ts- JIT key fetching during encryptioncli/index.ts- CLI commands and help textcli/enhancedInteractiveMode.ts- Interactive mode supportcli/unifiedKeyManager.ts- Unified key managementUsage Examples