Skip to content

feat: Add GitHub GPG key integration with JIT fetching - #95

Merged
anoncam merged 1 commit into
mainfrom
claude/plan-feature-implementation-011CUNWh39kygb1AZZkCmAj2
Oct 22, 2025
Merged

anoncam merged 1 commit into
mainfrom
claude/plan-feature-implementation-011CUNWh39kygb1AZZkCmAj2

Conversation

@anoncam

@anoncam anoncam commented Oct 22, 2025

Copy link
Copy Markdown
Owner

Summary

Implements GitHub public key fetching to enable encryption for GitHub users, as requested in issue #94. Users can now fetch and use GPG keys from any GitHub user's public profile, with support for just-in-time fetching during encryption.

Key Features

  • Fetch GitHub GPG keys: dedpaste keys --github <username>
  • Just-in-time fetching: Auto-fetches keys when encrypting with --for github:username
  • Custom naming: Support for --github-name option
  • User verification: Optional --verify flag
  • Full UI integration: Enhanced interactive mode includes GitHub key support

Implementation Details

New Files:

  • cli/githubUtils.ts - GitHub API integration (224 lines)
    • Fetches GPG keys from https://github.com/{username}.gpg
    • User verification via GitHub API
    • Comprehensive error handling

Modified Files:

  • src/types/index.ts - GitHub types and database schema
  • cli/keyManager.ts - GitHub key storage in ~/.dedpaste/github/
  • cli/encryptionUtils.ts - JIT key fetching during encryption
  • cli/index.ts - CLI commands and help text
  • cli/enhancedInteractiveMode.ts - Interactive mode support
  • cli/unifiedKeyManager.ts - Unified key management

Usage Examples

# Add a GitHub user's GPG key
dedpaste keys --github anoncam

# Add with custom name
dedpaste keys --github anoncam --github-name bob

# Encrypt for GitHub user (auto-fetches if needed)
echo "Secret password" | dedpaste send --encrypt --for github:anoncam --pgp

# Use enhanced interactive mode
dedpaste keys:enhanced  # GitHub appears in import sources

Implements GitHub public key fetching to enable encryption for GitHub users.
This feature allows users to fetch and use GPG keys from any GitHub user's
public profile, with support for just-in-time fetching during encryption.

New Features:
- Fetch GitHub user GPG keys via dedpaste keys --github <username>
- Just-in-time key fetching when encrypting with --for github:username
- Custom naming support with --github-name option
- User verification with --verify flag
- Full integration with enhanced interactive mode

Implementation Details:
- Created cli/githubUtils.ts with GitHub API integration
- Updated keyManager.ts to store GitHub keys in ~/.dedpaste/github/
- Extended encryptionUtils.ts with JIT GitHub key fetching
- Added GitHub type definitions and database schema
- Updated CLI help text and examples
- Full support in enhanced interactive mode

Usage:
  dedpaste keys --github username
  dedpaste send --encrypt --for github:username --pgp

The implementation follows the existing Keybase integration pattern and
supports the github:username prefix for key resolution.

Resolves #94

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
@anoncam
anoncam requested a review from Copilot October 22, 2025 16:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR implements GitHub GPG key integration, enabling users to fetch and encrypt content using public GPG keys from any GitHub user's profile. The feature includes just-in-time key fetching during encryption operations and full integration with the CLI's interactive mode.

Key Changes:

  • Added GitHub as a new key source type alongside existing self, friend, PGP, and Keybase types
  • Implemented automatic fetching of GPG keys when encrypting with --for github:username
  • Extended interactive mode to include GitHub as an import source option

Reviewed Changes

Copilot reviewed 8 out of 9 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
src/types/index.ts Added github to key type unions and introduced GitHubUser and GitHubKeyInfo interfaces
cli/githubUtils.ts New utility module for GitHub API integration, key fetching, and validation (224 lines)
cli/keyManager.ts Added GitHub key directory constant, database schema migration, and storage functions
cli/unifiedKeyManager.ts Integrated GitHub import case into unified key management system
cli/encryptionUtils.ts Implemented JIT key fetching for github: prefixed recipients
cli/index.ts Added CLI options and help text for GitHub key operations
cli/index.js Compiled JavaScript output of TypeScript changes
cli/enhancedInteractiveMode.ts Extended interactive mode UI with GitHub key support across all relevant flows

Comment thread cli/keyManager.ts
return true;
} else if (type === 'github' && db.keys.github[name]) {
// Remove the key file
const githubPath = typeof db.keys.github[name].path === 'string' ? db.keys.github[name].path : db.keys.github[name].path.public;

Copilot AI Oct 22, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] The path property access pattern is duplicated from the keybase block above. Consider extracting this into a helper function to reduce code duplication and improve maintainability. For example: getKeyPath(db.keys.github[name])

Copilot uses AI. Check for mistakes.
Comment thread cli/githubUtils.ts
}

// Sanitize username (GitHub usernames are alphanumeric + hyphens)
const sanitizedUsername = username.trim();

Copilot AI Oct 22, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The regex pattern for GitHub username validation should include a comment explaining the validation rules (alphanumeric characters and hyphens, cannot start or end with hyphen). This makes the code more maintainable and easier to understand.

Suggested change
const sanitizedUsername = username.trim();
const sanitizedUsername = username.trim();
// Validate GitHub username:
// - Only alphanumeric characters and hyphens are allowed
// - Cannot start or end with a hyphen
// - Cannot be empty

Copilot uses AI. Check for mistakes.
if (keyInfo.source === 'self') {
filename = exportPrivate ? 'dedpaste_private_key.pem' : 'dedpaste_public_key.pem';
} else if (keyInfo.type === 'pgp' || keyInfo.type === 'keybase') {
} else if (keyInfo.type === 'pgp' || keyInfo.type === 'keybase' || keyInfo.type === 'github') {

Copilot AI Oct 22, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] This condition is checking multiple key types that all use .asc extension. Consider grouping these types into a constant array (e.g., PGP_BASED_KEY_TYPES) and using includes() to make the code more maintainable when adding future PGP-based key types.

Copilot uses AI. Check for mistakes.
@anoncam
anoncam merged commit 9446a9c into main Oct 22, 2025
3 checks passed
@anoncam

anoncam commented Oct 22, 2025

Copy link
Copy Markdown
Owner Author

closes #94

github-actions Bot added a commit that referenced this pull request Oct 22, 2025
Version bump type: minor
PR: #95
Title: feat: Add GitHub GPG key integration with JIT fetching
anoncam added a commit that referenced this pull request Oct 22, 2025
This commit fixes the TypeScript errors that were causing the release
build to fail after merging PR #95 (GitHub GPG key integration).

Changes:
- Add missing 'github' and 'githubName' properties to KeysOptions interface
- Fix type mismatch in githubUtils.ts by mapping PgpKeyInfo to GitHubKeyAddInfo
  - Map keyId to fingerprint (importPgpKey returns keyId, not fingerprint)
  - Convert email from 'string | null' to 'string | undefined' using nullish coalescing
- Add 'github' to ImportOptions source type in unifiedKeyManager.ts

Fixes build errors:
- Property 'github' does not exist on type 'KeysOptions' (cli/index.ts:885-903)
- Property 'githubName' does not exist on type 'KeysOptions' (cli/index.ts:897)
- Property 'fingerprint' does not exist on type 'PgpKeyInfo' (cli/githubUtils.ts:177, 185)
- Type 'string | null' is not assignable to type 'string | undefined' (cli/githubUtils.ts:186)
- Argument of type 'PgpKeyInfo' is not assignable to parameter of type 'GitHubKeyAddInfo' (cli/githubUtils.ts:173)
- Type '"github"' is not comparable to ImportOptions source types (cli/unifiedKeyManager.ts:664)

Related to: #94

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants