Skip to content

Save private key and setup config files with owner-only permissions - #475

Merged
aharoitx merged 2 commits into
bitpay:10.3.xfrom
aharoitx:fix/im192-key-file-permissions
Oct 8, 2026
Merged

aharoitx merged 2 commits into
bitpay:10.3.xfrom
aharoitx:fix/im192-key-file-permissions

Conversation

@aharoitx

@aharoitx aharoitx commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

The SDK saved the merchant's private key with the default mode (usually 0644), so any local user could read it. This happens in KeyUtils.saveEcKey and KeyUtils.saveEcKeyAsHex, which the setup tool uses and merchants can also call directly.

The setup tool also saved BitPay.config.json with the default mode. That file holds the API tokens, and the private key too when the "plain text" option is used.

These files are now saved with mode 0600 (only the owner can read and write).

Changes

  • KeyUtils: new private helper writeOwnerOnlyFile, used by saveEcKey and saveEcKeyAsHex. It creates the file with 0600, or sets 0600 on an existing file before writing, and sets it again after writing.
  • BitPaySetup: saves BitPay.config.json the same way.
  • New tests in KeyUtilsTest.

On file systems without POSIX permissions (Windows), the files keep the default permissions. The new tests are skipped there. The code only uses Java 7 APIs, so Java 8 is still supported.

Testing

  • The new tests fail on 10.3.x (files are rw-r--r--) and pass with this change.
  • mvn test on Java 8 (Corretto 8.0.472): 611 passed, 0 skipped.
  • mvn checkstyle:check: OK

Jira: IM-192

KeyUtils.saveEcKey and KeyUtils.saveEcKeyAsHex wrote the private key
with the default mode (usually 0644), so any local user could read it.

Both now write the file with mode 0600 on file systems that support
POSIX permissions. If the file already exists, its permissions are
tightened before the key is written. On Windows the file keeps the
default permissions.
The setup tool wrote BitPay.config.json with the default mode (usually
0644). The file holds the API tokens, and with the "plain text" option
it also holds the private key, so any local user could read them.

It is now written with mode 0600 on file systems that support POSIX
permissions, the same way as the private key file.
@aharoitx
aharoitx merged commit 921f085 into bitpay:10.3.x Oct 8, 2026
6 checks passed
@aharoitx aharoitx changed the title Fix/im192 key file permissions Save private key and setup config files with owner-only permissions Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants