From 2c75ecaafd30d6cf0cc34ca47ccc9d7109ffcefd Mon Sep 17 00:00:00 2001 From: Hyun Kim Date: Tue, 6 Jan 2026 17:55:12 +0700 Subject: Initial commit: Touch ID Keychain CLI tool MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Touch ID authentication for all commands - Secure password input (no echo) - macOS Keychain storage with encryption πŸ€– Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 --- README.md | 113 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 113 insertions(+) create mode 100644 README.md (limited to 'README.md') diff --git a/README.md b/README.md new file mode 100644 index 0000000..96ffdab --- /dev/null +++ b/README.md @@ -0,0 +1,113 @@ +# keychain-fingerprint + +Touch ID 인증으둜 macOS Keychain λΉ„λ°€λ²ˆν˜Έμ— μ•ˆμ „ν•˜κ³  νŽΈλ¦¬ν•˜κ²Œ μ ‘κ·Όν•˜λŠ” CLI 도ꡬ + +## Why? + +macOS Keychain에 μ €μž₯된 λΉ„λ°€λ²ˆν˜Έμ— μ ‘κ·Όν•  λ•Œ 두 κ°€μ§€ λΆˆνŽΈν•¨μ΄ μžˆμŠ΅λ‹ˆλ‹€: + +### 문제 1: λ³΄μ•ˆ vs νŽΈμ˜μ„± λ”œλ ˆλ§ˆ + +`security find-generic-password` λͺ…λ Ήμ–΄λ‘œ λΉ„λ°€λ²ˆν˜Έμ— μ ‘κ·Όν•˜λ©΄: + +``` +"security"κ°€ ν‚€μ²΄μΈμ˜ "myapp"에 μ €μž₯된 κΈ°λ°€ 정보λ₯Ό μ‚¬μš©ν•˜λ €κ³  ν•©λ‹ˆλ‹€. +[κ±°λΆ€] [ν—ˆμš©] [항상 ν—ˆμš©] +``` + +- **"ν—ˆμš©"**: 맀번 Mac λΉ„λ°€λ²ˆν˜Έλ₯Ό μž…λ ₯ν•΄μ•Ό 함 β†’ λ²ˆκ±°λ‘œμ›€ +- **"항상 ν—ˆμš©"**: 이후 μ–΄λ–€ μ•±μ—μ„œλ“  λΉ„λ°€λ²ˆν˜Έ 없이 μ ‘κ·Ό κ°€λŠ₯ β†’ λ³΄μ•ˆ μ·¨μ•½ + +### 문제 2: λΉ„λ°€λ²ˆν˜Έ μž…λ ₯의 λΆˆνŽΈν•¨ + +Mac λΉ„λ°€λ²ˆν˜ΈλŠ” 보톡 κΈΈκ³  λ³΅μž‘ν•΄μ„œ 맀번 μž…λ ₯ν•˜κΈ° λ²ˆκ±°λ‘­μŠ΅λ‹ˆλ‹€. + +### ν•΄κ²°μ±…: Touch ID + +이 λ„κ΅¬λŠ” **Touch ID**둜 μΈμ¦ν•˜μ—¬: +- **λΉ λ₯΄κ³  νŽΈλ¦¬ν•¨**: 손가락 ν•œ 번으둜 인증 (λΉ„λ°€λ²ˆν˜Έ μž…λ ₯ λΆˆν•„μš”) +- **λ³΄μ•ˆ μœ μ§€**: λ‹€λ₯Έ μ•±μ—μ„œ μ ‘κ·Ό μ‹œ μ—¬μ „νžˆ Mac λΉ„λ°€λ²ˆν˜Έ ν•„μš” + +## Installation + +```bash +# Clone +git clone https://github.com/dss99911/keychain-fingerprint.git +cd keychain-fingerprint + +# Compile +swiftc -o keychain-fingerprint main.swift -framework LocalAuthentication -framework Security + +# Install (optional) +sudo cp keychain-fingerprint /usr/local/bin/ +``` + +## Usage + +```bash +# Save password (Touch ID β†’ secure input) +keychain-fingerprint set myapp user@example.com + +# Get password (Touch ID β†’ stdout) +keychain-fingerprint get myapp user@example.com + +# List saved items (Touch ID) +keychain-fingerprint list + +# Delete password (Touch ID) +keychain-fingerprint delete myapp user@example.com +``` + +### Shell Variable (Recommended) + +```bash +# Capture password in variable (not displayed on screen) +PASSWORD=$(keychain-fingerprint get myapp user@example.com) + +# Use the password +echo "Using password..." + +# Clear the variable when done +unset PASSWORD +``` + +## Security + +| Access Method | Authentication Required | +|---------------|------------------------| +| This app | Touch ID | +| Other apps / `security` command | Mac password | + +### How it works + +``` +β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” +β”‚ keychain-fingerprint β”‚ +β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ +β”‚ 1. Touch ID authentication β”‚ +β”‚ 2. Access Keychain (auto-authorized) β”‚ +β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ + +β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” +β”‚ Other apps / terminal β”‚ +β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ +β”‚ Keychain access β†’ Mac password prompt β”‚ +β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ +``` + +### Features + +- All commands require Touch ID +- Passwords stored encrypted in macOS Keychain +- Password input is hidden (no echo) +- Passwords only output to stdout (for variable capture) +- Device-only access (`kSecAttrAccessibleWhenUnlockedThisDeviceOnly`) + +## Requirements + +- macOS with Touch ID +- Xcode Command Line Tools (`xcode-select --install`) + +## License + +MIT -- cgit v1.3