diff --git a/Backup.ps1 b/Backup.ps1 index 1a5cc51..629d817 100644 --- a/Backup.ps1 +++ b/Backup.ps1 @@ -162,6 +162,11 @@ $manifest = Read-BakNRetManifest -Path $manifestPath $manifest.compressor = [pscustomobject]@{ name = $tool.Name; command = $tool.Command; extension = $tool.Extension; version = $toolVersion } $passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile } +if ($passwordFile) { + # 相对路径按**仓库根**解析,而不是按当前工作目录:计划任务的工作目录是 C:\Windows\System32, + # 在那里 Test-Path 找不到 baknret.key,加密条目就会以"拿不到口令"失败,而配置看上去没问题。 + $passwordFile = Resolve-BakNRetRootedPath -Path $passwordFile -Default $passwordFile -Root $PSScriptRoot +} $password = Get-BakNRetPassword -PasswordFile $passwordFile $encryptAll = [bool]$script:Config.Encryption.Enabled $showToolOutput = (-not $QuietTool) -and ($script:Config.ToolOutput -ne 'quiet') diff --git a/BackupConfig.psd1 b/BackupConfig.psd1 index fd6921b..6930bd7 100644 --- a/BackupConfig.psd1 +++ b/BackupConfig.psd1 @@ -49,15 +49,19 @@ # 口令本身按以下优先级获取(见 README「加密」): # 1. -Password 命令行参数 # 2. $env:BAKNRET_PASSWORD - # 3. PasswordFile 指向的文件首行 —— 必须指向仓库**之外**的文件; - # 出厂默认值留空:默认值指向仓库里的某个文件,等于鼓励把口令放进版本库 + # 3. PasswordFile 指向的文件首行 (首行即口令) + # + # 出厂默认值就是仓库根的 baknret.key,靠 .gitignore 的 *.key 兜住「不被提交」。 + # 这是**取舍**而非疏忽:留在仓库根最省事(口令与配置在一起,搬家不容易丢),代价是 + # 「不提交」这件事依赖一个规则文件 —— 谁写了 git add -f、或把整个目录复制到别处再 + # 初始化仓库,口令就会跟着走。要更稳就把文件放到仓库外,用下面的 B 或 A。 # 4. 交互式询问(仅交互式会话;计划任务里不会停下来等输入) # 全都拿不到时该条目明确失败,绝不退化成明文归档。 # # 注意 7z 只接受命令行口令,口令在本机进程列表里短暂可见,这是 7z 本身的限制。 Encryption = @{ Enabled = $false - PasswordFile = '' + PasswordFile = 'baknret.key' EncryptHeaders = $true } diff --git a/Restore.ps1 b/Restore.ps1 index 5d67ec3..1e552cb 100644 --- a/Restore.ps1 +++ b/Restore.ps1 @@ -115,6 +115,11 @@ if (-not $WhatIfPreference -and -not $VerifyOnly) { } $passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile } +if ($passwordFile) { + # 相对路径按**仓库根**解析,而不是按当前工作目录:计划任务的工作目录是 C:\Windows\System32, + # 在那里 Test-Path 找不到 baknret.key,加密条目就会以"拿不到口令"失败,而配置看上去没问题。 + $passwordFile = Resolve-BakNRetRootedPath -Path $passwordFile -Default $passwordFile -Root $PSScriptRoot +} $password = Get-BakNRetPassword -PasswordFile $passwordFile # ============================================================================