dnsmint: portable record lookup on removal

grep -F is not on Solaris /usr/bin/grep, and "\n" in a sed replacement is a
GNU extension that BSD sed writes as a literal n. The second is the one that
loses data: without the split the whole reply stays on one line, so the match
succeeds whatever the value is and the id taken is the first record under the
hostname rather than the one holding the challenge. Removal then deletes
somebody else's TXT record.

Literal newline in the replacement, as dns_glesys.sh does it, and a case
pattern per line with the case outside a command substitution.

Docs and Issues now point at dnsapi2 and at the tracking issue upstream.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
karthik
2026-09-13 02:10:58 -04:00
co-authored by Claude Opus 5
Unverified
parent 6bed53d080
commit 61ef816c48
+25 -3
View File
@@ -5,10 +5,10 @@ dns_dnsmint_info='DNSMint.com
authoritative nameservers, so records are published through its API rather authoritative nameservers, so records are published through its API rather
than a zone you run. than a zone you run.
Site: dnsmint.com Site: dnsmint.com
Docs: github.com/acmesh-official/acme.sh/wiki/dnsapi#dns_dnsmint Docs: github.com/acmesh-official/acme.sh/wiki/dnsapi2#dns_dnsmint
Options: Options:
DNSMINT_API_KEY API key. dns01:write is enough to issue certificates. DNSMINT_API_KEY API key. dns01:write is enough to issue certificates.
Issues: github.com/dnsmint/acme.sh Issues: github.com/acmesh-official/acme.sh/issues/7251
Author: DNSMint Author: DNSMint
' '
@@ -206,7 +206,29 @@ _dnsmint_record_rm() {
# Records come back as {"id":...,"name":"<fqdn>","type":"TXT","ttl":..., # Records come back as {"id":...,"name":"<fqdn>","type":"TXT","ttl":...,
# "data":{...,"text":["<value>"]}}. Match on the value so a name holding # "data":{...,"text":["<value>"]}}. Match on the value so a name holding
# several TXT records loses only the one that was added. # several TXT records loses only the one that was added.
_rid="$(echo "$response" | sed 's/},{/}\n{/g' | grep -F "\"$_value\"" | _egrep_o '"id":"[^"]*"' | cut -d'"' -f4 | _head_n 1)" #
# The replacement carries a literal newline: "\n" there is a GNU extension
# and BSD sed inserts the letter n, which would leave the whole reply on one
# line and match the first record under the hostname whatever its value.
_records="$(
printf "%s" "$response" | sed 's/},{/}\
{/g'
)"
_rid=""
while IFS= read -r _line; do
case "$_line" in
*"\"$_value\""*)
_rid="$(printf "%s" "$_line" | _egrep_o '"id":"[^"]*"' | cut -d'"' -f4)"
if [ -n "$_rid" ]; then
break
fi
;;
esac
done <<EOF
$_records
EOF
if [ -z "$_rid" ]; then if [ -z "$_rid" ]; then
_info "Record already gone, nothing to remove" _info "Record already gone, nothing to remove"
return 0 return 0