check / check (push) Successful in 52s
REPO_POLICIES.md sets the Go module root to sneak.berlin/go/<name>. go.mod, every import of the old path and the -X path in the Makefile LDFLAGS now use sneak.berlin/go/keyfunc; make fmt moved those imports to their new place in the sort order. The old path keeps no alias. The README gives the go install line next to the build from a clone and drops this issue from its TODO list, which now names the open 1.0 issues. Model: opus-5-5
103 lines
3.0 KiB
Go
103 lines
3.0 KiB
Go
package cli_test
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
"sneak.berlin/go/keyfunc/internal/agekey"
|
|
"sneak.berlin/go/keyfunc/internal/mnemonic"
|
|
)
|
|
|
|
func TestTheAgeCommandsPrintTheKey(t *testing.T) {
|
|
t.Setenv(mnemonic.Variable, example())
|
|
|
|
recipient := strings.TrimSpace(run(t, "age", "pub"))
|
|
require.True(t, strings.HasPrefix(recipient, "age1"))
|
|
|
|
identity := strings.TrimSpace(run(t, "age", "priv"))
|
|
require.True(t, strings.HasPrefix(identity, "AGE-SECRET-KEY-1"))
|
|
}
|
|
|
|
func TestAFileEncryptedByTheToolIsReadBackByIt(t *testing.T) {
|
|
t.Setenv(mnemonic.Variable, example())
|
|
|
|
plain := written(t, "notes.txt", "the secret\n")
|
|
sealed := filepath.Join(t.TempDir(), "notes.age")
|
|
|
|
run(t, "age", "encrypt", "-o", sealed, plain)
|
|
require.Equal(t, "the secret\n", run(t, "age", "decrypt", sealed))
|
|
}
|
|
|
|
func TestTheArmoredFormIsTextThatDecrypts(t *testing.T) {
|
|
t.Setenv(mnemonic.Variable, example())
|
|
|
|
plain := written(t, "notes.txt", "the secret\n")
|
|
|
|
armored := run(t, "age", "encrypt", "--armor", plain)
|
|
require.True(t, strings.HasPrefix(
|
|
armored, "-----BEGIN AGE ENCRYPTED FILE-----",
|
|
))
|
|
|
|
sealed := written(t, "notes.age", armored)
|
|
require.Equal(t, "the secret\n", run(t, "age", "decrypt", sealed))
|
|
}
|
|
|
|
func TestAnotherRecipientIsAddedAndTheDerivedOneStays(t *testing.T) {
|
|
t.Setenv(mnemonic.Variable, example())
|
|
|
|
theirs := strings.TrimSpace(run(t, "age", "pub", "-n", "7"))
|
|
plain := written(t, "notes.txt", "the secret\n")
|
|
sealed := filepath.Join(t.TempDir(), "notes.age")
|
|
|
|
run(t, "age", "encrypt", "--to", theirs, "-o", sealed, plain)
|
|
|
|
require.Equal(t, "the secret\n", run(t, "age", "decrypt", sealed))
|
|
require.Equal(t,
|
|
"the secret\n", run(t, "age", "decrypt", "-n", "7", sealed),
|
|
)
|
|
}
|
|
|
|
func TestAFileForAnotherKeyIsRefused(t *testing.T) {
|
|
t.Setenv(mnemonic.Variable, example())
|
|
|
|
plain := written(t, "notes.txt", "the secret\n")
|
|
sealed := filepath.Join(t.TempDir(), "notes.age")
|
|
|
|
run(t, "age", "encrypt", "-n", "7", "-o", sealed, plain)
|
|
|
|
_, err := execute(t, "age", "decrypt", sealed)
|
|
require.ErrorIs(t, err, agekey.ErrNotRecipient)
|
|
}
|
|
|
|
func TestARefusedDecryptionLeavesTheOutputFileAlone(t *testing.T) {
|
|
t.Setenv(mnemonic.Variable, example())
|
|
|
|
plain := written(t, "notes.txt", "the secret\n")
|
|
sealed := filepath.Join(t.TempDir(), "notes.age")
|
|
existing := written(t, "notes.out", "what was already there\n")
|
|
|
|
run(t, "age", "encrypt", "-n", "7", "-o", sealed, plain)
|
|
|
|
_, err := execute(t, "age", "decrypt", "-o", existing, sealed)
|
|
require.ErrorIs(t, err, agekey.ErrNotRecipient)
|
|
|
|
//nolint:gosec // the test made this path itself
|
|
kept, err := os.ReadFile(existing)
|
|
require.NoError(t, err)
|
|
require.Equal(t, "what was already there\n", string(kept))
|
|
}
|
|
|
|
// written puts the contents in a file of that name in a directory of
|
|
// this test's own and returns the path to it.
|
|
func written(t *testing.T, name, contents string) string {
|
|
t.Helper()
|
|
|
|
path := filepath.Join(t.TempDir(), name)
|
|
require.NoError(t, os.WriteFile(path, []byte(contents), 0o600))
|
|
|
|
return path
|
|
}
|