Check vault names in every command that takes one (closes #68)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
A vault name may use only lowercase ASCII letters, digits, `.`, `-` and `_`, and must not be empty, `.` or `..`; the error now states that rule. `vault create`, `vault import`, `vault select`, `vault remove`, both vault names of `mv` and shell completion of a `vault:secret` argument check the name as typed before building any path from it. Before, `vault import ..` wrote a long-term key and an unlocker into the state directory itself, and `vault select ..` made that the current vault. Model: opus-5-5
This commit was merged in pull request #93.
This commit is contained in:
@@ -123,7 +123,9 @@ func getVaultNamesCompletionFunc(fs afero.Fs, stateDir string) func(
|
||||
}
|
||||
|
||||
// completeVaultQualifiedSecrets completes "vault:secret" references once a
|
||||
// colon is present in the input
|
||||
// colon is present in the input. It completes nothing when the vault part
|
||||
// is not a valid vault name, so that a name such as ".." cannot list a
|
||||
// directory outside vaults.d.
|
||||
func completeVaultQualifiedSecrets(
|
||||
fs afero.Fs, stateDir, toComplete string,
|
||||
) []string {
|
||||
@@ -134,6 +136,10 @@ func completeVaultQualifiedSecrets(
|
||||
vaultName := parts[0]
|
||||
secretPrefix := parts[1]
|
||||
|
||||
if vault.ValidateVaultName(vaultName) != nil {
|
||||
return nil
|
||||
}
|
||||
|
||||
vlt := vault.NewVault(fs, stateDir, vaultName)
|
||||
|
||||
secrets, err := vlt.ListSecrets()
|
||||
|
||||
Reference in New Issue
Block a user