Check vault names in every command that takes one (closes #68)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
A vault name may use only lowercase ASCII letters, digits, `.`, `-` and `_`, and must not be empty, `.` or `..`; the error now states that rule. `vault create`, `vault import`, `vault select`, `vault remove`, both vault names of `mv` and shell completion of a `vault:secret` argument check the name as typed before building any path from it. Before, `vault import ..` wrote a long-term key and an unlocker into the state directory itself, and `vault select ..` made that the current vault. Model: opus-5-5
This commit was merged in pull request #93.
This commit is contained in:
+11
-5
@@ -811,9 +811,9 @@ func (cli *Instance) moveSecret(
|
||||
cmd, vlt, srcSecretName, destSecretName, force)
|
||||
}
|
||||
|
||||
// Both vaults must be existing vaults by exact name, so that two
|
||||
// spellings of one vault, such as "work" and "work/", are never taken for
|
||||
// two vaults. A named vault does not become the current vault.
|
||||
// Both vault names must be valid and name existing vaults exactly, so
|
||||
// that two spellings of one vault, such as "work" and "work/", are never
|
||||
// taken for two vaults. A named vault does not become the current vault.
|
||||
srcVault, err := cli.existingVault(srcVaultName)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -833,9 +833,15 @@ func (cli *Instance) moveSecret(
|
||||
cmd, srcVault, srcSecretName, destVault, destSecretName, force)
|
||||
}
|
||||
|
||||
// existingVault returns the vault with the given name, or an error if there
|
||||
// is none. Unlike vault.SelectVault, it leaves the current vault as it is.
|
||||
// existingVault returns the vault with the given name, or an error if the
|
||||
// name is not a valid vault name or there is no such vault. Unlike
|
||||
// vault.SelectVault, it leaves the current vault as it is.
|
||||
func (cli *Instance) existingVault(name string) (*vault.Vault, error) {
|
||||
err := vault.ValidateVaultName(name)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
vaults, err := vault.ListVaults(cli.fs, cli.stateDir)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to list vaults: %w", err)
|
||||
|
||||
Reference in New Issue
Block a user