Ask before removing a secret, version, vault or unlocker (closes #39)
check / check (push) Failing after 2s

secret rm, secret version rm, secret vault remove and secret unlocker
remove ask [y/N] on a terminal, naming what they remove, and go ahead
only on y or yes. Without --force, a command whose stdin is not a
terminal fails at once. --force, now also on rm and version rm,
removes without asking; it replaces the old refusals to remove a vault
with secrets or the last unlocker without --force. The checks run and
the question is asked before the state directory lock is taken; under
the lock the checks run again, and nothing is removed if they would
ask a different question.

Model: opus-5-5
This commit was merged in pull request #100.
This commit is contained in:
2026-10-04 17:41:48 +02:00
parent 7e4e0f7806
commit 1cc8653981
17 changed files with 1146 additions and 256 deletions
+5
View File
@@ -3,6 +3,7 @@ package cli
import (
"fmt"
"io"
"os"
"git.eeqj.de/sneak/secret/internal/secret"
@@ -21,6 +22,10 @@ type Instance struct {
// none.
Mnemonic *memguard.LockedBuffer
UnlockPassphrase *memguard.LockedBuffer
// terminal, when set, stands in for the terminal that confirm reads
// the user's answer from; only tests set it. When it is nil, confirm
// reads stdin, and only when stdin is a terminal.
terminal io.Reader
}
// NewCLIInstance creates a new CLI instance with the real filesystem