Name only the mnemonic when it cannot be read (closes #115)
check / check (push) Failing after 2s

secret init and secret vault create read the mnemonic with the new
secret.ReadMnemonic, whose every error wraps the new
secret.ErrMnemonicNotRead. It shares the terminal read with ReadPassphrase,
whose errors still wrap ErrPassphraseNotRead. Without a terminal the error
names the environment variable that gives the value instead:
SB_SECRET_MNEMONIC for the mnemonic, SB_UNLOCK_PASSPHRASE for the
passphrase. A test pins the message of init without a terminal.

Model: opus-5-5
This commit was merged in pull request #116.
This commit is contained in:
2026-10-05 01:43:00 +02:00
parent 43f66bf369
commit 2503f2db96
5 changed files with 86 additions and 23 deletions
+2 -2
View File
@@ -55,11 +55,11 @@ func (cli *Instance) promptMnemonic() (*memguard.LockedBuffer, func(), error) {
secret.Debug("Prompting user for mnemonic phrase")
// Read mnemonic securely without echo
mnemonicBuffer, err := secret.ReadPassphrase("Enter your BIP39 mnemonic phrase: ")
mnemonicBuffer, err := secret.ReadMnemonic("Enter your BIP39 mnemonic phrase: ")
if err != nil {
secret.Debug("Failed to read mnemonic from stdin", "error", err)
return nil, nil, fmt.Errorf("failed to read mnemonic: %w", err)
return nil, nil, err
}
fmt.Fprintln(os.Stderr) // Add newline after hidden input