Name only the mnemonic when it cannot be read (closes #115)
check / check (push) Failing after 2s

secret init and secret vault create read the mnemonic with the new
secret.ReadMnemonic, whose every error wraps the new
secret.ErrMnemonicNotRead. It shares the terminal read with ReadPassphrase,
whose errors still wrap ErrPassphraseNotRead. Without a terminal the error
names the environment variable that gives the value instead:
SB_SECRET_MNEMONIC for the mnemonic, SB_UNLOCK_PASSPHRASE for the
passphrase. A test pins the message of init without a terminal.

Model: opus-5-5
This commit was merged in pull request #116.
This commit is contained in:
2026-10-05 01:43:00 +02:00
parent 43f66bf369
commit 2503f2db96
5 changed files with 86 additions and 23 deletions
+3 -3
View File
@@ -260,9 +260,9 @@ func TestPassphraseNotReadNamesNoMnemonic(t *testing.T) {
assert.Equal(t, "Error: failed to unlock vault: "+
"failed to get long-term key: failed to get unlocker identity: "+
"failed to read passphrase: cannot read passphrase from non-terminal "+
"stdin (piped input or script). Please set the SB_UNLOCK_PASSPHRASE "+
"environment variable or run interactively\n", string(output))
"failed to read passphrase: stdin is not a terminal (piped input or "+
"script). Please set the SB_UNLOCK_PASSPHRASE environment variable or "+
"run interactively\n", string(output))
}
// TestCryptoUnlockFailureNamesMnemonic checks that `secret encrypt` and