Reject invalid secret names before any command builds a path (closes #33)
check / check (push) Successful in 49s
check / check (push) Successful in 49s
`secret rm ..` deleted the whole vault; `secret rm .` and `secret rm ""` deleted every secret. rm, mv, the version commands, encrypt and decrypt built paths from the name unchecked; import checked it only after reading the source file. Each now calls vault.ValidateSecretName, which wraps the existing rule, on the name as given, before building any path; MoveSecret checks both names before switching the current vault. Its error and README.md state the rule. The test-only copy of the rule in internal/secret is removed. The regression test runs each rejected command on a copy of two in-memory vaults and requires the exact error and an unchanged state directory. Model: opus-5-5
This commit is contained in:
@@ -113,7 +113,9 @@ automatically switch to another vault if removing the current one.
|
||||
Adds a secret to the current vault. Reads the secret value from stdin.
|
||||
- `--force, -f`: Overwrite existing secret
|
||||
|
||||
**Secret Name Format:** `[a-z0-9\.\-\_\/]+`
|
||||
**Secret Name Format:** only ASCII letters, digits, `.`, `-`, `_` and `/`
|
||||
are allowed, and a name must not be empty, start with `.` or `/`, end with
|
||||
`/`, contain `//`, or have `..` as a path segment.
|
||||
- Forward slashes (`/`) are converted to percent signs (`%`) for storage
|
||||
- Examples: `database/password`, `api.key`, `ssh_private_key`
|
||||
|
||||
|
||||
Reference in New Issue
Block a user