Make an unlocker's ID the name of its directory (closes #98)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
Keychain and Secure Enclave unlocker IDs were the creation time to the minute plus the host name, and passphrase unlocker IDs the time to the minute, so two created within one minute shared an ID, and `unlocker select`, `unlocker remove` and the selection after `unlocker add` acted on the older one. Every unlocker's ID is now its directory name, unique in its vault. PGP unlocker IDs were `pgp-<fingerprint>`; the check that refuses a second PGP unlocker for one key now compares the fingerprint in the other unlockers' metadata. Model: opus-5-5
This commit is contained in:
@@ -211,7 +211,9 @@ Generates and stores a random secret.
|
||||
|
||||
#### `secret unlocker list [--json]` / `secret unlocker ls`
|
||||
|
||||
Lists all unlockers in the current vault with their metadata.
|
||||
Lists all unlockers in the current vault with their metadata. An unlocker's ID,
|
||||
which `secret unlocker select` and `secret unlocker remove` take, is the name of
|
||||
its directory in `unlockers.d`.
|
||||
|
||||
#### `secret unlocker add <type> [options]`
|
||||
|
||||
|
||||
Reference in New Issue
Block a user