internal/cli drops its copies of vault.ErrSecretNotFound, ErrVaultNotFound, ErrVersionNotFound and ErrSecretExists and of the secret package's keychain and Secure Enclave errors, and its second error for an unknown unlocker type, an invalid mnemonic, a length below 1, an unsupported secret type and an oversized secret. vault.ErrNilValueBuffer becomes secret.ErrNilValueBuffer. Every error of secret.ReadPassphrase wraps ErrPassphraseNotRead. ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for a key the keyring lacks. storeInKeychain returns errNilDataBuffer. bip85's ErrPasswordTooShort and ErrEncodedTooShort go with their unreachable checks, as does the macOS check in macOS-only code. Tests that matched these errors' text use errors.Is. Model: opus-5-5
This commit is contained in:
@@ -45,15 +45,6 @@ func TestRejectedMoveWithinVaultLeavesStateUnchanged(t *testing.T) {
|
||||
{`mv --force work:x ""`, workX, "", true, ontoItself},
|
||||
// "work" is a vault name, so the destination is work:x.
|
||||
{"mv --force work:x work", workX, "work", true, ontoItself},
|
||||
{
|
||||
"mv work:nosuch work:y", "work:nosuch", "work:y", false,
|
||||
"secret 'nosuch' not found",
|
||||
},
|
||||
// Only an existing vault is used.
|
||||
{
|
||||
"mv --force nosuch:x nosuch:y", "nosuch:x", "nosuch:y", true,
|
||||
"vault 'nosuch' does not exist",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
@@ -70,6 +61,33 @@ func TestRejectedMoveWithinVaultLeavesStateUnchanged(t *testing.T) {
|
||||
})
|
||||
}
|
||||
|
||||
missing := []struct {
|
||||
command string
|
||||
source, dest string
|
||||
force bool
|
||||
want error
|
||||
}{
|
||||
{
|
||||
"mv work:nosuch work:y", "work:nosuch", "work:y", false,
|
||||
vault.ErrSecretNotFound,
|
||||
},
|
||||
// Only an existing vault is used.
|
||||
{
|
||||
"mv --force nosuch:x nosuch:y", "nosuch:x", "nosuch:y", true,
|
||||
vault.ErrVaultNotFound,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range missing {
|
||||
t.Run(tt.command, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
requireRejectedAndUnchanged(t, before, tt.want, func(c *cli.Instance) error {
|
||||
return c.MoveSecret(&cobra.Command{}, tt.source, tt.dest, tt.force)
|
||||
})
|
||||
})
|
||||
}
|
||||
|
||||
// Each of these spells "work" a second way. The spelling is not a valid
|
||||
// vault name, so the move is not taken for a move between two vaults,
|
||||
// which would delete the destination, here the source.
|
||||
|
||||
Reference in New Issue
Block a user