Vault.GetSecret and Vault.GetSecretVersion return the decrypted value as a *memguard.LockedBuffer instead of copying it into an ordinary []byte that nothing wiped. Every caller destroys the buffer, and `secret get` writes its bytes straight to stdout, still with no trailing newline. Instance.Print, which formatted through fmt and had no other callers, is removed, and so is a debug log line in `get --version` that held the plaintext value. Model: opus-5-5
This commit was merged in pull request #87.
This commit is contained in:
@@ -342,7 +342,10 @@ func TestLongestNames(t *testing.T) {
|
||||
|
||||
got, err := vlt.GetSecret(name)
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, "long", string(got))
|
||||
|
||||
defer got.Destroy()
|
||||
|
||||
assert.Equal(t, []byte("long"), got.Bytes())
|
||||
|
||||
vaultDir, err := vlt.GetDirectory()
|
||||
require.NoError(t, err)
|
||||
@@ -380,7 +383,10 @@ func TestForcedCopyKeepsDestinationUntilReplaced(t *testing.T) {
|
||||
|
||||
value, err := dest.GetSecret("shared")
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, "old", string(value))
|
||||
|
||||
defer value.Destroy()
|
||||
|
||||
assert.Equal(t, []byte("old"), value.Bytes())
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user