Vault.GetSecret and Vault.GetSecretVersion return the decrypted value as a *memguard.LockedBuffer instead of copying it into an ordinary []byte that nothing wiped. Every caller destroys the buffer, and `secret get` writes its bytes straight to stdout, still with no trailing newline. Instance.Print, which formatted through fmt and had no other callers, is removed, and so is a debug log line in `get --version` that held the plaintext value. Model: opus-5-5
This commit was merged in pull request #87.
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
package vault_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"slices"
|
||||
@@ -197,10 +198,11 @@ func testDeepPathSecrets(t *testing.T, fs afero.Fs, tempDir string) {
|
||||
if err != nil {
|
||||
t.Fatalf("Failed to retrieve deep path secret: %v", err)
|
||||
}
|
||||
defer retrievedValue.Destroy()
|
||||
|
||||
if string(retrievedValue) != string(expectedValue) {
|
||||
if !bytes.Equal(retrievedValue.Bytes(), expectedValue) {
|
||||
t.Errorf("Retrieved value doesn't match. Expected %q, got %q",
|
||||
string(expectedValue), string(retrievedValue))
|
||||
expectedValue, retrievedValue.Bytes())
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user