CreatePGPUnlocker got the vault's long-term key from the keychain unlocker's helper, which on every platform but macOS is a stub that always fails. It now calls the vault's GetOrDeriveLongTermKey, as adding a passphrase unlocker does: from the mnemonic, checked against the vault, or else from the current unlocker. That method joins VaultInterface. The test GPG key gains an encryption subkey, and a new test adds a PGP unlocker with the long-term key from the mnemonic and from a passphrase unlocker, then reads a secret through it. Model: opus-5-5
This commit was merged in pull request #95.
This commit is contained in:
@@ -25,6 +25,15 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `secret unlocker add pgp` works on Linux
|
||||
(https://git.eeqj.de/sneak/secret/issues/88). `CreatePGPUnlocker` gets
|
||||
the vault's long-term key as adding a passphrase unlocker does, with the
|
||||
vault's `GetOrDeriveLongTermKey`, now part of `VaultInterface`: from the
|
||||
mnemonic, checked against the vault, or else from the current unlocker.
|
||||
Before, it used the keychain unlocker's helper, which on every platform
|
||||
but macOS always failed. A test adds a PGP unlocker for a throwaway GPG
|
||||
key, getting the long-term key once from the mnemonic and once from a
|
||||
passphrase unlocker, and reads a secret through the new unlocker.
|
||||
- 2026-10-04: A vault name may use only lowercase ASCII letters, digits,
|
||||
`.`, `-` and `_`, and must not be empty, `.` or `..`
|
||||
(https://git.eeqj.de/sneak/secret/issues/68); the error and `README.md`
|
||||
|
||||
Reference in New Issue
Block a user