Accept a version argument only if the secret has that version (closes #67)
check / check (push) Successful in 1m23s

version rm, version promote and get --version joined the version
argument into a path unchecked, so "", ".", "..", "../../.." removed or
read every version, the secret, the vault or directories above it.

A version is now accepted only if it is one of the versions
ListVersions lists for the secret, compared by name before any path is
built (secret.VersionExists, used by all three). An empty --version is
rejected instead of meaning the current version: GetSecretVersion no
longer treats "" as current, and GetSecret looks the current version
up itself.

Model: opus-5-5
This commit is contained in:
2026-10-03 23:54:09 +00:00
parent a5faec0466
commit 76321c5291
11 changed files with 192 additions and 73 deletions
+7
View File
@@ -1943,6 +1943,13 @@ func test23ErrorHandling(t *testing.T, tempDir, secretPath, testMnemonic string,
require.Error(t, err, "get non-existent version should fail")
assert.Contains(t, output, "not found", "should indicate version not found")
// An empty --version is not a version; it does not mean the current one
output, err = runSecretWithEnv(map[string]string{
secret.EnvMnemonic: testMnemonic,
}, "get", "--version", "", "database/password")
require.Error(t, err, "get with an empty version should fail")
assert.Contains(t, output, "version '' not found", "should reject the empty version")
// Promote non-existent version
output, err = runSecretWithEnv(map[string]string{
secret.EnvMnemonic: testMnemonic,