Accept a version argument only if the secret has that version (closes #67)
check / check (push) Successful in 1m23s
check / check (push) Successful in 1m23s
version rm, version promote and get --version joined the version argument into a path unchecked, so "", ".", "..", "../../.." removed or read every version, the secret, the vault or directories above it. A version is now accepted only if it is one of the versions ListVersions lists for the secret, compared by name before any path is built (secret.VersionExists, used by all three). An empty --version is rejected instead of meaning the current version: GetSecretVersion no longer treats "" as current, and GetSecret looks the current version up itself. Model: opus-5-5
This commit is contained in:
@@ -1943,6 +1943,13 @@ func test23ErrorHandling(t *testing.T, tempDir, secretPath, testMnemonic string,
|
||||
require.Error(t, err, "get non-existent version should fail")
|
||||
assert.Contains(t, output, "not found", "should indicate version not found")
|
||||
|
||||
// An empty --version is not a version; it does not mean the current one
|
||||
output, err = runSecretWithEnv(map[string]string{
|
||||
secret.EnvMnemonic: testMnemonic,
|
||||
}, "get", "--version", "", "database/password")
|
||||
require.Error(t, err, "get with an empty version should fail")
|
||||
assert.Contains(t, output, "version '' not found", "should reject the empty version")
|
||||
|
||||
// Promote non-existent version
|
||||
output, err = runSecretWithEnv(map[string]string{
|
||||
secret.EnvMnemonic: testMnemonic,
|
||||
|
||||
Reference in New Issue
Block a user