Stop secret mv deleting a secret moved onto itself (closes #73)
check / check (push) Successful in 1m32s

`secret mv --force x x` deleted the secret: a move within one vault
removes an existing destination before renaming the source onto it. The
same happened for `work:x work:`, `work:x work` and `work:x ""`, where an
empty destination defaults to the source name.

moveSecretWithinVault now rejects a move whose two names are the same
before touching anything. A move within a named vault works in that
vault directly instead of selecting it, so the current vault never
changes; the vault must be one of the existing vaults.

The test runs each rejected move on a copy of two in-memory vaults and
requires the exact error and an unchanged state directory.

Model: opus-5-5
This commit is contained in:
2026-10-03 23:47:57 +00:00
parent a5faec0466
commit 974b1b6dc5
3 changed files with 131 additions and 21 deletions
+6
View File
@@ -25,6 +25,12 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-03: `secret mv` rejects a move whose destination is the
source (`mv --force x x`, `mv --force work:x work:`, or an empty
destination, which defaults to the source name) before changing
anything; before, `--force` removed the destination first and so
deleted the secret. A move within a named vault no longer makes that
vault the current one, whether it succeeds or fails.
- 2026-10-03: Every command that builds a path from a secret name
checks the name first with `vault.ValidateSecretName` and touches
nothing when it is invalid: `rm`, `mv` (both names, within a vault