Ask before removing a secret, version, vault or unlocker (closes #39)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
secret rm, secret version rm, secret vault remove and secret unlocker remove ask [y/N] on a terminal, naming what they remove, and go ahead only on y or yes. Without --force, a command whose stdin is not a terminal fails at once. --force, now also on rm and version rm, removes without asking; it replaces the old refusals to remove a vault with secrets or the last unlocker without --force. The checks run and the question is asked before the state directory lock is taken; under the lock the checks run again, and nothing is removed if they would ask a different question. Model: opus-5-5
This commit is contained in:
+81
-43
@@ -47,7 +47,6 @@ var (
|
||||
errGPGKeyAlreadyUnlocker = errors.New(
|
||||
"is already added as an unlocker")
|
||||
errUnsupportedUnlockerType = errors.New("unsupported unlocker type")
|
||||
errLastUnlocker = errors.New("refusing to remove last unlocker")
|
||||
)
|
||||
|
||||
// UnlockerInfo represents unlocker information for display
|
||||
@@ -267,10 +266,11 @@ func newUnlockerRemoveCmd() *cobra.Command {
|
||||
Use: "remove <unlocker-id>",
|
||||
Aliases: []string{"rm"},
|
||||
Short: "Remove an unlocker",
|
||||
Long: `Remove an unlocker from the current vault. Cannot remove ` +
|
||||
`the last unlocker if the vault has secrets unless --force is ` +
|
||||
`used. Warning: Without unlockers and without your mnemonic, ` +
|
||||
`vault data will be permanently inaccessible.`,
|
||||
Long: `Remove an unlocker from the current vault. Asks for ` +
|
||||
`confirmation first, saying whether it is the vault's last ` +
|
||||
`unlocker; when stdin is not a terminal, fails unless --force ` +
|
||||
`is given. Warning: Without unlockers and without your ` +
|
||||
`mnemonic, vault data will be permanently inaccessible.`,
|
||||
Args: cobra.ExactArgs(1),
|
||||
ValidArgsFunction: getUnlockerIDsCompletionFunc(cli.fs, cli.stateDir),
|
||||
RunE: func(cmd *cobra.Command, args []string) error {
|
||||
@@ -286,7 +286,7 @@ func newUnlockerRemoveCmd() *cobra.Command {
|
||||
}
|
||||
|
||||
cmd.Flags().BoolP("force", "f", false,
|
||||
"Force removal of last unlocker even if vault has secrets")
|
||||
"Remove without asking for confirmation, even the last unlocker")
|
||||
|
||||
return cmd
|
||||
}
|
||||
@@ -726,55 +726,91 @@ func (cli *Instance) addPGPUnlocker(cmd *cobra.Command) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// UnlockersRemove removes an unlocker, holding the state directory lock
|
||||
// while removeUnlocker runs
|
||||
// UnlockersRemove removes an unlocker from the current vault, after asking
|
||||
// the user to confirm unless force is set.
|
||||
func (cli *Instance) UnlockersRemove(
|
||||
unlockerID string, force bool, cmd *cobra.Command,
|
||||
) error {
|
||||
release, err := vault.LockStateDir(cli.fs, cli.stateDir)
|
||||
var found unlockerToRemove
|
||||
|
||||
release, err := cli.askThenLock(cmd, force, func() (string, error) {
|
||||
var err error
|
||||
|
||||
found, err = cli.findUnlockerToRemove(unlockerID)
|
||||
|
||||
return found.question, err
|
||||
})
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer release()
|
||||
|
||||
return cli.removeUnlocker(unlockerID, force, cmd)
|
||||
return cli.removeUnlocker(unlockerID, found, cmd)
|
||||
}
|
||||
|
||||
// removeUnlocker removes an unlocker with safety checks
|
||||
func (cli *Instance) removeUnlocker(
|
||||
unlockerID string, force bool, cmd *cobra.Command,
|
||||
) error {
|
||||
// Get current vault
|
||||
// unlockerToRemove is what removing an unlocker removes, as
|
||||
// findUnlockerToRemove found it.
|
||||
type unlockerToRemove struct {
|
||||
vlt *vault.Vault
|
||||
// last is set when the unlocker counts as the vault's last one, and
|
||||
// secrets is then the number of secrets in the vault.
|
||||
last bool
|
||||
secrets int
|
||||
// question names what is removed, for the user to confirm.
|
||||
question string
|
||||
}
|
||||
|
||||
// findUnlockerToRemove checks that the current vault has the unlocker and
|
||||
// finds whether it is the vault's last one.
|
||||
func (cli *Instance) findUnlockerToRemove(
|
||||
unlockerID string,
|
||||
) (unlockerToRemove, error) {
|
||||
vlt, err := vault.GetCurrentVault(cli.fs, cli.stateDir)
|
||||
if err != nil {
|
||||
return err
|
||||
return unlockerToRemove{}, err
|
||||
}
|
||||
|
||||
exists, err := vlt.HasUnlocker(unlockerID)
|
||||
if err != nil {
|
||||
return unlockerToRemove{}, err
|
||||
}
|
||||
|
||||
if !exists {
|
||||
return unlockerToRemove{}, fmt.Errorf("unlocker with ID %s %w",
|
||||
unlockerID, vault.ErrUnlockerNotFound)
|
||||
}
|
||||
|
||||
// Get list of unlockers. It leaves out a directory whose metadata file
|
||||
// is missing or cannot be checked for, read or parsed.
|
||||
unlockers, err := vlt.ListUnlockers()
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to list unlockers: %w", err)
|
||||
return unlockerToRemove{},
|
||||
fmt.Errorf("failed to list unlockers: %w", err)
|
||||
}
|
||||
|
||||
vaultDir, err := vlt.GetDirectory()
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to get vault directory: %w", err)
|
||||
return unlockerToRemove{},
|
||||
fmt.Errorf("failed to get vault directory: %w", err)
|
||||
}
|
||||
|
||||
unlockersDir := filepath.Join(vaultDir, "unlockers.d")
|
||||
|
||||
// Check if we're removing the last unlocker
|
||||
removingLast := false
|
||||
found := unlockerToRemove{
|
||||
vlt: vlt,
|
||||
question: fmt.Sprintf("Permanently remove unlocker '%s' from vault "+
|
||||
"'%s'? It is not the vault's last unlocker.",
|
||||
unlockerID, vlt.GetName()),
|
||||
}
|
||||
|
||||
if len(unlockers) == 1 {
|
||||
lastID, err := findUnlockerIDByMetadata(
|
||||
cli.fs, unlockersDir, unlockers[0], true)
|
||||
if err != nil {
|
||||
return err
|
||||
return unlockerToRemove{}, err
|
||||
}
|
||||
|
||||
removingLast = lastID == unlockerID
|
||||
found.last = lastID == unlockerID
|
||||
}
|
||||
|
||||
// unlockerID may instead name a directory left out of the list. If its
|
||||
@@ -783,34 +819,36 @@ func (cli *Instance) removeUnlocker(
|
||||
// for or read, the unlocker may be the only working one, so removing it
|
||||
// counts as removing the last unlocker.
|
||||
if metadataUnreadable(cli.fs, filepath.Join(unlockersDir, unlockerID)) {
|
||||
removingLast = true
|
||||
found.last = true
|
||||
}
|
||||
|
||||
if removingLast {
|
||||
// Check if vault has secrets
|
||||
numSecrets, err := vlt.NumSecrets()
|
||||
if found.last {
|
||||
found.secrets, err = vlt.NumSecrets()
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to count secrets: %w", err)
|
||||
return unlockerToRemove{},
|
||||
fmt.Errorf("failed to count secrets: %w", err)
|
||||
}
|
||||
|
||||
if numSecrets > 0 && !force {
|
||||
cmd.Println("ERROR: Cannot remove the last unlocker when the " +
|
||||
"vault contains secrets.")
|
||||
cmd.Println("WARNING: Without unlockers, you MUST have your " +
|
||||
"mnemonic phrase to decrypt the vault.")
|
||||
cmd.Println("If you want to proceed anyway, use --force")
|
||||
|
||||
return errLastUnlocker
|
||||
}
|
||||
|
||||
if numSecrets > 0 && force {
|
||||
cmd.Println("WARNING: Removing the last unlocker. You MUST " +
|
||||
"have your mnemonic phrase to access this vault again!")
|
||||
}
|
||||
found.question = fmt.Sprintf("Permanently remove unlocker '%s', "+
|
||||
"the last unlocker of vault '%s', which holds %d secret(s)? "+
|
||||
"Without an unlocker the vault opens only with its mnemonic.",
|
||||
unlockerID, vlt.GetName(), found.secrets)
|
||||
}
|
||||
|
||||
// Remove the unlocker
|
||||
err = vlt.RemoveUnlocker(unlockerID)
|
||||
return found, nil
|
||||
}
|
||||
|
||||
// removeUnlocker removes the unlocker that findUnlockerToRemove found. The
|
||||
// caller holds the state directory lock.
|
||||
func (cli *Instance) removeUnlocker(
|
||||
unlockerID string, found unlockerToRemove, cmd *cobra.Command,
|
||||
) error {
|
||||
if found.last && found.secrets > 0 {
|
||||
cmd.Println("WARNING: Removing the last unlocker. You MUST " +
|
||||
"have your mnemonic phrase to access this vault again!")
|
||||
}
|
||||
|
||||
err := found.vlt.RemoveUnlocker(unlockerID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user