Ask before removing a secret, version, vault or unlocker (closes #39)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
secret rm, secret version rm, secret vault remove and secret unlocker remove ask [y/N] on a terminal, naming what they remove, and go ahead only on y or yes. Without --force, a command whose stdin is not a terminal fails at once. --force, now also on rm and version rm, removes without asking; it replaces the old refusals to remove a vault with secrets or the last unlocker without --force. The checks run and the question is asked before the state directory lock is taken; under the lock the checks run again, and nothing is removed if they would ask a different question. Model: opus-5-5
This commit is contained in:
@@ -272,6 +272,24 @@ func (v *Vault) readUnlockerMetadataOrWarn(
|
||||
return metadata, true
|
||||
}
|
||||
|
||||
// HasUnlocker reports whether RemoveUnlocker finds something to remove by
|
||||
// the ID unlockerID: an unlocker with that ID, or an unlocker directory of
|
||||
// that name that ListUnlockers skips.
|
||||
func (v *Vault) HasUnlocker(unlockerID string) (bool, error) {
|
||||
vaultDir, err := v.GetDirectory()
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
_, unlockerDir, err := v.findUnlockerByID(
|
||||
filepath.Join(vaultDir, "unlockers.d"), unlockerID)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
return unlockerDir != "", nil
|
||||
}
|
||||
|
||||
// RemoveUnlocker removes an unlocker from this vault. An unlocker
|
||||
// directory that ListUnlockers skips is removed by its directory name; its
|
||||
// type is unknown, so only the directory is removed.
|
||||
|
||||
Reference in New Issue
Block a user