Say the mnemonic still opens a vault its unlocker cannot (closes #47)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
When the vault cannot be opened through its current unlocker, the error now ends by saying that the vault still opens with its mnemonic, and that 'secret unlocker add passphrase' run with SB_SECRET_MNEMONIC set gives it a new unlocker; only when the vault metadata records the key the mnemonic derives. 'secret encrypt' and 'secret decrypt' read the key secret through vault.GetSecret, as 'secret get' does, so they say it too. An unreadable 'current' file's error names 'secret version list' and 'secret version promote'. Causes stay wrapped. Model: opus-5-5
This commit is contained in:
@@ -18,6 +18,21 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: When the vault cannot be opened through its current unlocker,
|
||||
because a file the unlocker needs is missing or damaged, its keychain item
|
||||
or Secure Enclave key is gone, or the passphrase is wrong, the error now
|
||||
ends by saying that the vault still opens with its mnemonic, and that
|
||||
`secret unlocker add passphrase`, run with `SB_SECRET_MNEMONIC` set to it,
|
||||
gives the vault a new unlocker
|
||||
(https://git.eeqj.de/sneak/secret/issues/47). Before, it ended with the
|
||||
bare cause. The advice is given only when the vault metadata records the
|
||||
key the mnemonic derives, so not for a vault created without a mnemonic.
|
||||
`secret vault import` is not named: it refuses a vault that has a
|
||||
long-term key. `secret encrypt` and `secret decrypt` now read the key
|
||||
secret through `vault.GetSecret`, as `secret get` does, so they give the
|
||||
same advice. When a secret's `current` file cannot be read, the error says
|
||||
that `secret version list` lists its versions and `secret version promote`
|
||||
makes one current. The causes stay wrapped.
|
||||
- 2026-10-04: README's Storage Architecture, `secret version promote`,
|
||||
Technical Details and Testing text matches the code
|
||||
(https://git.eeqj.de/sneak/secret/issues/102). `current` and
|
||||
@@ -388,8 +403,6 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
||||
(`secret.IdentityToLockedBuffer` overwrites only the string itself).
|
||||
- Medium priority:
|
||||
- Standardize error messages; stop leaking internals.
|
||||
- Graceful handling of corrupted or missing key files with recovery
|
||||
suggestions.
|
||||
- Split oversized CLI functions.
|
||||
- Cleanups: read statedir from environment or default instead of
|
||||
passing it around.
|
||||
|
||||
Reference in New Issue
Block a user