Say the mnemonic still opens a vault its unlocker cannot (closes #47)
check / check (push) Failing after 2s

When the vault cannot be opened through its current unlocker, the error
now ends by saying that the vault still opens with its mnemonic, and
that 'secret unlocker add passphrase' run with SB_SECRET_MNEMONIC set
gives it a new unlocker; only when the vault metadata records the key
the mnemonic derives. 'secret encrypt' and 'secret decrypt' read the key
secret through vault.GetSecret, as 'secret get' does, so they say it
too. An unreadable 'current' file's error names 'secret version list'
and 'secret version promote'. Causes stay wrapped.

Model: opus-5-5
This commit is contained in:
2026-10-04 19:04:32 +00:00
parent 1a23fd3125
commit af7246c608
5 changed files with 328 additions and 25 deletions
+15 -2
View File
@@ -18,6 +18,21 @@ https://git.eeqj.de/sneak/secret/milestone/12
# Completed Steps
- 2026-10-04: When the vault cannot be opened through its current unlocker,
because a file the unlocker needs is missing or damaged, its keychain item
or Secure Enclave key is gone, or the passphrase is wrong, the error now
ends by saying that the vault still opens with its mnemonic, and that
`secret unlocker add passphrase`, run with `SB_SECRET_MNEMONIC` set to it,
gives the vault a new unlocker
(https://git.eeqj.de/sneak/secret/issues/47). Before, it ended with the
bare cause. The advice is given only when the vault metadata records the
key the mnemonic derives, so not for a vault created without a mnemonic.
`secret vault import` is not named: it refuses a vault that has a
long-term key. `secret encrypt` and `secret decrypt` now read the key
secret through `vault.GetSecret`, as `secret get` does, so they give the
same advice. When a secret's `current` file cannot be read, the error says
that `secret version list` lists its versions and `secret version promote`
makes one current. The causes stay wrapped.
- 2026-10-04: README's Storage Architecture, `secret version promote`,
Technical Details and Testing text matches the code
(https://git.eeqj.de/sneak/secret/issues/102). `current` and
@@ -388,8 +403,6 @@ https://git.eeqj.de/sneak/secret/milestone/12
(`secret.IdentityToLockedBuffer` overwrites only the string itself).
- Medium priority:
- Standardize error messages; stop leaking internals.
- Graceful handling of corrupted or missing key files with recovery
suggestions.
- Split oversized CLI functions.
- Cleanups: read statedir from environment or default instead of
passing it around.