Check vault names in every command that takes one (closes #68)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
A vault name may use only lowercase ASCII letters, digits, `.`, `-` and `_`, and must not be empty, `.` or `..`; the error now states that rule. `vault create`, `vault import`, `vault select`, `vault remove`, both vault names of `mv` and shell completion of a `vault:secret` argument check the name as typed before building any path from it. Before, `vault import ..` wrote a long-term key and an unlocker into the state directory itself, and `vault select ..` made that the current vault. Model: opus-5-5
This commit is contained in:
@@ -25,6 +25,15 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: A vault name may use only lowercase ASCII letters, digits,
|
||||
`.`, `-` and `_`, and must not be empty, `.` or `..`
|
||||
(https://git.eeqj.de/sneak/secret/issues/68); the error and `README.md`
|
||||
state the rule. `vault create`, `vault import`, `vault select`,
|
||||
`vault remove`, both vault names of `mv` and shell completion of a
|
||||
`vault:secret` argument check the name as typed with
|
||||
`vault.ValidateVaultName` before building any path from it. Before,
|
||||
`vault import ..` wrote a long-term key and an unlocker into the state
|
||||
directory itself, and `vault select ..` made that the current vault.
|
||||
- 2026-10-04: `script/cibuild` runs the checks again on an unchanged
|
||||
tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the
|
||||
current time as the `CHECK_EPOCH` build argument, which both the lint
|
||||
|
||||
Reference in New Issue
Block a user