1 Commits
Author SHA1 Message Date
sneak 720fa80235 Reject invalid secret names before any command builds a path (closes #33)
check / check (push) Successful in 49s
`secret rm ..` resolved to the vault directory and deleted the whole
vault; `secret rm .` and `secret rm ""` deleted every secret. rm, mv,
the version commands, encrypt and decrypt built paths from the name
without checking it; import checked it only after reading the source
file.

vault.ValidateSecretName wraps the existing name rule; its error and
README.md state the rule. Each of those commands calls it on the name
as given, before building any path; MoveSecret checks both names once,
for every form of the move, before switching the current vault.
AddSecret, GetSecretVersion and GetSecretObject use it too.

The regression test copies two in-memory vaults for each rejected
command and requires the exact error and an unchanged state directory.

Model: opus-5-5
2026-10-03 14:54:16 +00:00
3 changed files with 20 additions and 29 deletions
+3 -1
View File
@@ -113,7 +113,9 @@ automatically switch to another vault if removing the current one.
Adds a secret to the current vault. Reads the secret value from stdin.
- `--force, -f`: Overwrite existing secret
**Secret Name Format:** `[a-z0-9\.\-\_\/]+`
**Secret Name Format:** only letters, digits, `.`, `-`, `_` and `/` are
allowed, and a name must not be empty, start with `.` or `/`, end with `/`,
contain `//`, or have `..` as a path segment.
- Forward slashes (`/`) are converted to percent signs (`%`) for storage
- Examples: `database/password`, `api.key`, `ssh_private_key`
+1 -1
View File
@@ -30,7 +30,7 @@ Bring the repo into policy compliance in one commit:
nothing when it is invalid: `rm`, `mv` (both names, within a vault
and between vaults, before switching the current vault), `import`,
`version list`/`promote`/`rm`, `encrypt` and `decrypt`. The error
states the naming rule. Before, `secret rm ..` deleted the whole
and `README.md` state the naming rule. Before, `secret rm ..` deleted the whole
vault and `secret rm .` every secret in it.
- 2026-10-02: A plain `docker build .` builds again: the size tests
skip a case that needs more locked memory than the process can
+16 -27
View File
@@ -712,13 +712,8 @@ func (cli *Instance) MoveSecret(
srcVaultName, srcSecretName, srcQualified := ParseVaultSecretRef(source)
destVaultName, destSecretName, destQualified := ParseVaultSecretRef(dest)
// If neither is qualified, this is a simple within-vault rename
if !srcQualified && !destQualified {
return cli.moveSecretWithinVault(cmd, srcSecretName, destSecretName, force)
}
// Cross-vault move requires source to be qualified
if !srcQualified {
if !srcQualified && destQualified {
return errCrossVaultSourceUnqualified
}
@@ -726,29 +721,27 @@ func (cli *Instance) MoveSecret(
// Format: "work:secret default" means move to vault "default"
// Format: "work:secret default:newname" means move to vault "default"
// with a new name
if !destQualified {
if srcQualified && !destQualified {
// Check if dest is actually a vault name
vaults, err := vault.ListVaults(cli.fs, cli.stateDir)
if err == nil && slices.Contains(vaults, dest) {
// dest is a vault name, use source secret name
destVaultName = dest
destSecretName = srcSecretName
}
// If destVaultName is still empty, dest is a secret name in source vault
if destVaultName == "" {
} else {
// dest is a secret name in source vault
destVaultName = srcVaultName
destSecretName = dest
}
}
// If destination secret name is empty, use source secret name
if destSecretName == "" {
// If destination secret name is empty, use source secret name. A plain
// rename keeps it empty, so that the check below rejects it.
if srcQualified && destSecretName == "" {
destSecretName = srcSecretName
}
// Check both names before selecting a vault below, so that a rejected
// move leaves the current vault as it was.
// Check both names, for every form of the move, before selecting a vault
// below, so that a rejected move leaves the current vault as it was.
err := vault.ValidateSecretName(srcSecretName)
if err != nil {
return err
@@ -759,6 +752,11 @@ func (cli *Instance) MoveSecret(
return err
}
// If neither is qualified, this is a simple within-vault rename
if !srcQualified && !destQualified {
return cli.moveSecretWithinVault(cmd, srcSecretName, destSecretName, force)
}
// Same vault? Use simple rename if possible (optimization)
if srcVaultName == destVaultName {
// Select the vault and do a simple move
@@ -775,20 +773,11 @@ func (cli *Instance) MoveSecret(
cmd, srcVaultName, srcSecretName, destVaultName, destSecretName, force)
}
// moveSecretWithinVault handles rename within the current vault
// moveSecretWithinVault handles rename within the current vault. Its caller,
// MoveSecret, has already checked both secret names.
func (cli *Instance) moveSecretWithinVault(
cmd *cobra.Command, source, dest string, force bool,
) error {
err := vault.ValidateSecretName(source)
if err != nil {
return err
}
err = vault.ValidateSecretName(dest)
if err != nil {
return err
}
currentVlt, err := vault.GetCurrentVault(cli.fs, cli.stateDir)
if err != nil {
return err