Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ba49308da2 |
@@ -118,32 +118,14 @@ func newFsFromSnapshot(t *testing.T, tree map[string]string) afero.Fs {
|
|||||||
return fs
|
return fs
|
||||||
}
|
}
|
||||||
|
|
||||||
// requireRejectedAndUnchanged runs a command on a copy of the state
|
|
||||||
// directory recorded in before. It requires exactly the error
|
|
||||||
// vault.ValidateSecretName gives for the rejected name, so that a later
|
|
||||||
// check rejecting the name does not count, and everything under the state
|
|
||||||
// directory as it was: the error alone proves nothing, since it could come
|
|
||||||
// after the vault had already been deleted.
|
|
||||||
func requireRejectedAndUnchanged(
|
|
||||||
t *testing.T, before map[string]string, rejected string,
|
|
||||||
run func(c *cli.Instance) error,
|
|
||||||
) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
fs := newFsFromSnapshot(t, before)
|
|
||||||
|
|
||||||
err := run(cli.NewCLIInstanceWithStateDir(fs, testStateDir))
|
|
||||||
|
|
||||||
require.Equal(t, before, snapshotStateDir(t, fs))
|
|
||||||
require.ErrorIs(t, err, vault.ErrInvalidSecretName)
|
|
||||||
require.EqualError(t, err, vault.ValidateSecretName(rejected).Error())
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestInvalidSecretNameLeavesVaultsUnchanged is a regression test for
|
// TestInvalidSecretNameLeavesVaultsUnchanged is a regression test for
|
||||||
// https://git.eeqj.de/sneak/secret/issues/33, where `secret rm ..` deleted
|
// https://git.eeqj.de/sneak/secret/issues/33, where `secret rm ..` deleted
|
||||||
// the whole vault, and `secret rm .` or `secret rm ""` every secret in it.
|
// the whole vault, and `secret rm .` or `secret rm ""` every secret in it.
|
||||||
// Moves and imports use --force, so that only the name check stands in
|
// Each command must fail with exactly the error vault.ValidateSecretName
|
||||||
// the way.
|
// gives for the name, and leave everything under the state directory as it
|
||||||
|
// was: the error alone proves nothing, since it could come after the vault
|
||||||
|
// had already been deleted. Moves and imports use --force, so that only
|
||||||
|
// the name check stands in the way.
|
||||||
//
|
//
|
||||||
//nolint:paralleltest // newTwoVaultFs uses t.Setenv
|
//nolint:paralleltest // newTwoVaultFs uses t.Setenv
|
||||||
func TestInvalidSecretNameLeavesVaultsUnchanged(t *testing.T) {
|
func TestInvalidSecretNameLeavesVaultsUnchanged(t *testing.T) {
|
||||||
@@ -226,7 +208,13 @@ func TestInvalidSecretNameLeavesVaultsUnchanged(t *testing.T) {
|
|||||||
|
|
||||||
for _, tt := range tests {
|
for _, tt := range tests {
|
||||||
t.Run(tt.command, func(t *testing.T) {
|
t.Run(tt.command, func(t *testing.T) {
|
||||||
requireRejectedAndUnchanged(t, before, tt.rejected, tt.run)
|
fs := newFsFromSnapshot(t, before)
|
||||||
|
|
||||||
|
err := tt.run(cli.NewCLIInstanceWithStateDir(fs, testStateDir))
|
||||||
|
|
||||||
|
require.Equal(t, before, snapshotStateDir(t, fs))
|
||||||
|
require.ErrorIs(t, err, vault.ErrInvalidSecretName)
|
||||||
|
require.EqualError(t, err, vault.ValidateSecretName(tt.rejected).Error())
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user