Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
79bc021412 |
+22
-15
@@ -30,6 +30,8 @@ func TestRejectedMoveWithinVaultLeavesStateUnchanged(t *testing.T) {
|
|||||||
workX = "work:x"
|
workX = "work:x"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// internal/cli declares these errors itself and does not export them, so
|
||||||
|
// only their text can be compared.
|
||||||
tests := []struct {
|
tests := []struct {
|
||||||
command string
|
command string
|
||||||
source, dest string
|
source, dest string
|
||||||
@@ -52,21 +54,6 @@ func TestRejectedMoveWithinVaultLeavesStateUnchanged(t *testing.T) {
|
|||||||
"mv --force nosuch:x nosuch:y", "nosuch:x", "nosuch:y", true,
|
"mv --force nosuch:x nosuch:y", "nosuch:x", "nosuch:y", true,
|
||||||
"vault 'nosuch' does not exist",
|
"vault 'nosuch' does not exist",
|
||||||
},
|
},
|
||||||
// Each of these spells "work" a second way. The spelling is not a
|
|
||||||
// valid vault name, so the move is not taken for a move between two
|
|
||||||
// vaults, which would delete the destination, here the source.
|
|
||||||
{
|
|
||||||
"mv --force work:x work/:x", workX, "work/:x", true,
|
|
||||||
vault.ValidateVaultName("work/").Error(),
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"mv --force work/:x work:", "work/:x", "work:", true,
|
|
||||||
vault.ValidateVaultName("work/").Error(),
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"mv --force work:x ./work:x", workX, "./work:x", true,
|
|
||||||
vault.ValidateVaultName("./work").Error(),
|
|
||||||
},
|
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, tt := range tests {
|
||||||
@@ -82,6 +69,26 @@ func TestRejectedMoveWithinVaultLeavesStateUnchanged(t *testing.T) {
|
|||||||
require.EqualError(t, err, tt.wantErr)
|
require.EqualError(t, err, tt.wantErr)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Each of these spells "work" a second way. The spelling is not a valid
|
||||||
|
// vault name, so the move is not taken for a move between two vaults,
|
||||||
|
// which would delete the destination, here the source.
|
||||||
|
invalidNames := []struct{ source, dest string }{
|
||||||
|
{workX, "work/:x"},
|
||||||
|
{"work/:x", "work:"},
|
||||||
|
{workX, "./work:x"},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range invalidNames {
|
||||||
|
t.Run("mv --force "+tt.source+" "+tt.dest, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
requireRejectedAndUnchanged(t, before, vault.ErrInvalidVaultName,
|
||||||
|
func(c *cli.Instance) error {
|
||||||
|
return c.MoveSecret(&cobra.Command{}, tt.source, tt.dest, true)
|
||||||
|
})
|
||||||
|
})
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestMoveWithinOtherVaultKeepsCurrentVault checks that `secret mv work:x
|
// TestMoveWithinOtherVaultKeepsCurrentVault checks that `secret mv work:x
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ package secret
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"os"
|
"os"
|
||||||
|
"path/filepath"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -107,5 +108,10 @@ func TestSecureEnclaveUnlockerGetIdentityMissingFile(t *testing.T) {
|
|||||||
// GetIdentity should fail because the encrypted longterm key file is missing
|
// GetIdentity should fail because the encrypted longterm key file is missing
|
||||||
identity, err := unlocker.GetIdentity()
|
identity, err := unlocker.GetIdentity()
|
||||||
assert.Nil(t, identity)
|
assert.Nil(t, identity)
|
||||||
|
|
||||||
|
var cause *os.PathError
|
||||||
|
|
||||||
|
require.ErrorAs(t, err, &cause)
|
||||||
require.ErrorIs(t, err, os.ErrNotExist)
|
require.ErrorIs(t, err, os.ErrNotExist)
|
||||||
|
assert.Equal(t, filepath.Join(dir, seLongtermFilename), cause.Path)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -70,13 +70,15 @@ func TestVaultErrors(t *testing.T) {
|
|||||||
return vlt.CopySecretAllVersions(vlt, testSecretName, testSecretName, false)
|
return vlt.CopySecretAllVersions(vlt, testSecretName, testSecretName, false)
|
||||||
}, vault.ErrSecretExists},
|
}, vault.ErrSecretExists},
|
||||||
{"copy a secret without versions", func(vlt *vault.Vault) error {
|
{"copy a secret without versions", func(vlt *vault.Vault) error {
|
||||||
|
const versionless = "versionless"
|
||||||
|
|
||||||
err := vlt.GetFilesystem().MkdirAll(
|
err := vlt.GetFilesystem().MkdirAll(
|
||||||
filepath.Join(vaultDir, "secrets.d", missingName), secret.DirPerms)
|
filepath.Join(vaultDir, "secrets.d", versionless), secret.DirPerms)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
return vlt.CopySecretAllVersions(vlt, missingName, "copy", false)
|
return vlt.CopySecretAllVersions(vlt, versionless, "copy", false)
|
||||||
}, vault.ErrNoVersions},
|
}, vault.ErrNoVersions},
|
||||||
{"remove a missing unlocker", func(vlt *vault.Vault) error {
|
{"remove a missing unlocker", func(vlt *vault.Vault) error {
|
||||||
return vlt.RemoveUnlocker(missingName)
|
return vlt.RemoveUnlocker(missingName)
|
||||||
|
|||||||
@@ -37,8 +37,13 @@ func TestAddSecretFailsWithMissingPublicKey(t *testing.T) {
|
|||||||
defer value.Destroy()
|
defer value.Destroy()
|
||||||
|
|
||||||
err := vlt.AddSecret(testSecretName, value, false)
|
err := vlt.AddSecret(testSecretName, value, false)
|
||||||
|
|
||||||
|
var cause *os.PathError
|
||||||
|
|
||||||
|
require.ErrorAs(t, err, &cause)
|
||||||
require.ErrorIs(t, err, os.ErrNotExist,
|
require.ErrorIs(t, err, os.ErrNotExist,
|
||||||
"AddSecret should fail when public key is missing")
|
"AddSecret should fail when public key is missing")
|
||||||
|
assert.Equal(t, filepath.Join(vaultDir, "pub.age"), cause.Path)
|
||||||
|
|
||||||
// Verify that the secret directory was NOT created
|
// Verify that the secret directory was NOT created
|
||||||
secretDir := filepath.Join(vaultDir, "secrets.d", testSecretName)
|
secretDir := filepath.Join(vaultDir, "secrets.d", testSecretName)
|
||||||
|
|||||||
Reference in New Issue
Block a user