Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c0b02b3dcb |
@@ -23,7 +23,9 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
|||||||
keeps its own copies of `vault.ErrSecretNotFound`, `ErrVaultNotFound`,
|
keeps its own copies of `vault.ErrSecretNotFound`, `ErrVaultNotFound`,
|
||||||
`ErrVersionNotFound` and `ErrSecretExists`: `secret mv`, `rm`, `decrypt`,
|
`ErrVersionNotFound` and `ErrSecretExists`: `secret mv`, `rm`, `decrypt`,
|
||||||
`vault import`, `vault remove` and `version list`, `promote` and `rm` wrap
|
`vault import`, `vault remove` and `version list`, `promote` and `rm` wrap
|
||||||
the `vault` errors. Messages are unchanged, except that `secret decrypt`
|
the `vault` errors. `errUnsupportedUnlockerType` is removed: `secret
|
||||||
|
unlocker add` gives `errInvalidUnlockerType` for an unknown type, whichever
|
||||||
|
check rejects it. Messages are unchanged, except that `secret decrypt`
|
||||||
of a missing secret says "not found", as `secret get` does, not "does not
|
of a missing secret says "not found", as `secret get` does, not "does not
|
||||||
exist". Every error of `secret.ReadPassphrase` wraps
|
exist". Every error of `secret.ReadPassphrase` wraps
|
||||||
`secret.ErrPassphraseNotRead`, which supplies the words "failed to read
|
`secret.ErrPassphraseNotRead`, which supplies the words "failed to read
|
||||||
|
|||||||
@@ -61,16 +61,29 @@ func TestRejectedMoveWithinVaultLeavesStateUnchanged(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// A missing secret, and a missing vault: only an existing vault is used.
|
missing := []struct {
|
||||||
for source, want := range map[string]error{
|
command string
|
||||||
"work:nosuch": vault.ErrSecretNotFound,
|
source, dest string
|
||||||
"nosuch:x": vault.ErrVaultNotFound,
|
force bool
|
||||||
} {
|
want error
|
||||||
t.Run("mv --force "+source+" work:y", func(t *testing.T) {
|
}{
|
||||||
|
{
|
||||||
|
"mv work:nosuch work:y", "work:nosuch", "work:y", false,
|
||||||
|
vault.ErrSecretNotFound,
|
||||||
|
},
|
||||||
|
// Only an existing vault is used.
|
||||||
|
{
|
||||||
|
"mv --force nosuch:x nosuch:y", "nosuch:x", "nosuch:y", true,
|
||||||
|
vault.ErrVaultNotFound,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range missing {
|
||||||
|
t.Run(tt.command, func(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
requireRejectedAndUnchanged(t, before, want, func(c *cli.Instance) error {
|
requireRejectedAndUnchanged(t, before, tt.want, func(c *cli.Instance) error {
|
||||||
return c.MoveSecret(&cobra.Command{}, source, "work:y", true)
|
return c.MoveSecret(&cobra.Command{}, tt.source, tt.dest, tt.force)
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -47,7 +47,6 @@ var (
|
|||||||
// composes "GPG key <id> is already added as an unlocker".
|
// composes "GPG key <id> is already added as an unlocker".
|
||||||
errGPGKeyAlreadyUnlocker = errors.New(
|
errGPGKeyAlreadyUnlocker = errors.New(
|
||||||
"is already added as an unlocker")
|
"is already added as an unlocker")
|
||||||
errUnsupportedUnlockerType = errors.New("unsupported unlocker type")
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// UnlockerInfo represents unlocker information for display
|
// UnlockerInfo represents unlocker information for display
|
||||||
@@ -439,7 +438,7 @@ func (cli *Instance) UnlockersAdd(unlockerType string, cmd *cobra.Command) error
|
|||||||
}
|
}
|
||||||
|
|
||||||
return fmt.Errorf("%w: %s (supported: %s)",
|
return fmt.Errorf("%w: %s (supported: %s)",
|
||||||
errUnsupportedUnlockerType, unlockerType, supportedTypes)
|
errInvalidUnlockerType, unlockerType, supportedTypes)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user