Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a83743383e |
@@ -23,9 +23,7 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
|||||||
keeps its own copies of `vault.ErrSecretNotFound`, `ErrVaultNotFound`,
|
keeps its own copies of `vault.ErrSecretNotFound`, `ErrVaultNotFound`,
|
||||||
`ErrVersionNotFound` and `ErrSecretExists`: `secret mv`, `rm`, `decrypt`,
|
`ErrVersionNotFound` and `ErrSecretExists`: `secret mv`, `rm`, `decrypt`,
|
||||||
`vault import`, `vault remove` and `version list`, `promote` and `rm` wrap
|
`vault import`, `vault remove` and `version list`, `promote` and `rm` wrap
|
||||||
the `vault` errors. `errUnsupportedUnlockerType` is removed: `secret
|
the `vault` errors. Messages are unchanged, except that `secret decrypt`
|
||||||
unlocker add` gives `errInvalidUnlockerType` for an unknown type, whichever
|
|
||||||
check rejects it. Messages are unchanged, except that `secret decrypt`
|
|
||||||
of a missing secret says "not found", as `secret get` does, not "does not
|
of a missing secret says "not found", as `secret get` does, not "does not
|
||||||
exist". Every error of `secret.ReadPassphrase` wraps
|
exist". Every error of `secret.ReadPassphrase` wraps
|
||||||
`secret.ErrPassphraseNotRead`, which supplies the words "failed to read
|
`secret.ErrPassphraseNotRead`, which supplies the words "failed to read
|
||||||
|
|||||||
@@ -61,29 +61,16 @@ func TestRejectedMoveWithinVaultLeavesStateUnchanged(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
missing := []struct {
|
// A missing secret, and a missing vault: only an existing vault is used.
|
||||||
command string
|
for source, want := range map[string]error{
|
||||||
source, dest string
|
"work:nosuch": vault.ErrSecretNotFound,
|
||||||
force bool
|
"nosuch:x": vault.ErrVaultNotFound,
|
||||||
want error
|
|
||||||
} {
|
} {
|
||||||
{
|
t.Run("mv --force "+source+" work:y", func(t *testing.T) {
|
||||||
"mv work:nosuch work:y", "work:nosuch", "work:y", false,
|
|
||||||
vault.ErrSecretNotFound,
|
|
||||||
},
|
|
||||||
// Only an existing vault is used.
|
|
||||||
{
|
|
||||||
"mv --force nosuch:x nosuch:y", "nosuch:x", "nosuch:y", true,
|
|
||||||
vault.ErrVaultNotFound,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range missing {
|
|
||||||
t.Run(tt.command, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
requireRejectedAndUnchanged(t, before, tt.want, func(c *cli.Instance) error {
|
requireRejectedAndUnchanged(t, before, want, func(c *cli.Instance) error {
|
||||||
return c.MoveSecret(&cobra.Command{}, tt.source, tt.dest, tt.force)
|
return c.MoveSecret(&cobra.Command{}, source, "work:y", true)
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -47,6 +47,7 @@ var (
|
|||||||
// composes "GPG key <id> is already added as an unlocker".
|
// composes "GPG key <id> is already added as an unlocker".
|
||||||
errGPGKeyAlreadyUnlocker = errors.New(
|
errGPGKeyAlreadyUnlocker = errors.New(
|
||||||
"is already added as an unlocker")
|
"is already added as an unlocker")
|
||||||
|
errUnsupportedUnlockerType = errors.New("unsupported unlocker type")
|
||||||
)
|
)
|
||||||
|
|
||||||
// UnlockerInfo represents unlocker information for display
|
// UnlockerInfo represents unlocker information for display
|
||||||
@@ -438,7 +439,7 @@ func (cli *Instance) UnlockersAdd(unlockerType string, cmd *cobra.Command) error
|
|||||||
}
|
}
|
||||||
|
|
||||||
return fmt.Errorf("%w: %s (supported: %s)",
|
return fmt.Errorf("%w: %s (supported: %s)",
|
||||||
errInvalidUnlockerType, unlockerType, supportedTypes)
|
errUnsupportedUnlockerType, unlockerType, supportedTypes)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user