Accept a version argument only if the secret has that version (closes #67) #77

Merged
clawbot merged 1 commits from issue-67-check-version-argument into next 2026-10-04 03:25:01 +02:00
Collaborator

secret version rm, secret version promote and secret get --version put the version argument into a file path without checking it, so secret version rm x ../../.. deleted the whole vault, .. the secret x, and . or "" every version of it (#67).

A version is now accepted only if it is one of the versions secret version list shows for that secret: the argument, as typed, is compared with the names in the secret's versions directory before any path is built. One function, secret.VersionExists, does this for all three commands.

What the diff does not make obvious:

  • secret get --version "" now fails; before, an empty --version silently meant the current version. For this, vault.GetSecretVersion no longer treats "" as the current version. vault.GetSecret reads the current version's name from the current file and then fetches it like any other version, so that name is checked too. secret get without --version behaves as before.
  • The vault's "version not found" error now quotes the version and secret name, as the one from version rm and version promote already did, so an empty version shows up in it.
  • The regression tests reuse the state-recording helper from #65. Its assertion helper now takes the expected error instead of a rejected secret name and compares exact messages; its separate check that the error wraps the invalid-name error is dropped, since the exact message already pins it.

Model: opus-5-5

`secret version rm`, `secret version promote` and `secret get --version` put the version argument into a file path without checking it, so `secret version rm x ../../..` deleted the whole vault, `..` the secret `x`, and `.` or `""` every version of it (https://git.eeqj.de/sneak/secret/issues/67). A version is now accepted only if it is one of the versions `secret version list` shows for that secret: the argument, as typed, is compared with the names in the secret's `versions` directory before any path is built. One function, `secret.VersionExists`, does this for all three commands. What the diff does not make obvious: - `secret get --version ""` now fails; before, an empty `--version` silently meant the current version. For this, `vault.GetSecretVersion` no longer treats `""` as the current version. `vault.GetSecret` reads the current version's name from the `current` file and then fetches it like any other version, so that name is checked too. `secret get` without `--version` behaves as before. - The vault's "version not found" error now quotes the version and secret name, as the one from `version rm` and `version promote` already did, so an empty version shows up in it. - The regression tests reuse the state-recording helper from https://git.eeqj.de/sneak/secret/pulls/65. Its assertion helper now takes the expected error instead of a rejected secret name and compares exact messages; its separate check that the error wraps the invalid-name error is dropped, since the exact message already pins it. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 02:25:39 +02:00
clawbot self-assigned this 2026-10-04 02:25:39 +02:00
clawbot added 1 commit 2026-10-04 02:25:39 +02:00
version rm, version promote and get --version joined the version
argument into a path unchecked, so "", ".", "..", "../../.." removed or
read every version, the secret, the vault or directories above it.

A version is now accepted only if it is one of the versions
ListVersions lists for the secret, compared by name before any path is
built (secret.VersionExists, used by all three). An empty --version is
rejected instead of meaning the current version: GetSecretVersion no
longer treats "" as current, and GetSecret looks the current version
up itself.

Model: opus-5-5
Author
Collaborator

secret version rm, secret version promote and secret get --version now accept a version only if it is one of the secret's versions, compared as typed before any path is built, and the tests show that the rejected arguments leave everything under the state directory unchanged.

Judgement call: a hidden or leftover directory inside a secret's versions directory counts as a version, because secret version list shows it and the definition of done accepts any existing entry. So version promote accepts its name, and nothing outside that directory is touched.

Model: opus-5-5

`secret version rm`, `secret version promote` and `secret get --version` now accept a version only if it is one of the secret's versions, compared as typed before any path is built, and the tests show that the rejected arguments leave everything under the state directory unchanged. Judgement call: a hidden or leftover directory inside a secret's `versions` directory counts as a version, because `secret version list` shows it and the definition of done accepts any existing entry. So `version promote` accepts its name, and nothing outside that directory is touched. Model: opus-5-5
clawbot merged commit bdb1c7ec18 into next 2026-10-04 03:25:01 +02:00
clawbot deleted branch issue-67-check-version-argument 2026-10-04 03:25:01 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#77