//nolint:testpackage // white-box test of unexported internals package cli import ( "path/filepath" "testing" "github.com/stretchr/testify/require" ) // unknownTestGPGUserID is a GPG user ID that no key in the test keyring has. const unknownTestGPGUserID = "not-in-keyring@example.com" // TestAddPGPUnlockerUnknownKey asserts that adding a PGP unlocker for a key // the keyring does not hold fails at looking up the key's fingerprint and // leaves no new unlocker directory. The error must come from the lookup: a // lookup moved after anything is written would also come after getting the // vault's long-term key, which fails first on every platform but macOS // (https://git.eeqj.de/sneak/secret/issues/88). // //nolint:paralleltest // t.Setenv (GNUPGHOME) forbids parallel tests func TestAddPGPUnlockerUnknownKey(t *testing.T) { newTestGPGKey(t) base := newListTestVault(t, 1) instance, cmd := newTestInstance(base) cmd.Flags().String("keyid", unknownTestGPGUserID, "") err := instance.addPGPUnlocker(cmd) require.ErrorContains(t, err, "failed to resolve GPG key fingerprint") assertDirEntries(t, base, filepath.Join(testVaultDir(listTestVaultName), listTestUnlockersDirName), listTestUnlockerDirOne) }