check / check (push) Waiting to run
A vault name may use only lowercase ASCII letters, digits, `.`, `-` and `_`, and must not be empty, `.` or `..`; the error now states that rule. `vault create`, `vault import`, `vault select`, `vault remove`, both vault names of `mv` and shell completion of a `vault:secret` argument check the name as typed before building any path from it. Before, `vault import ..` wrote a long-term key and an unlocker into the state directory itself, and `vault select ..` made that the current vault. Model: opus-5-5
42 lines
1.3 KiB
Go
42 lines
1.3 KiB
Go
//nolint:testpackage // white-box test of unexported internals
|
|
package cli
|
|
|
|
import (
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"github.com/spf13/afero"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// TestVaultSecretCompletionRejectsInvalidVaultName is a regression test for
|
|
// https://git.eeqj.de/sneak/secret/issues/68: completing a `vault:secret`
|
|
// argument lists nothing when the vault part is not a valid vault name, even
|
|
// where that name, joined onto vaults.d, leads to a secrets.d directory.
|
|
func TestVaultSecretCompletionRejectsInvalidVaultName(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
const (
|
|
stateDir = "/state"
|
|
dirPerm = 0o700
|
|
)
|
|
|
|
fs := afero.NewMemMapFs()
|
|
|
|
// The vault "work" holds the secret "x". So does every directory an
|
|
// invalid name below would lead to from vaults.d.
|
|
for _, vaultName := range []string{"work", ".", "..", "a/b"} {
|
|
secretDir := filepath.Join(stateDir, "vaults.d", vaultName, "secrets.d", "x")
|
|
require.NoError(t, fs.MkdirAll(secretDir, dirPerm))
|
|
}
|
|
|
|
assert.Equal(t, []string{"work:x"},
|
|
completeVaultQualifiedSecrets(fs, stateDir, "work:"))
|
|
|
|
for _, toComplete := range []string{".:", "..:", "a/b:"} {
|
|
assert.Empty(t, completeVaultQualifiedSecrets(fs, stateDir, toComplete),
|
|
"completing %q", toComplete)
|
|
}
|
|
}
|