check / check (push) Failing after 2s
init and vault create put the mnemonic into the process environment for vault.CreateVault to read back, so every program they ran, gpg included, inherited it, and SB_SECRET_MNEMONIC and SB_UNLOCK_PASSPHRASE were read at 13 places and never unset. Each command that may need them now reads both once, in its RunE, into locked buffers on the CLI Instance, and unsets them at once. The buffers are passed down: vault.CreateVault takes the mnemonic, a Vault carries Mnemonic and UnlockPassphrase, and the PGP, keychain and Secure Enclave unlocker constructors take both; CreatePGPUnlocker sets them on the vault it loads through SetMnemonic and SetUnlockPassphrase, new in VaultInterface. README warns against both variables. Model: opus-5-5
106 lines
3.4 KiB
Go
106 lines
3.4 KiB
Go
//nolint:testpackage // white-box test of unexported internals
|
|
package cli
|
|
|
|
import (
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"git.eeqj.de/sneak/secret/internal/vault"
|
|
"github.com/awnumar/memguard"
|
|
"github.com/spf13/afero"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// unknownTestGPGUserID is a GPG user ID that no key in the test keyring has.
|
|
const unknownTestGPGUserID = "not-in-keyring@example.com"
|
|
|
|
// The secret TestAddPGPUnlocker stores, then reads through the new unlocker.
|
|
const (
|
|
addTestSecretName = "api-key"
|
|
addTestSecretValue = "value"
|
|
)
|
|
|
|
// TestAddPGPUnlocker adds a PGP unlocker for a throwaway GPG key to a vault
|
|
// with a passphrase unlocker, getting the vault's long-term key from the
|
|
// mnemonic or, with no mnemonic given, from the passphrase unlocker. It
|
|
// then reads a secret with neither the mnemonic nor the passphrase given, so
|
|
// through the new unlocker, which the add selects.
|
|
//
|
|
//nolint:paralleltest // t.Setenv (GNUPGHOME) forbids parallel tests
|
|
func TestAddPGPUnlocker(t *testing.T) {
|
|
newTestGPGKey(t)
|
|
|
|
passphrase := memguard.NewBufferFromBytes([]byte(testPassphrase))
|
|
t.Cleanup(passphrase.Destroy)
|
|
|
|
tests := []struct {
|
|
name string
|
|
// mnemonic is the mnemonic given while the unlocker is added, or nil.
|
|
mnemonic *memguard.LockedBuffer
|
|
}{
|
|
{"long-term key from the mnemonic", testMnemonicBuffer(t)},
|
|
{"long-term key from the current unlocker", nil},
|
|
}
|
|
|
|
for _, test := range tests {
|
|
t.Run(test.name, func(t *testing.T) {
|
|
fs := afero.NewMemMapFs()
|
|
vlt, err := vault.CreateVault(fs, listTestStateDir, listTestVaultName,
|
|
testMnemonicBuffer(t))
|
|
require.NoError(t, err)
|
|
|
|
err = vlt.AddSecret(addTestSecretName,
|
|
memguard.NewBufferFromBytes([]byte(addTestSecretValue)), false)
|
|
require.NoError(t, err)
|
|
|
|
_, err = vlt.CreatePassphraseUnlocker(
|
|
memguard.NewBufferFromBytes([]byte(testPassphrase)))
|
|
require.NoError(t, err)
|
|
|
|
instance, cmd := newTestInstance(fs)
|
|
instance.Mnemonic = test.mnemonic
|
|
instance.UnlockPassphrase = passphrase
|
|
|
|
cmd.Flags().String("keyid", unreadableTestGPGUserID, "")
|
|
require.NoError(t, instance.UnlockersAdd(unlockerTypePGP, cmd))
|
|
|
|
reopened := vault.NewVault(fs, listTestStateDir, listTestVaultName)
|
|
|
|
current, err := reopened.GetCurrentUnlocker()
|
|
require.NoError(t, err)
|
|
assert.Equal(t, unlockerTypePGP, current.GetType())
|
|
|
|
value, err := reopened.GetSecret(addTestSecretName)
|
|
require.NoError(t, err)
|
|
|
|
defer value.Destroy()
|
|
|
|
assert.Equal(t, addTestSecretValue, value.String())
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestAddPGPUnlockerUnknownKey asserts that adding a PGP unlocker for a key
|
|
// the keyring does not hold fails at looking up the key's fingerprint and
|
|
// leaves no new unlocker directory. The error must come from the lookup: a
|
|
// lookup moved after anything is written would also come after getting the
|
|
// vault's long-term key, which fails first here: this vault's unlockers hold
|
|
// no keys.
|
|
//
|
|
//nolint:paralleltest // t.Setenv (GNUPGHOME) forbids parallel tests
|
|
func TestAddPGPUnlockerUnknownKey(t *testing.T) {
|
|
newTestGPGKey(t)
|
|
|
|
base := newListTestVault(t, 1)
|
|
instance, cmd := newTestInstance(base)
|
|
cmd.Flags().String("keyid", unknownTestGPGUserID, "")
|
|
|
|
err := instance.addPGPUnlocker(cmd)
|
|
|
|
require.ErrorContains(t, err, "failed to resolve GPG key fingerprint")
|
|
assertDirEntries(t, base,
|
|
filepath.Join(testVaultDir(listTestVaultName), listTestUnlockersDirName),
|
|
listTestUnlockerDirOne)
|
|
}
|