Files
secret/internal
sneak 720fa80235
check / check (push) Successful in 49s
Reject invalid secret names before any command builds a path (closes #33)
`secret rm ..` resolved to the vault directory and deleted the whole
vault; `secret rm .` and `secret rm ""` deleted every secret. rm, mv,
the version commands, encrypt and decrypt built paths from the name
without checking it; import checked it only after reading the source
file.

vault.ValidateSecretName wraps the existing name rule; its error and
README.md state the rule. Each of those commands calls it on the name
as given, before building any path; MoveSecret checks both names once,
for every form of the move, before switching the current vault.
AddSecret, GetSecretVersion and GetSecretObject use it too.

The regression test copies two in-memory vaults for each rejected
command and requires the exact error and an unchanged state directory.

Model: opus-5-5
2026-10-03 14:54:16 +00:00
..