check / check (push) Failing after 3s
REPO_POLICIES.md requires the module root sneak.berlin/go/<name>. go.mod, every import (rewritten with gofmt -r), the -X flags in script/build and the examples in the pkg READMEs now use the new path. go mod tidy lists go-humanize and fatih/color as direct requirements, since internal/cli imports them. This breaks anyone who fetched or imported git.eeqj.de/sneak/secret: they must switch to sneak.berlin/go/secret, which resolves to this repository. Model: opus-5-5
68 lines
2.0 KiB
Go
68 lines
2.0 KiB
Go
//nolint:testpackage // white-box test of unexported internals
|
|
package cli
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/awnumar/memguard"
|
|
"github.com/spf13/afero"
|
|
"github.com/stretchr/testify/require"
|
|
"sneak.berlin/go/secret/internal/vault"
|
|
)
|
|
|
|
// TestInvalidMnemonicError checks that every command that takes a mnemonic
|
|
// returns errInvalidMnemonicPhrase for one that is not valid BIP39. The vault
|
|
// "other" has no long-term key, as vault import needs.
|
|
func TestInvalidMnemonicError(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
tests := []struct {
|
|
command string
|
|
run func(c *Instance) error
|
|
}{
|
|
{"secret init", func(c *Instance) error { return c.Init(c.cmd) }},
|
|
{"secret vault create work", func(c *Instance) error {
|
|
return c.CreateVault(c.cmd, "work")
|
|
}},
|
|
{"secret vault import other", func(c *Instance) error {
|
|
return c.VaultImport(c.cmd, "other")
|
|
}},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.command, func(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
fs := afero.NewMemMapFs()
|
|
_, err := vault.CreateVault(fs, listTestStateDir, "other", nil, nil)
|
|
require.NoError(t, err)
|
|
|
|
instance, _ := newTestInstance(fs)
|
|
instance.Mnemonic = memguard.NewBufferFromBytes([]byte("not a mnemonic"))
|
|
t.Cleanup(instance.Mnemonic.Destroy)
|
|
|
|
require.ErrorIs(t, tt.run(instance), errInvalidMnemonicPhrase)
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestGenerateSecretErrors checks that `secret generate secret` gives one
|
|
// error for a length below 1 and one for a type it cannot generate.
|
|
func TestGenerateSecretErrors(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
instance, cmd := newTestInstance(afero.NewMemMapFs())
|
|
|
|
err := instance.GenerateSecret(cmd, "x", 0, "base58", false)
|
|
require.ErrorIs(t, err, errLengthTooSmall)
|
|
|
|
_, err = generateRandomString(0, "ab")
|
|
require.ErrorIs(t, err, errLengthTooSmall)
|
|
|
|
err = instance.GenerateSecret(cmd, "x", defaultSecretLength, "mnemonic", false)
|
|
require.ErrorIs(t, err, errUnsupportedSecretType)
|
|
|
|
err = instance.GenerateSecret(cmd, "x", defaultSecretLength, "hex", false)
|
|
require.ErrorIs(t, err, errUnsupportedSecretType)
|
|
}
|