check / check (push) Failing after 3s
internal/cli's copies of vault.ErrSecretNotFound, ErrVaultNotFound, ErrVersionNotFound and ErrSecretExists are removed; the commands wrap the vault errors. errUnsupportedUnlockerType is removed for errInvalidUnlockerType, which names the same failure. Every error of secret.ReadPassphrase wraps ErrPassphraseNotRead, so its callers no longer add those words. ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for a key the keyring lacks, recognised by gpg's status line. storeInKeychain returns errNilDataBuffer. bip85's ErrPasswordTooShort and ErrEncodedTooShort go with their unreachable checks. Tests that matched these errors' text use errors.Is. Model: opus-5-5
107 lines
3.4 KiB
Go
107 lines
3.4 KiB
Go
//nolint:testpackage // white-box test of unexported internals
|
|
package cli
|
|
|
|
import (
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"git.eeqj.de/sneak/secret/internal/secret"
|
|
"git.eeqj.de/sneak/secret/internal/vault"
|
|
"github.com/awnumar/memguard"
|
|
"github.com/spf13/afero"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// unknownTestGPGUserID is a GPG user ID that no key in the test keyring has.
|
|
const unknownTestGPGUserID = "not-in-keyring@example.com"
|
|
|
|
// The secret TestAddPGPUnlocker stores, then reads through the new unlocker.
|
|
const (
|
|
addTestSecretName = "api-key"
|
|
addTestSecretValue = "value"
|
|
)
|
|
|
|
// TestAddPGPUnlocker adds a PGP unlocker for a throwaway GPG key to a vault
|
|
// with a passphrase unlocker, getting the vault's long-term key from the
|
|
// mnemonic or, with no mnemonic given, from the passphrase unlocker. It
|
|
// then reads a secret with neither the mnemonic nor the passphrase given, so
|
|
// through the new unlocker, which the add selects.
|
|
//
|
|
//nolint:paralleltest // t.Setenv (GNUPGHOME) forbids parallel tests
|
|
func TestAddPGPUnlocker(t *testing.T) {
|
|
newTestGPGKey(t)
|
|
|
|
passphrase := memguard.NewBufferFromBytes([]byte(testPassphrase))
|
|
t.Cleanup(passphrase.Destroy)
|
|
|
|
tests := []struct {
|
|
name string
|
|
// mnemonic is the mnemonic given while the unlocker is added, or nil.
|
|
mnemonic *memguard.LockedBuffer
|
|
}{
|
|
{"long-term key from the mnemonic", testMnemonicBuffer(t)},
|
|
{"long-term key from the current unlocker", nil},
|
|
}
|
|
|
|
for _, test := range tests {
|
|
t.Run(test.name, func(t *testing.T) {
|
|
fs := afero.NewMemMapFs()
|
|
vlt, err := vault.CreateVault(fs, listTestStateDir, listTestVaultName,
|
|
testMnemonicBuffer(t), nil)
|
|
require.NoError(t, err)
|
|
|
|
err = vlt.AddSecret(addTestSecretName,
|
|
memguard.NewBufferFromBytes([]byte(addTestSecretValue)), false)
|
|
require.NoError(t, err)
|
|
|
|
_, err = vlt.CreatePassphraseUnlocker(
|
|
memguard.NewBufferFromBytes([]byte(testPassphrase)))
|
|
require.NoError(t, err)
|
|
|
|
instance, cmd := newTestInstance(fs)
|
|
instance.Mnemonic = test.mnemonic
|
|
instance.UnlockPassphrase = passphrase
|
|
|
|
cmd.Flags().String("keyid", unreadableTestGPGUserID, "")
|
|
require.NoError(t, instance.UnlockersAdd(unlockerTypePGP, cmd))
|
|
|
|
reopened := vault.NewVault(fs, listTestStateDir, listTestVaultName)
|
|
|
|
current, err := reopened.GetCurrentUnlocker()
|
|
require.NoError(t, err)
|
|
assert.Equal(t, unlockerTypePGP, current.GetType())
|
|
|
|
value, err := reopened.GetSecret(addTestSecretName)
|
|
require.NoError(t, err)
|
|
|
|
defer value.Destroy()
|
|
|
|
assert.Equal(t, addTestSecretValue, value.String())
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestAddPGPUnlockerUnknownKey asserts that adding a PGP unlocker for a key
|
|
// the keyring does not hold fails at looking up the key's fingerprint and
|
|
// leaves no new unlocker directory. The error must come from the lookup: a
|
|
// lookup moved after anything is written would also come after getting the
|
|
// vault's long-term key, which fails first here: this vault's unlockers hold
|
|
// no keys.
|
|
//
|
|
//nolint:paralleltest // t.Setenv (GNUPGHOME) forbids parallel tests
|
|
func TestAddPGPUnlockerUnknownKey(t *testing.T) {
|
|
newTestGPGKey(t)
|
|
|
|
base := newListTestVault(t, 1)
|
|
instance, cmd := newTestInstance(base)
|
|
cmd.Flags().String("keyid", unknownTestGPGUserID, "")
|
|
|
|
err := instance.addPGPUnlocker(cmd)
|
|
|
|
require.ErrorIs(t, err, secret.ErrGPGKeyNotFound)
|
|
assertDirEntries(t, base,
|
|
filepath.Join(testVaultDir(listTestVaultName), listTestUnlockersDirName),
|
|
listTestUnlockerDirOne)
|
|
}
|