check / check (push) Failing after 19s
Vault.GetSecret and Vault.GetSecretVersion return the decrypted value as a *memguard.LockedBuffer instead of copying it into an ordinary []byte that nothing wiped. Every caller destroys the buffer, and `secret get` writes its bytes straight to stdout, still with no trailing newline. Instance.Print, which formatted through fmt and had no other callers, is removed, and so is a debug log line in `get --version` that held the plaintext value. Model: opus-5-5
71 lines
1.7 KiB
Go
71 lines
1.7 KiB
Go
// Package cli implements the command-line interface for the secret application.
|
|
package cli
|
|
|
|
import (
|
|
"fmt"
|
|
|
|
"git.eeqj.de/sneak/secret/internal/secret"
|
|
"github.com/spf13/afero"
|
|
"github.com/spf13/cobra"
|
|
)
|
|
|
|
// Instance encapsulates all CLI functionality and state
|
|
type Instance struct {
|
|
fs afero.Fs
|
|
stateDir string
|
|
cmd *cobra.Command
|
|
}
|
|
|
|
// NewCLIInstance creates a new CLI instance with the real filesystem
|
|
func NewCLIInstance() (*Instance, error) {
|
|
fs := afero.NewOsFs()
|
|
|
|
stateDir, err := secret.DetermineStateDir("")
|
|
if err != nil {
|
|
return nil, fmt.Errorf("cannot determine state directory: %w", err)
|
|
}
|
|
|
|
return &Instance{
|
|
fs: fs,
|
|
stateDir: stateDir,
|
|
}, nil
|
|
}
|
|
|
|
// NewCLIInstanceWithFs creates a new CLI instance with the given
|
|
// filesystem (for testing)
|
|
func NewCLIInstanceWithFs(fs afero.Fs) (*Instance, error) {
|
|
stateDir, err := secret.DetermineStateDir("")
|
|
if err != nil {
|
|
return nil, fmt.Errorf("cannot determine state directory: %w", err)
|
|
}
|
|
|
|
return &Instance{
|
|
fs: fs,
|
|
stateDir: stateDir,
|
|
}, nil
|
|
}
|
|
|
|
// NewCLIInstanceWithStateDir creates a new CLI instance with custom state
|
|
// directory (for testing)
|
|
func NewCLIInstanceWithStateDir(fs afero.Fs, stateDir string) *Instance {
|
|
return &Instance{
|
|
fs: fs,
|
|
stateDir: stateDir,
|
|
}
|
|
}
|
|
|
|
// SetFilesystem sets the filesystem for this CLI instance (for testing)
|
|
func (cli *Instance) SetFilesystem(fs afero.Fs) {
|
|
cli.fs = fs
|
|
}
|
|
|
|
// SetStateDir sets the state directory for this CLI instance (for testing)
|
|
func (cli *Instance) SetStateDir(stateDir string) {
|
|
cli.stateDir = stateDir
|
|
}
|
|
|
|
// GetStateDir returns the state directory for this CLI instance
|
|
func (cli *Instance) GetStateDir() string {
|
|
return cli.stateDir
|
|
}
|