Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e5a13e8fdb |
@@ -26,11 +26,12 @@ the tag exists and is exercised; what is left is merging `next` to
|
|||||||
([issue #240](https://git.eeqj.de/sneak/vaultik/issues/240)). A config
|
([issue #240](https://git.eeqj.de/sneak/vaultik/issues/240)). A config
|
||||||
file that others can read was warned about as containing S3
|
file that others can read was warned about as containing S3
|
||||||
credentials even when it set none, as a `file://` config does. The
|
credentials even when it set none, as a `file://` config does. The
|
||||||
warning now names the credentials only when `s3.access_key_id` or
|
warning now says the file may contain S3 credentials only when
|
||||||
`s3.secret_access_key` is set, and otherwise says the file is readable
|
`s3.access_key_id` or `s3.secret_access_key` is set, since either may
|
||||||
by others. `snapshot purge` against a destination store it could not
|
come from a `${...}` reference rather than the file, and otherwise
|
||||||
list gave an error with `listing remote snapshots:` in it twice; the
|
says the file is readable by others. `snapshot purge` against a
|
||||||
prefix now appears once.
|
destination store it could not list gave an error with
|
||||||
|
`listing remote snapshots:` in it twice; the prefix now appears once.
|
||||||
|
|
||||||
- 2026-10-07: Made per-name retention work when the hostname contains `_`
|
- 2026-10-07: Made per-name retention work when the hostname contains `_`
|
||||||
([issue #230](https://git.eeqj.de/sneak/vaultik/issues/230)). A
|
([issue #230](https://git.eeqj.de/sneak/vaultik/issues/230)). A
|
||||||
|
|||||||
@@ -412,10 +412,12 @@ func (c *Config) setAgeSecretKey() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// readableByOthersWarning is the warning Load logs when others can read
|
// readableByOthersWarning is the warning Load logs when others can read
|
||||||
// the config file. It names the S3 credentials only when they are set.
|
// the config file. It says "may contain" because the S3 credentials are
|
||||||
|
// seen only after smartconfig has replaced any ${...} reference in the
|
||||||
|
// file with its value, so a set credential need not be in the file.
|
||||||
func (c *Config) readableByOthersWarning() string {
|
func (c *Config) readableByOthersWarning() string {
|
||||||
if c.S3.AccessKeyID != "" || c.S3.SecretAccessKey != "" {
|
if c.S3.AccessKeyID != "" || c.S3.SecretAccessKey != "" {
|
||||||
return "Config file contains S3 credentials and is readable by others"
|
return "Config file is readable by others and may contain S3 credentials"
|
||||||
}
|
}
|
||||||
|
|
||||||
return "Config file is readable by others"
|
return "Config file is readable by others"
|
||||||
|
|||||||
@@ -423,11 +423,16 @@ snapshots:
|
|||||||
}
|
}
|
||||||
|
|
||||||
// TestLoadWarnsReadableConfigWithS3Credentials checks that a config file
|
// TestLoadWarnsReadableConfigWithS3Credentials checks that a config file
|
||||||
// others can read is warned about as holding the S3 credentials it sets.
|
// others can read and that sets S3 credentials, as values or as ${ENV:...}
|
||||||
|
// references, is warned about as one that may contain them.
|
||||||
//
|
//
|
||||||
//nolint:paralleltest // loadReadableConfig replaces os.Stderr
|
//nolint:paralleltest // loadReadableConfig replaces os.Stderr
|
||||||
func TestLoadWarnsReadableConfigWithS3Credentials(t *testing.T) {
|
func TestLoadWarnsReadableConfigWithS3Credentials(t *testing.T) {
|
||||||
stderr := loadReadableConfig(t, `
|
t.Setenv("VAULTIK_TEST_ACCESS_KEY_ID", "test-access-key")
|
||||||
|
t.Setenv("VAULTIK_TEST_SECRET_ACCESS_KEY", "test-secret-key")
|
||||||
|
|
||||||
|
configs := map[string]string{
|
||||||
|
"values": `
|
||||||
storage_url: s3://bucket/prefix?endpoint=s3.example.com
|
storage_url: s3://bucket/prefix?endpoint=s3.example.com
|
||||||
s3:
|
s3:
|
||||||
access_key_id: test-access-key
|
access_key_id: test-access-key
|
||||||
@@ -436,10 +441,28 @@ snapshots:
|
|||||||
home:
|
home:
|
||||||
paths:
|
paths:
|
||||||
- /home
|
- /home
|
||||||
`)
|
`,
|
||||||
|
"references": `
|
||||||
|
storage_url: s3://bucket/prefix?endpoint=s3.example.com
|
||||||
|
s3:
|
||||||
|
access_key_id: ${ENV:VAULTIK_TEST_ACCESS_KEY_ID}
|
||||||
|
secret_access_key: ${ENV:VAULTIK_TEST_SECRET_ACCESS_KEY}
|
||||||
|
snapshots:
|
||||||
|
home:
|
||||||
|
paths:
|
||||||
|
- /home
|
||||||
|
`,
|
||||||
|
}
|
||||||
|
|
||||||
if !strings.Contains(stderr,
|
for name, configYAML := range configs {
|
||||||
"Config file contains S3 credentials and is readable by others") {
|
t.Run(name, func(t *testing.T) {
|
||||||
t.Errorf("expected a warning naming the S3 credentials, got %q", stderr)
|
stderr := loadReadableConfig(t, configYAML)
|
||||||
|
|
||||||
|
if !strings.Contains(stderr,
|
||||||
|
"Config file is readable by others and may contain S3 credentials") {
|
||||||
|
t.Errorf("expected a warning naming the S3 credentials, got %q",
|
||||||
|
stderr)
|
||||||
|
}
|
||||||
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user