check / check (pull_request) Successful in 2m29s
Restore and verify --deep now parse the configured age secret key a single time through a new internal helper that uses age.ParseIdentities and hands every identity to age.Decrypt. A key file with several identities (a whole age-keygen file) is fully accepted, so a blob encrypted to any of its recipients decrypts, not just the first. The helper is the first step of both commands, so a missing or unparseable key now fails before anything is downloaded. Its error names the configuration source (VAULTIK_AGE_SECRET_KEY or age_secret_key) and never echoes the key value. config.extractAgeSecretKey and its silent fallback are removed; the key is stored raw and parsed only where decryption happens, so backup, list and prune are unaffected. README, the restore help, and the missing-key error now show the key read from a file with $(cat ...) rather than typed literally, keeping it out of shell history, and say the variable may hold the whole key file. Model: opus-4-8