check / check (pull_request) Successful in 1m22s
Production encryption and decryption already run through blobgen; the crypto package (Encryptor, Decryptor, UpdateRecipients, the fx Module) and Vaultik.GetEncryptor/GetDecryptor had no production caller. Delete crypto and route verify --deep through the same blobgen reader restore uses: it parses the age key once and reads both the database (still streamed to a temp file) and every blob through blobgen.NewReader. The second, blob-ID hash step is now one exported function, blobgen.DoubleSHA256, called by the three former copies. Writer.Sum256 (the double hash) becomes Writer.ContentID so it no longer shares the name Sum256 with Reader.Sum256 (the single plaintext hash). CompressData and CompressStream, unused outside tests, are deleted. Delete the unused, never-adopted secret/config newtypes in internal/types (the redacting AgeSecretKey and AWSSecretAccessKey plus AgeRecipient, S3Endpoint, BucketName, S3Prefix, AWSRegion, AWSAccessKeyID). Delete the uncalled CleanupIncompleteSnapshots (and deleteSnapshot, its only caller, now dead) and correct ARCHITECTURE.md. The only multi-recipient test moves to blobgen; the pre-#131 encrypted-bytes hash test is removed. Model: opus-4-8
55 lines
1.5 KiB
Go
55 lines
1.5 KiB
Go
package blobgen_test
|
|
|
|
import (
|
|
"bytes"
|
|
"io"
|
|
"testing"
|
|
|
|
"filippo.io/age"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
"sneak.berlin/go/vaultik/internal/blobgen"
|
|
)
|
|
|
|
// TestMultipleRecipients verifies that data written for several recipients can
|
|
// be read back by each recipient's identity. Moved from internal/crypto, which
|
|
// held the only multi-recipient test; blobgen is now the sole encryption path.
|
|
func TestMultipleRecipients(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
identities := make([]*age.X25519Identity, 3)
|
|
recipients := make([]string, 3)
|
|
|
|
for i := range identities {
|
|
identity, err := age.GenerateX25519Identity()
|
|
require.NoError(t, err)
|
|
|
|
identities[i] = identity
|
|
recipients[i] = identity.Recipient().String()
|
|
}
|
|
|
|
plaintext := []byte("Secret message for multiple recipients")
|
|
|
|
var encrypted bytes.Buffer
|
|
|
|
writer, err := blobgen.NewWriter(&encrypted, 3, recipients)
|
|
require.NoError(t, err)
|
|
_, err = writer.Write(plaintext)
|
|
require.NoError(t, err)
|
|
require.NoError(t, writer.Close())
|
|
|
|
// Every recipient's identity must recover the original plaintext.
|
|
for i, identity := range identities {
|
|
reader, err := blobgen.NewReader(
|
|
bytes.NewReader(encrypted.Bytes()), identity)
|
|
require.NoError(t, err, "recipient %d should open the reader", i+1)
|
|
|
|
got, err := io.ReadAll(reader)
|
|
require.NoError(t, err, "recipient %d should read the plaintext", i+1)
|
|
require.NoError(t, reader.Close())
|
|
|
|
assert.Equal(t, plaintext, got,
|
|
"recipient %d should recover the original plaintext", i+1)
|
|
}
|
|
}
|