feat: multi-recipient encrypt core + recipients.txt (EGB-283)
- Add RECIPIENTS_FILE_NAME / RECIPIENTS_FILE constants; update resolve_store to re-derive RECIPIENTS_FILE after store resolution. - Add _validate_age_recipient (native age1 X25519 key format check, injection rail). - Add RECIPIENT_ARGS global array and _load_recipients (absent → single pubkey legacy path; present → parse+validate recipients.txt, refuse symlink, die on bad/empty). - Rewire all 5 push encrypt sites (push_dir_to_project, cmd_push inline, push_external_files ×2, cmd_push_workspaces) to use RECIPIENT_ARGS; drop pubkey threading from push_dir_to_project and push_external_files signatures. - New test/recipients.bats (4 tests): legacy single-key, multi-recipient decrypt, invalid key rejection, symlink rejection. - Fix test/test_helper.bash: set GIT_AUTHOR/COMMITTER env vars so git commit works with isolated $HOME. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
3a7eea5529
commit
0f9de1c2fd
3 changed files with 129 additions and 14 deletions
|
|
@ -19,6 +19,14 @@ setup() {
|
|||
# not be a real ancestor of /tmp). EGB-281 F9.
|
||||
export HOME="$TEST_TMPDIR"
|
||||
|
||||
# Provide git author identity so `git commit` works with the fresh temp HOME
|
||||
# (no ~/.gitconfig is present in the isolated dir). GIT_* env vars override
|
||||
# any global config and survive the HOME redirect.
|
||||
export GIT_AUTHOR_NAME="Test User"
|
||||
export GIT_AUTHOR_EMAIL="test@example.com"
|
||||
export GIT_COMMITTER_NAME="Test User"
|
||||
export GIT_COMMITTER_EMAIL="test@example.com"
|
||||
|
||||
# Secrets repo lives in temp
|
||||
export SECRETS_DIR="$TEST_TMPDIR/secrets-repo"
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue