fix: validate-before-mutate in recipients add/rm + verify messaging + doc/UX polish (EGB-283)
- Fix 1 (IMPORTANT): _recipients_rm and _recipients_add now call _load_recipients BEFORE any mutation. A hand-corrupted recipients.txt dies at validation, leaving the file untouched — prevents inconsistent state where the file is changed but blobs are not re-encrypted. On a legacy store (no recipients.txt), _load_recipients succeeds via the derived-pubkey path so the bootstrap path still works. - Fix 2 (MINOR): Guard _check_blob_recipient_count behind a successful decrypt in both _verify_all and _verify_project — an undecryptable blob no longer produces a spurious "encrypted to 0 recipients" finding. Reword _verify_all summary to "failed (decrypt or recipient-count)" since both failure modes now increment the counter. - Fix 3 (MINOR): Correct README offboarding comment from "New blobs are no longer readable" (contradicts the re-encrypt of EVERY blob) to "Existing blobs are re-encrypted; the removed key can no longer decrypt them." - Fix 4 (MINOR): cmd_reencrypt prints an advisory when no recipients.txt exists (single-key store), so the operator knows they can add teammates. - Fix 5 (MINOR): Test coverage for ambiguous-name rm refusing to remove when multiple recipients share a --name label. Tests: 5 new tests in test/recipients.bats (34 total, all pass). Full suite 276 tests: 5 known pre-existing failures (3 mode-600/stat, 2 jq-PATH), none new. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
f7576a3eae
commit
17772dfec6
3 changed files with 84 additions and 11 deletions
|
|
@ -494,7 +494,7 @@ you age1yourpublickey…
|
|||
# Remove the recipient by name (or public key) and re-encrypt the store
|
||||
secrets recipients rm alice
|
||||
# => Removes alice from recipients.txt, re-encrypts every blob, pushes.
|
||||
# New blobs are no longer readable by alice's key.
|
||||
# Existing blobs are re-encrypted; the removed key can no longer decrypt them.
|
||||
```
|
||||
|
||||
> **Important:** git history can't be un-shared. If alice had access during a period when genuinely sensitive values were stored, rotate those values now (update them in the external system and run `secrets push`). The re-encrypt prevents future access; history is permanent.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue