fix: secrets which prints full .secrets-store path (v0.1.0.1)
_find_secrets_store_file used to set _LAST_FOUND_AT inside the $(...) subshell that resolve_store invoked it from, so the parent shell never received the value and `secrets which` reported `source: .secrets-store file ()` with empty parens. Function now returns a tab-separated <dir>\t<source-path> tuple; resolve_store splits it in the parent shell. Caught by /land-and-deploy post-merge fresh-clone verification — the existing test grepped for the substring ".secrets-store file" which matched the broken truncated form. Tightened to assert the full file path appears in the parenthetical. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
09a7bdcc46
commit
1bb729f73b
4 changed files with 20 additions and 6 deletions
|
|
@ -5,6 +5,12 @@ All notable changes to this project will be documented in this file.
|
||||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
|
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
|
||||||
and this project adheres to a four-digit MAJOR.MINOR.PATCH.MICRO version scheme.
|
and this project adheres to a four-digit MAJOR.MINOR.PATCH.MICRO version scheme.
|
||||||
|
|
||||||
|
## [0.1.0.1] - 2026-05-09
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- `secrets which` now prints the full path of the `.secrets-store` file that won resolution. Before this fix, `_find_secrets_store_file` set `_LAST_FOUND_AT` inside a `$(...)` subshell, so the parent shell never saw it; the source line read `.secrets-store file ()` with empty parens. The function now returns a tab-separated `<dir>\t<source-file-path>` tuple that `resolve_store` splits in the parent shell. Caught by the `/land-and-deploy` post-merge fresh-clone check; the existing test was too lenient and matched the truncated form. Test tightened to assert the full path appears in the parenthetical.
|
||||||
|
|
||||||
## [0.1.0.0] - 2026-05-09
|
## [0.1.0.0] - 2026-05-09
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
@ -36,4 +42,5 @@ and this project adheres to a four-digit MAJOR.MINOR.PATCH.MICRO version scheme.
|
||||||
|
|
||||||
- 37 → 66 tests. New coverage: store resolution rules and precedence, walk-up boundaries, command-injection prevention, key-file re-derivation across stores, teammate-onboarding error path, monorepo workspace binding, F1–F5 adversarial regressions.
|
- 37 → 66 tests. New coverage: store resolution rules and precedence, walk-up boundaries, command-injection prevention, key-file re-derivation across stores, teammate-onboarding error path, monorepo workspace binding, F1–F5 adversarial regressions.
|
||||||
|
|
||||||
|
[0.1.0.1]: https://github.com/bmajewski/secrets/releases/tag/v0.1.0.1
|
||||||
[0.1.0.0]: https://github.com/bmajewski/secrets/releases/tag/v0.1.0.0
|
[0.1.0.0]: https://github.com/bmajewski/secrets/releases/tag/v0.1.0.0
|
||||||
|
|
|
||||||
2
VERSION
2
VERSION
|
|
@ -1 +1 @@
|
||||||
0.1.0.0
|
0.1.0.1
|
||||||
|
|
|
||||||
13
secrets
13
secrets
|
|
@ -159,7 +159,10 @@ _parse_secrets_store_file() {
|
||||||
# Walk up from cwd looking for .secrets-store. Bounded by $HOME — never
|
# Walk up from cwd looking for .secrets-store. Bounded by $HOME — never
|
||||||
# walks INTO or PAST $HOME. If cwd is outside $HOME entirely (e.g. /tmp),
|
# walks INTO or PAST $HOME. If cwd is outside $HOME entirely (e.g. /tmp),
|
||||||
# the walk does not run. Symlinks are resolved with `cd -P`.
|
# the walk does not run. Symlinks are resolved with `cd -P`.
|
||||||
# On success: prints expanded store dir, sets _LAST_FOUND_AT, returns 0.
|
# On success: prints "<expanded-store-dir>\t<source-file-path>" and returns 0.
|
||||||
|
# The caller (resolve_store) splits the tab-separated tuple. We can't set a
|
||||||
|
# parent-shell variable from here because we're typically called inside
|
||||||
|
# `$(...)` command substitution, which runs in a subshell.
|
||||||
_find_secrets_store_file() {
|
_find_secrets_store_file() {
|
||||||
local dir
|
local dir
|
||||||
dir=$(pwd -P 2>/dev/null) || dir="$PWD"
|
dir=$(pwd -P 2>/dev/null) || dir="$PWD"
|
||||||
|
|
@ -183,8 +186,7 @@ _find_secrets_store_file() {
|
||||||
if content=$(_parse_secrets_store_file "$dir/.secrets-store"); then
|
if content=$(_parse_secrets_store_file "$dir/.secrets-store"); then
|
||||||
local expanded
|
local expanded
|
||||||
expanded=$(_expand_store_path "$content")
|
expanded=$(_expand_store_path "$content")
|
||||||
_LAST_FOUND_AT="$dir/.secrets-store"
|
printf '%s\t%s\n' "$expanded" "$dir/.secrets-store"
|
||||||
printf '%s\n' "$expanded"
|
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
@ -204,7 +206,10 @@ resolve_store() {
|
||||||
resolved=$(_expand_store_path "$STORE_OVERRIDE")
|
resolved=$(_expand_store_path "$STORE_OVERRIDE")
|
||||||
source="--store flag"
|
source="--store flag"
|
||||||
_LAST_FOUND_AT=""
|
_LAST_FOUND_AT=""
|
||||||
elif resolved=$(_find_secrets_store_file); then
|
elif _find_result=$(_find_secrets_store_file); then
|
||||||
|
# _find_secrets_store_file returns "<dir>\t<source-file-path>"
|
||||||
|
resolved="${_find_result%%$'\t'*}"
|
||||||
|
_LAST_FOUND_AT="${_find_result#*$'\t'}"
|
||||||
source=".secrets-store file ($_LAST_FOUND_AT)"
|
source=".secrets-store file ($_LAST_FOUND_AT)"
|
||||||
elif [ -n "${_USER_SECRETS_DIR:-}" ]; then
|
elif [ -n "${_USER_SECRETS_DIR:-}" ]; then
|
||||||
resolved="$_USER_SECRETS_DIR"
|
resolved="$_USER_SECRETS_DIR"
|
||||||
|
|
|
||||||
|
|
@ -540,7 +540,9 @@ EOF
|
||||||
run "$SECRETS_BIN" which
|
run "$SECRETS_BIN" which
|
||||||
[ "$status" -eq 0 ]
|
[ "$status" -eq 0 ]
|
||||||
[[ "$output" == *"$HOME/.secrets-work"* ]]
|
[[ "$output" == *"$HOME/.secrets-work"* ]]
|
||||||
[[ "$output" == *".secrets-store file"* ]]
|
# Source line must include both the rule name AND the resolved file path,
|
||||||
|
# not the empty parens (".secrets-store file ()") that v0.1.0.0 shipped.
|
||||||
|
[[ "$output" == *".secrets-store file ("*"$WORK_DIR/myapp/.secrets-store)"* ]]
|
||||||
}
|
}
|
||||||
|
|
||||||
@test "--store flag overrides .secrets-store file and SECRETS_DIR env" {
|
@test "--store flag overrides .secrets-store file and SECRETS_DIR env" {
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue