feat: secrets recipients add (EGB-283)
Add `secrets recipients add <age1...> [--name <label>]`: validates the age key and optional display name, bootstraps recipients.txt with the local pubkey on a legacy store (keeping the operator as a recipient), rejects duplicates, appends the new key (with optional name comment), then re-encrypts the entire store to the updated recipient list. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
a10f390519
commit
c262661030
2 changed files with 89 additions and 1 deletions
|
|
@ -123,3 +123,45 @@ make_second_identity() {
|
|||
run age -d -i "$SECRETS_DIR/key.txt" "$SECRETS_DIR/myproj/.env.age"
|
||||
[ "$status" -eq 0 ]
|
||||
}
|
||||
|
||||
@test "recipients add bootstraps a legacy store and re-encrypts" {
|
||||
init_with_remote
|
||||
create_project_dir myproj
|
||||
run "$SECRETS_BIN" push
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name bob
|
||||
[ "$status" -eq 0 ]
|
||||
[ -e "$SECRETS_DIR/recipients.txt" ]
|
||||
# recipients.txt now has self + bob (2 keys).
|
||||
run "$SECRETS_BIN" recipients list
|
||||
[[ "$output" == *"recipients: 2"* ]] || false
|
||||
[[ "$output" == *"bob"* ]] || false
|
||||
# Existing blob re-encrypted: bob can read it.
|
||||
run age -d -i "$TEST_TMPDIR/bob.txt" "$SECRETS_DIR/myproj/.env.age"
|
||||
[ "$status" -eq 0 ]
|
||||
}
|
||||
|
||||
@test "recipients add rejects a non-age key" {
|
||||
init_with_remote
|
||||
run "$SECRETS_BIN" recipients add "ssh-ed25519 AAAAfoo"
|
||||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"valid age recipient"* ]] || false
|
||||
}
|
||||
|
||||
@test "recipients add rejects a duplicate" {
|
||||
init_with_remote
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name bob
|
||||
[ "$status" -eq 0 ]
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB"
|
||||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"already present"* ]] || false
|
||||
}
|
||||
|
||||
@test "recipients add rejects an unsafe --name" {
|
||||
init_with_remote
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name 'bob; rm -rf ~'
|
||||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"Invalid --name"* ]] || false
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue