feat: secrets recipients rm with lockout guards (EGB-283)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
4ba0234bd7
commit
cad5b66f77
2 changed files with 99 additions and 1 deletions
|
|
@ -181,3 +181,51 @@ make_second_identity() {
|
|||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"--name requires a value"* ]] || false
|
||||
}
|
||||
|
||||
@test "recipients rm removes a recipient and re-encrypts to the rest" {
|
||||
init_with_remote
|
||||
create_project_dir myproj
|
||||
run "$SECRETS_BIN" push
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name bob
|
||||
run "$SECRETS_BIN" recipients rm bob
|
||||
[ "$status" -eq 0 ]
|
||||
run "$SECRETS_BIN" recipients list
|
||||
[[ "$output" == *"recipients: 1"* ]] || false
|
||||
# Store key still reads its own blobs.
|
||||
run age -d -i "$SECRETS_DIR/key.txt" "$SECRETS_DIR/myproj/.env.age"
|
||||
[ "$status" -eq 0 ]
|
||||
}
|
||||
|
||||
@test "recipients rm refuses to remove the last recipient" {
|
||||
init_with_remote
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name bob # store = self + bob
|
||||
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
||||
run "$SECRETS_BIN" recipients rm bob # back to self only
|
||||
[ "$status" -eq 0 ]
|
||||
run "$SECRETS_BIN" recipients rm "$STORE_PUB" # would be the last
|
||||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"last recipient"* ]] || false
|
||||
}
|
||||
|
||||
@test "recipients rm of your own key requires --yes" {
|
||||
init_with_remote
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name bob
|
||||
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
||||
run "$SECRETS_BIN" recipients rm "$STORE_PUB"
|
||||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"your own key"* ]] || false
|
||||
run "$SECRETS_BIN" recipients rm "$STORE_PUB" --yes
|
||||
[ "$status" -eq 0 ]
|
||||
}
|
||||
|
||||
@test "recipients rm of a non-existent target errors" {
|
||||
init_with_remote
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name bob
|
||||
run "$SECRETS_BIN" recipients rm carol
|
||||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"No recipient matches"* ]] || false
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue