feat: verify asserts blob recipient-count matches recipients.txt (EGB-283)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
ae52b8c077
commit
e4cd524483
2 changed files with 70 additions and 0 deletions
|
|
@ -267,3 +267,26 @@ make_second_identity() {
|
|||
[ "$status" -eq 0 ]
|
||||
[[ "$output" == *"recipients: single-key"* ]] || false
|
||||
}
|
||||
|
||||
@test "verify --all passes on a healthy multi-recipient store" {
|
||||
init_with_remote
|
||||
create_project_dir myproj
|
||||
run "$SECRETS_BIN" push
|
||||
make_second_identity
|
||||
run "$SECRETS_BIN" recipients add "$BOB_PUB" --name bob # re-encrypts to 2
|
||||
run "$SECRETS_BIN" verify --all
|
||||
[ "$status" -eq 0 ]
|
||||
}
|
||||
|
||||
@test "verify flags a blob whose recipient count drifted" {
|
||||
init_with_remote
|
||||
create_project_dir myproj
|
||||
run "$SECRETS_BIN" push # single-key blob (1 stanza)
|
||||
make_second_identity
|
||||
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
||||
# Declare 2 recipients but do NOT re-encrypt — the on-disk blob still has 1.
|
||||
printf '%s\n%s\n' "$STORE_PUB" "$BOB_PUB" > "$SECRETS_DIR/recipients.txt"
|
||||
run "$SECRETS_BIN" verify --all
|
||||
[ "$status" -ne 0 ]
|
||||
[[ "$output" == *"recipient"* ]] || false
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue