#!/usr/bin/env bash # Shared setup/teardown for secrets bats tests. # Creates isolated temp directories for each test — no side effects. SECRETS_BIN="$(cd "$(dirname "${BATS_TEST_FILENAME}")/.." && pwd)/secrets" setup() { # Check age is available if ! command -v age >/dev/null 2>&1; then skip "age is not installed" fi # Create isolated temp environment export TEST_TMPDIR TEST_TMPDIR=$(mktemp -d) # Isolate HOME so .secrets-store walk-up cannot stray into the real # developer's home directory (or pick up files in / if HOME happens to # not be a real ancestor of /tmp). EGB-281 F9. export HOME="$TEST_TMPDIR" # Provide git author identity so `git commit` works with the fresh temp HOME # (no ~/.gitconfig is present in the isolated dir). GIT_* env vars override # any global config and survive the HOME redirect. export GIT_AUTHOR_NAME="Test User" export GIT_AUTHOR_EMAIL="test@example.com" export GIT_COMMITTER_NAME="Test User" export GIT_COMMITTER_EMAIL="test@example.com" # Secrets repo lives in temp export SECRETS_DIR="$TEST_TMPDIR/secrets-repo" # Working directory for simulating project dirs (kept under $HOME so # the .secrets-store walk-up logic, which is bounded by $HOME, can find # files placed in test fixtures). export WORK_DIR="$HOME/work" mkdir -p "$WORK_DIR" # Create a bare "remote" repo for push/pull testing export REMOTE_DIR="$TEST_TMPDIR/remote.git" git init --bare "$REMOTE_DIR" >/dev/null 2>&1 } teardown() { rm -rf "$TEST_TMPDIR" } # Helper: initialize secrets and add remote init_with_remote() { run "$SECRETS_BIN" init cd "$SECRETS_DIR" git remote add origin "$REMOTE_DIR" # Initial commit so push works git commit --allow-empty -m "init" >/dev/null 2>&1 git push -u origin main >/dev/null 2>&1 || git push -u origin master >/dev/null 2>&1 cd - } # Helper: create .env files in a temp project dir and cd into it create_project_dir() { local name="${1:-testproj}" local dir="$WORK_DIR/$name" mkdir -p "$dir" echo "SECRET_KEY=abc123" > "$dir/.env" echo "DB_HOST=staging.db.example.com" > "$dir/.env.staging" cd "$dir" } # Helper: create a project dir bound to a store via .secrets-store file create_bound_project_dir() { local name="$1" local store_value="$2" local dir="$WORK_DIR/$name" mkdir -p "$dir" echo "SECRET_KEY=abc123" > "$dir/.env" echo "$store_value" > "$dir/.secrets-store" cd "$dir" }