78 lines
2.6 KiB
Bash
78 lines
2.6 KiB
Bash
#!/usr/bin/env bats
|
|
load test_helper
|
|
|
|
# A throwaway second identity for "another teammate".
|
|
make_second_identity() {
|
|
age-keygen -o "$TEST_TMPDIR/bob.txt" 2>/dev/null
|
|
BOB_PUB=$(age-keygen -y "$TEST_TMPDIR/bob.txt")
|
|
}
|
|
|
|
@test "push without recipients.txt stays single-key (legacy behavior)" {
|
|
init_with_remote
|
|
create_project_dir myproj
|
|
run "$SECRETS_BIN" push
|
|
[ "$status" -eq 0 ]
|
|
# No recipients.txt was created by push.
|
|
[ ! -e "$SECRETS_DIR/recipients.txt" ]
|
|
# Blob decrypts with the store's own key.
|
|
run age -d -i "$SECRETS_DIR/key.txt" "$SECRETS_DIR/myproj/.env.age"
|
|
[ "$status" -eq 0 ]
|
|
}
|
|
|
|
@test "push with a hand-written recipients.txt encrypts to every listed key" {
|
|
init_with_remote
|
|
make_second_identity
|
|
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
|
printf '# self\n%s\n# bob\n%s\n' "$STORE_PUB" "$BOB_PUB" > "$SECRETS_DIR/recipients.txt"
|
|
create_project_dir myproj
|
|
run "$SECRETS_BIN" push
|
|
[ "$status" -eq 0 ]
|
|
# Bob (a recipient) can decrypt the pushed blob with HIS key.
|
|
run age -d -i "$TEST_TMPDIR/bob.txt" "$SECRETS_DIR/myproj/.env.age"
|
|
[ "$status" -eq 0 ]
|
|
# And the store key still can too.
|
|
run age -d -i "$SECRETS_DIR/key.txt" "$SECRETS_DIR/myproj/.env.age"
|
|
[ "$status" -eq 0 ]
|
|
}
|
|
|
|
@test "push refuses a recipients.txt with an invalid key" {
|
|
init_with_remote
|
|
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
|
printf '%s\nnot-an-age-key\n' "$STORE_PUB" > "$SECRETS_DIR/recipients.txt"
|
|
create_project_dir myproj
|
|
run "$SECRETS_BIN" push
|
|
[ "$status" -ne 0 ]
|
|
[[ "$output" == *"Invalid recipient"* ]] || false
|
|
}
|
|
|
|
@test "push refuses a symlinked recipients.txt" {
|
|
init_with_remote
|
|
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
|
printf '%s\n' "$STORE_PUB" > "$TEST_TMPDIR/elsewhere.txt"
|
|
ln -s "$TEST_TMPDIR/elsewhere.txt" "$SECRETS_DIR/recipients.txt"
|
|
create_project_dir myproj
|
|
run "$SECRETS_BIN" push
|
|
[ "$status" -ne 0 ]
|
|
[[ "$output" == *"symlink"* ]] || false
|
|
}
|
|
|
|
@test "recipients list on a legacy store shows the single derived key" {
|
|
init_with_remote
|
|
run "$SECRETS_BIN" recipients list
|
|
[ "$status" -eq 0 ]
|
|
[[ "$output" == *"single-key"* ]] || false
|
|
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
|
[[ "$output" == *"$STORE_PUB"* ]] || false
|
|
}
|
|
|
|
@test "recipients list shows names and keys from recipients.txt" {
|
|
init_with_remote
|
|
make_second_identity
|
|
STORE_PUB=$(age-keygen -y "$SECRETS_DIR/key.txt")
|
|
printf '# alice\n%s\n# bob\n%s\n' "$STORE_PUB" "$BOB_PUB" > "$SECRETS_DIR/recipients.txt"
|
|
run "$SECRETS_BIN" recipients list
|
|
[ "$status" -eq 0 ]
|
|
[[ "$output" == *"recipients: 2"* ]] || false
|
|
[[ "$output" == *"alice"* ]] || false
|
|
[[ "$output" == *"bob"* ]] || false
|
|
}
|