fix(thothctl): fail closed on partial secret loads

This commit is contained in:
2026-08-11 05:10:32 +02:00
parent 69cc47c13f
commit 783cc3bb34
7 changed files with 60 additions and 18 deletions
+17
View File
@@ -218,6 +218,23 @@ func TestRunWorkspaceRejectsDeclaredSecretInHumanChrome(t *testing.T) {
}
}
func TestRunWorkspacePartialSecretLoadEmitsNoOutput(t *testing.T) {
fixture := newCLIFixture(t, "")
firstSecret := filepath.Join(fixture.root, "first-secret")
missingSecret := filepath.Join(fixture.root, "missing-secret")
if err := os.WriteFile(firstSecret, []byte("workspace operation failed"), 0o600); err != nil {
t.Fatal(err)
}
fixture.setEnvContents(t, "FIRST_SECRET_FILE="+firstSecret+"\nSECOND_SECRET_FILE="+missingSecret+"\n")
var stdout, stderr bytes.Buffer
code := run(context.Background(), []string{"--installation", fixture.installationPath, "workspace", "inspect", "--workspace", "psd"}, &stdout, &stderr)
if code != 2 || stdout.Len() != 0 || stderr.Len() != 0 {
t.Fatalf("exit=%d stdout=%q stderr=%q, want exit 2 and no output", code, stdout.String(), stderr.String())
}
assertDockerNotInvoked(t, fixture)
}
func TestRunWorkspaceErrorPrefixNeverLeaksDeclaredSecret(t *testing.T) {
fixture := newCLIFixture(t, "UNLABELLED_SECRET_FILE=%s\n")
secretPath := filepath.Join(fixture.root, "secret")