Skip to content

fix(secrets): warn when the vault beside config.toml disagrees with the home vault - #160

Merged
chinkan merged 1 commit into
mainfrom
fix/vault-import-conflict-warn
Oct 6, 2026
Merged

chinkan merged 1 commit into
mainfrom
fix/vault-import-conflict-warn

Conversation

@chinkan

@chinkan chinkan commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Follow-up to #157 (issue #156).

Problem

import_config_dir_vault copies secrets from <config_dir>/secrets/vault into the home vault, and names already in the home vault win. When the same name holds a different value in both vaults, the old value was ignored silently, so a user who re-ran the wizard in another folder had no hint why a secret they just entered was not used.

Change

  • import_config_dir_vault now returns (copied, conflicts). conflicts is the sorted list of names present in both vaults with different values. Values are never returned or logged.
  • main.rs logs one warn per name: Secret `<name>` differs between vaults: using the home vault value, ignoring the vault beside config.toml.
  • Behaviour is unchanged: the home vault still wins, nothing is overwritten, the old vault is kept.

Tests

  • config_dir_vault_secrets_are_copied_without_overwriting now asserts the differing name is reported on the first and second run, and that a name with the same value in both vaults is not reported.
  • No-op cases assert (0, []).
  • cargo fmt --check, cargo clippy --locked --all-targets -- -D warnings, cargo test --locked: 921 passed.

…he home vault

import_config_dir_vault now also returns the names present in both vaults
with different values. Boot logs one warn per name (never the value) saying
the home vault value is used. Behaviour is unchanged.

chinkan commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

TL ACCEPT at 96fcb49 (comment — same-account Approve blocked).

Returns (copied, conflicts) with sorted key names only; main warns names, home still wins, behaviour unchanged. Tests cover conflict on first/second run and no-op (0, []). Merge after Product GO + QA GO + CI (Analyze (rust) green; AI findings 402 non-block). No tag.

Note: PR base is 71d349f; merge onto current main 655e6b6 is fine (no conflict expected with #158 script-only).

@chinkan
chinkan merged commit 6b2cf0d into main Oct 6, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant