Skip to content

Clean up secrets removed from the config (unload, load prune, status) #33

Description

@iamralch

Problem

Removing a secret from config.yml leaves it behind, and keysafe gives no easy way to clean it up.

Steps to reproduce:

  1. A profile has OLD_TOKEN (kind env), and it is loaded in a shell with keysafe load -p personal.
  2. Delete the OLD_TOKEN entry from config.yml.
  3. keysafe unload -p personal unsets every configured secret but leaves OLD_TOKEN exported in the shell.
  4. keysafe unload -p personal OLD_TOKEN fails with "unknown secret", because names are resolved against the current config.
  5. keysafe load -p personal rewrites <profile>.metadata from the current config (Cache::save), so keysafe loses its record that OLD_TOKEN was ever loaded.
  6. The cached value stays in the keychain under keysafe.personal until the user happens to run keysafe profile clear personal.

The same happens to file secrets, whose files stay in the runtime dir, and to ssh keys, which stay in ssh-agent until they expire.

profile clear already handles this for the keychain, because it enumerates the service's accounts (#31). The other commands don't.

Where

  • src/app/exec.rs: UnloadCommand::execute builds its list from profile.secrets (config) only.
  • src/vault/cache.rs: Cache::save overwrites the metadata with the current config, so names that were removed are dropped.
  • No command prunes keychain items under keysafe.<profile> that the config no longer names.

Proposal

  1. unload uses what was recorded, not just the config. Unset the union of configured names and names recorded in the profile metadata. Allow unload <NAME> for names that are recorded but not configured, and delete their files and agent keys too.
  2. load prunes stale secrets. After a successful full-profile load, delete keychain items under keysafe.<profile> whose names aren't in the config, and print e.g. Pruned 2 stale secrets from personal. Also unset previously recorded names that are no longer configured, so open shells don't keep stale variables. Do this before save() replaces the metadata.
  3. status / doctor report orphans. List keychain items, metadata entries and agent keys that the config no longer names, and suggest keysafe unload or keysafe profile clear.

Related: config validation message

A half-deleted entry (a - kind: env line left without name/path) produces:

invalid config file …/config.yml: secret at profile 'personal' index 3 missing 'name' field

It would be easier to fix with the line number and the fields that are present, e.g.
secret #4 in profile 'personal' (line 17, kind: env) is missing 'name' and 'path'.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions