fix(secrets): preserve OP_CONFIG_DIR for 1Password
This commit is contained in:
@@ -38,7 +38,7 @@ _DEFAULT_TOKEN_ENV = "OP_SERVICE_ACCOUNT_TOKEN"
|
||||
# dynamically in _op_child_env().
|
||||
_OP_ENV_ALLOWLIST = (
|
||||
"PATH", "HOME", "USERPROFILE", "APPDATA", "LOCALAPPDATA", "SystemRoot",
|
||||
"TMPDIR", "TMP", "TEMP", "XDG_CONFIG_HOME", "XDG_RUNTIME_DIR",
|
||||
"TMPDIR", "TMP", "TEMP", "XDG_CONFIG_HOME", "XDG_RUNTIME_DIR", "OP_CONFIG_DIR",
|
||||
"OP_ACCOUNT", "OP_CONNECT_HOST", "OP_CONNECT_TOKEN",
|
||||
# Lets a user skip op's desktop-app integration probe (which can hang with
|
||||
# no timeout on a wedged desktop container) and go straight to token auth.
|
||||
|
||||
@@ -217,6 +217,17 @@ def test_find_op_pinned_path_not_on_path(tmp_path, monkeypatch):
|
||||
|
||||
|
||||
|
||||
def test_op_child_env_forwards_config_directory(monkeypatch):
|
||||
"""The op child must retain an explicit 1Password config location."""
|
||||
monkeypatch.setenv("OP_CONFIG_DIR", "/tmp/op-config")
|
||||
monkeypatch.setenv("UNRELATED_PROVIDER_TOKEN", "must-not-leak")
|
||||
|
||||
env = op._op_child_env("")
|
||||
|
||||
assert env["OP_CONFIG_DIR"] == "/tmp/op-config"
|
||||
assert "UNRELATED_PROVIDER_TOKEN" not in env
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# apply_onepassword_secrets
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
@@ -221,3 +221,13 @@ def test_onepassword_multi_url_item_binds_every_saved_web_origin():
|
||||
# helpers: dedupe keeps first occurrence; app-only items keep their single origin
|
||||
assert _all_origins(["https://a.com/x", "https://a.com/y"]) == ["https://a.com"]
|
||||
assert _web_origins(["androidapp://com.x"]) == ("androidapp://com.x",)
|
||||
|
||||
|
||||
def test_onepassword_backend_env_forwards_config_directory(monkeypatch):
|
||||
"""Vault reads use the same explicit 1Password CLI config location."""
|
||||
from agent.vault_backends.onepassword import OnePasswordLoginBackend
|
||||
|
||||
monkeypatch.setenv("OP_CONFIG_DIR", "/tmp/op-config")
|
||||
backend = OnePasswordLoginBackend({"enabled": True})
|
||||
|
||||
assert backend._env(None)["OP_CONFIG_DIR"] == "/tmp/op-config"
|
||||
|
||||
Reference in New Issue
Block a user