fix(secrets): preserve OP_CONFIG_DIR for 1Password

This commit is contained in:
KoNit-K
2026-09-15 22:16:40 +08:00
committed by Teknium
parent 30b22b54ae
commit a457e91a50
3 changed files with 22 additions and 1 deletions

View File

@@ -38,7 +38,7 @@ _DEFAULT_TOKEN_ENV = "OP_SERVICE_ACCOUNT_TOKEN"
# dynamically in _op_child_env().
_OP_ENV_ALLOWLIST = (
"PATH", "HOME", "USERPROFILE", "APPDATA", "LOCALAPPDATA", "SystemRoot",
"TMPDIR", "TMP", "TEMP", "XDG_CONFIG_HOME", "XDG_RUNTIME_DIR",
"TMPDIR", "TMP", "TEMP", "XDG_CONFIG_HOME", "XDG_RUNTIME_DIR", "OP_CONFIG_DIR",
"OP_ACCOUNT", "OP_CONNECT_HOST", "OP_CONNECT_TOKEN",
# Lets a user skip op's desktop-app integration probe (which can hang with
# no timeout on a wedged desktop container) and go straight to token auth.

View File

@@ -217,6 +217,17 @@ def test_find_op_pinned_path_not_on_path(tmp_path, monkeypatch):
def test_op_child_env_forwards_config_directory(monkeypatch):
"""The op child must retain an explicit 1Password config location."""
monkeypatch.setenv("OP_CONFIG_DIR", "/tmp/op-config")
monkeypatch.setenv("UNRELATED_PROVIDER_TOKEN", "must-not-leak")
env = op._op_child_env("")
assert env["OP_CONFIG_DIR"] == "/tmp/op-config"
assert "UNRELATED_PROVIDER_TOKEN" not in env
# ---------------------------------------------------------------------------
# apply_onepassword_secrets
# ---------------------------------------------------------------------------

View File

@@ -221,3 +221,13 @@ def test_onepassword_multi_url_item_binds_every_saved_web_origin():
# helpers: dedupe keeps first occurrence; app-only items keep their single origin
assert _all_origins(["https://a.com/x", "https://a.com/y"]) == ["https://a.com"]
assert _web_origins(["androidapp://com.x"]) == ("androidapp://com.x",)
def test_onepassword_backend_env_forwards_config_directory(monkeypatch):
"""Vault reads use the same explicit 1Password CLI config location."""
from agent.vault_backends.onepassword import OnePasswordLoginBackend
monkeypatch.setenv("OP_CONFIG_DIR", "/tmp/op-config")
backend = OnePasswordLoginBackend({"enabled": True})
assert backend._env(None)["OP_CONFIG_DIR"] == "/tmp/op-config"