Address review: clarify version comment and swap test order

This commit is contained in:
mvdbeek
2026-04-21 15:18:50 +02:00
parent 098e5bf4e3
commit 16fb151cbb
2 changed files with 4 additions and 4 deletions
+1 -1
View File
@@ -157,7 +157,7 @@ class HashicorpVault(Vault):
return None
def _read_legacy_and_migrate(self, key: str) -> Optional[str]:
# Galaxy < 26.x emitted a leading slash in Vault paths, which hvac's
# Galaxy <= 26.0 emitted a leading slash in Vault paths, which hvac's
# format_url turned into a double-slash KV v2 key. Vault 1.x accepted
# it silently; Vault 2.0 rejects it. Fall back to reading the legacy
# form and rewrite under the canonical key so the secret survives the
+3 -3
View File
@@ -145,14 +145,14 @@ def test_vault_key_prefix_wrapper_emits_canonical_path(prefix):
inner.client.secrets.kv.read_secret_version.return_value = {"data": {"data": {"value": "v"}}}
vault = VaultKeyValidationWrapper(VaultKeyPrefixWrapper(inner, prefix=prefix))
assert vault.read_secret("user/1/preferences/editor") == "v"
inner.client.secrets.kv.read_secret_version.assert_called_once_with(path="galaxy/user/1/preferences/editor")
vault.write_secret("user/1/preferences/editor", "vscode")
inner.client.secrets.kv.v2.create_or_update_secret.assert_called_once_with(
path="galaxy/user/1/preferences/editor", secret={"value": "vscode"}
)
assert vault.read_secret("user/1/preferences/editor") == "v"
inner.client.secrets.kv.read_secret_version.assert_called_once_with(path="galaxy/user/1/preferences/editor")
@pytest.mark.parametrize("prefix", ["", "/", "gal//axy", "gal /axy", "gal/ axy"])
def test_vault_key_prefix_wrapper_rejects_invalid_prefix(prefix):