Recoverable means sealed to the current operator key; recovery names the provider
From review: the export counted any operator-sealed row as recoverable, so a secret sealed to a replaced key was reported as openable with the current one; replacing the key counted orphans in one table of two; and a pair credential held from two providers was recovered as whichever row came first. The export now lists what the current key opens, what an earlier key opens, and what has no copy; `secret recover` takes --provider and refuses ambiguity; files that must not exist are created exclusively; one constructor builds the export for the operator's file and the vault's disk alike.
This commit is contained in:
@@ -763,10 +763,14 @@ type Kept struct {
|
||||
// KeptExport is what a person keeps beside the operator key, and what a vault keeps on its disk:
|
||||
// every operator-sealed copy, and the honest list of what has none.
|
||||
type KeptExport struct {
|
||||
Export int `json:"export"`
|
||||
OperatorKey string `json:"operator-key"`
|
||||
Fingerprint string `json:"fingerprint"`
|
||||
Export int `json:"export"`
|
||||
OperatorKey string `json:"operator-key"`
|
||||
Fingerprint string `json:"fingerprint"`
|
||||
// Kept is sealed to OperatorKey. EarlierKey is sealed to a key the mesh has since replaced —
|
||||
// recoverable with that key, if the person still has it, and with nothing else. Unrecoverable
|
||||
// has no operator copy at all.
|
||||
Kept []Kept `json:"kept"`
|
||||
EarlierKey []Kept `json:"sealed-to-earlier-key,omitempty"`
|
||||
Unrecoverable []Kept `json:"unrecoverable,omitempty"`
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user