Skip to content

[Keyvault] az keyvault secret download : Add overwrite flag#31650

Closed
a0x1ab wants to merge 0 commit intoAzure:devfrom
a0x1ab:dev
Closed

[Keyvault] az keyvault secret download : Add overwrite flag#31650
a0x1ab wants to merge 0 commit intoAzure:devfrom
a0x1ab:dev

Conversation

@a0x1ab
Copy link
Copy Markdown
Member

@a0x1ab a0x1ab commented Jun 13, 2025

Related command
keyvault

Description

  • az keyvault secret download command previously failed when provided with an existing file for the file path parameter.
  • Feature was requested to allow users to provide an existing file along with the overwrite flag to allow the secret downloaded to be overwritten onto the selected file path.
  • This feature allows users to provide an additional flag to the az keyvault secret download command to overwrite the existing file with the downloaded secret.
  • Cassette for re-recorded for future tests

Testing Guide

  • az keyvault secret download --vault-name {kv} -n download-{enc} --file "{dest_path}" --overwrite : overwrite existing path file with the contents of the downloaded secret

This checklist is used to make sure that common guidelines for a pull request are followed.

@a0x1ab a0x1ab self-assigned this Jun 13, 2025
Copilot AI review requested due to automatic review settings June 13, 2025 02:52
@a0x1ab a0x1ab added the KeyVault az keyvault label Jun 13, 2025
@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd bot commented Jun 13, 2025

️✔️AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.9
️✔️acs
️✔️latest
️✔️3.12
️✔️3.9
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.9
️✔️ams
️✔️latest
️✔️3.12
️✔️3.9
️✔️apim
️✔️latest
️✔️3.12
️✔️3.9
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.9
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.9
️✔️aro
️✔️latest
️✔️3.12
️✔️3.9
️✔️backup
️✔️latest
️✔️3.12
️✔️3.9
️✔️batch
️✔️latest
️✔️3.12
️✔️3.9
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.9
️✔️billing
️✔️latest
️✔️3.12
️✔️3.9
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.9
️✔️cdn
️✔️latest
️✔️3.12
️✔️3.9
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.9
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.9
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.9
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.9
️✔️config
️✔️latest
️✔️3.12
️✔️3.9
️✔️configure
️✔️latest
️✔️3.12
️✔️3.9
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.9
️✔️container
️✔️latest
️✔️3.12
️✔️3.9
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.9
️✔️core
️✔️latest
️✔️3.12
️✔️3.9
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.9
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.9
️✔️dls
️✔️latest
️✔️3.12
️✔️3.9
️✔️dms
️✔️latest
️✔️3.12
️✔️3.9
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.9
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.9
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.9
️✔️find
️✔️latest
️✔️3.12
️✔️3.9
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.9
️✔️identity
️✔️latest
️✔️3.12
️✔️3.9
️✔️iot
️✔️latest
️✔️3.12
️✔️3.9
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.9
️✔️lab
️✔️latest
️✔️3.12
️✔️3.9
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.9
️✔️maps
️✔️latest
️✔️3.12
️✔️3.9
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.9
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.9
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.9
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.9
️✔️network
️✔️latest
️✔️3.12
️✔️3.9
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.9
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.9
️✔️profile
️✔️latest
️✔️3.12
️✔️3.9
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.9
️✔️redis
️✔️latest
️✔️3.12
️✔️3.9
️✔️relay
️✔️latest
️✔️3.12
️✔️3.9
️✔️resource
️✔️latest
️✔️3.12
️✔️3.9
️✔️role
️✔️latest
️✔️3.12
️✔️3.9
️✔️search
️✔️latest
️✔️3.12
️✔️3.9
️✔️security
️✔️latest
️✔️3.12
️✔️3.9
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.9
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.9
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.9
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.9
️✔️sql
️✔️latest
️✔️3.12
️✔️3.9
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.9
️✔️storage
️✔️latest
️✔️3.12
️✔️3.9
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.9
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.9
️✔️util
️✔️latest
️✔️3.12
️✔️3.9
️✔️vm
️✔️latest
️✔️3.12
️✔️3.9

@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd bot commented Jun 13, 2025

⚠️AzureCLI-BreakingChangeTest
⚠️keyvault
rule cmd_name rule_message suggest_message
⚠️ 1006 - ParaAdd keyvault secret download cmd keyvault secret download added parameter overwrite

@yonzhan
Copy link
Copy Markdown
Collaborator

yonzhan commented Jun 13, 2025

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions
Copy link
Copy Markdown

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds an overwrite flag to the "az keyvault secret download" command to allow overwriting existing files when downloading secrets.

  • Modified tests to verify overwrite functionality.
  • Updated the secret download helper in custom.py to support the new overwrite flag.
  • Enhanced parameter definitions in _params.py to include the overwrite flag.

Reviewed Changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
tests/latest/test_keyvault_commands.py Updated test functions to pass dest_path and validate overwrite behavior.
custom.py Modified download_secret to include and check the overwrite flag.
_params.py Added the overwrite flag argument definition.
Comments suppressed due to low confidence (1)

src/azure-cli/azure/cli/command_modules/keyvault/custom.py:1465

  • [nitpick] Consider updating the associated error message to mention that users can use the '--overwrite' flag to overwrite an existing file, which would provide clearer guidance on how to resolve the issue.
if not overwrite and (os.path.isfile(file_path) or os.path.isdir(file_path)):

dest_path = os.path.join(TEST_DIR, 'recover-{}'.format(encoding))
_test_set_and_download(encoding, dest_path)
_test_download_with_overwrite(encoding, dest_path)
if os.path.exists(dest_path):
Copy link

Copilot AI Jun 13, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] Consider using a try-finally block or the test framework's cleanup features to ensure that the dest_path file is removed even if an assertion fails, thereby improving test reliability.

Copilot uses AI. Check for mistakes.
@a0x1ab
Copy link
Copy Markdown
Member Author

a0x1ab commented Jun 13, 2025

@microsoft-github-policy-service agree company="Microsoft"

help="Encoding of the secret. By default, will look for the 'file-encoding' tag on the secret. "
"Otherwise will assume 'utf-8'.", default=None)
c.argument('overwrite', arg_type=get_three_state_flag(), options_list=['--overwrite'], help="Overwrite the file if it exists.",
default=False)
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since download_secret has overwrite=False, we don't need to set default value here.

This line exceeds 120 characters; we only exceed the limit if there’s a valid reason.


# region KeyVault Secret
def download_secret(client, file_path, name=None, encoding=None, version=''): # pylint: disable=unused-argument
def download_secret(client, file_path, name=None, encoding=None, version='', overwrite: bool = False): # pylint: disable=unused-argument
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our project does not have type hinting.

""" Download a secret from a KeyVault. """
if os.path.isfile(file_path) or os.path.isdir(file_path):
if not overwrite and (os.path.isfile(file_path) or os.path.isdir(file_path)):
raise CLIError("File or directory named '{}' already exists.".format(file_path))
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can improve the error message by adding an introduction to overwrite.

@bebound
Copy link
Copy Markdown
Contributor

bebound commented Jun 13, 2025

For the PR title, it usually looks like this: [module] [breaking change?] [fix #xxx?] [affect command?] brief introduction
You can find more examples in https://github.com/Azure/azure-cli/blob/dev/src/azure-cli/HISTORY.rst?plain=1

@a0x1ab a0x1ab changed the title [Keyvault] Add overwrite flag to az keyvault secret download command [Keyvault] az keyvault secret download : Add overwrite flag Jun 16, 2025
@a0x1ab a0x1ab closed this Jun 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Auto-Assign Auto assign by bot KeyVault az keyvault

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants