@@ -521,8 +521,9 @@ func TestMasterKey_Identities_Passphrase(t *testing.T) {
521521 t .Setenv (SopsAgeKeyEnv , mockEncryptedIdentity )
522522 //blocks calling gpg-agent
523523 os .Unsetenv ("XDG_RUNTIME_DIR" )
524- t . Setenv ( SopsAgePasswordEnv , mockIdentityPassphrase )
524+ testOnlyAgePassword = mockIdentityPassphrase
525525 got , err := key .Decrypt ()
526+ testOnlyAgePassword = ""
526527
527528 assert .NoError (t , err )
528529 assert .EqualValues (t , mockEncryptedKeyPlain , got )
@@ -540,9 +541,11 @@ func TestMasterKey_Identities_Passphrase(t *testing.T) {
540541 t .Setenv (SopsAgeKeyFileEnv , keyPath )
541542 //blocks calling gpg-agent
542543 os .Unsetenv ("XDG_RUNTIME_DIR" )
543- t . Setenv ( SopsAgePasswordEnv , mockIdentityPassphrase )
544+ testOnlyAgePassword = mockIdentityPassphrase
544545
545546 got , err := key .Decrypt ()
547+ testOnlyAgePassword = ""
548+
546549 assert .NoError (t , err )
547550 assert .EqualValues (t , mockEncryptedKeyPlain , got )
548551 })
@@ -552,9 +555,11 @@ func TestMasterKey_Identities_Passphrase(t *testing.T) {
552555 t .Setenv (SopsAgeKeyEnv , mockEncryptedIdentity )
553556 //blocks calling gpg-agent
554557 os .Unsetenv ("XDG_RUNTIME_DIR" )
555- t . Setenv ( SopsAgePasswordEnv , mockIdentityPassphrase )
558+ testOnlyAgePassword = mockIdentityPassphrase
556559
557560 got , err := key .Decrypt ()
561+ testOnlyAgePassword = ""
562+
558563 assert .Error (t , err )
559564 assert .ErrorContains (t , err , "failed to create reader for decrypting sops data key with age" )
560565 assert .Nil (t , got )
0 commit comments