|
1 |
| -select |
2 |
| - 1 |
3 |
| -from |
4 |
| - vault.create_secret('my_s3kre3t'); |
5 |
| - ?column? |
6 |
| ----------- |
7 |
| - 1 |
8 |
| -(1 row) |
9 |
| - |
10 |
| -select |
11 |
| - 1 |
12 |
| -from |
13 |
| - vault.create_secret( |
| 1 | +SET ROLE service_role; |
| 2 | +SELECT EXISTS ( |
| 3 | + SELECT 1 FROM vault.create_secret('my_s3kre3t') |
| 4 | +) AS can_create_secret; |
| 5 | + can_create_secret |
| 6 | +------------------- |
| 7 | + t |
| 8 | +(1 row) |
| 9 | + |
| 10 | +SELECT EXISTS ( |
| 11 | + SELECT 1 FROM vault.create_secret( |
14 | 12 | 'another_s3kre3t',
|
15 | 13 | 'unique_name',
|
16 | 14 | 'This is the description'
|
17 |
| - ); |
18 |
| - ?column? |
19 |
| ----------- |
20 |
| - 1 |
21 |
| -(1 row) |
22 |
| - |
23 |
| -insert into vault.secrets (secret) |
24 |
| -values |
25 |
| - ('s3kre3t_k3y'); |
26 |
| -select |
27 |
| - name, |
28 |
| - description |
29 |
| -from |
30 |
| - vault.decrypted_secrets |
31 |
| -order by |
32 |
| - created_at desc |
33 |
| -limit |
34 |
| - 3; |
35 |
| - name | description |
36 |
| --------------+------------------------- |
37 |
| - | |
38 |
| - unique_name | This is the description |
39 |
| - | |
40 |
| -(3 rows) |
41 |
| - |
42 |
| - |
| 15 | + ) |
| 16 | +) AS can_create_secret_with_params; |
| 17 | + can_create_secret_with_params |
| 18 | +------------------------------- |
| 19 | + t |
| 20 | +(1 row) |
| 21 | + |
| 22 | +SELECT EXISTS ( |
| 23 | + SELECT 1 FROM vault.secrets LIMIT 1 |
| 24 | +) AS can_select_from_secrets; |
| 25 | + can_select_from_secrets |
| 26 | +------------------------- |
| 27 | + t |
| 28 | +(1 row) |
| 29 | + |
| 30 | +INSERT INTO vault.secrets (secret) |
| 31 | +VALUES ('s3kre3t_k3y') |
| 32 | +RETURNING EXISTS ( |
| 33 | + SELECT 1 |
| 34 | +) AS can_insert_into_secrets; |
| 35 | +ERROR: permission denied for function _crypto_aead_det_noncegen |
| 36 | +SELECT EXISTS ( |
| 37 | + SELECT name, description FROM vault.decrypted_secrets LIMIT 1 |
| 38 | +) AS can_select_from_decrypted_secrets; |
| 39 | + can_select_from_decrypted_secrets |
| 40 | +----------------------------------- |
| 41 | + t |
| 42 | +(1 row) |
| 43 | + |
| 44 | +INSERT INTO vault.secrets (secret) VALUES ('temp_secret_to_delete'); |
| 45 | +ERROR: permission denied for function _crypto_aead_det_noncegen |
| 46 | +WITH deleted AS ( |
| 47 | + DELETE FROM vault.secrets |
| 48 | + WHERE secret = 'temp_secret_to_delete' |
| 49 | + RETURNING 1 |
| 50 | +) |
| 51 | +SELECT EXISTS (SELECT 1 FROM deleted) AS can_delete_from_secrets; |
| 52 | + can_delete_from_secrets |
| 53 | +------------------------- |
| 54 | + f |
| 55 | +(1 row) |
| 56 | + |
| 57 | +INSERT INTO vault.secrets (secret) VALUES ('temp_secret_to_delete_from_decrypted'); |
| 58 | +ERROR: permission denied for function _crypto_aead_det_noncegen |
| 59 | +WITH deleted AS ( |
| 60 | + DELETE FROM vault.decrypted_secrets |
| 61 | + WHERE secret = 'temp_secret_to_delete_from_decrypted' |
| 62 | + RETURNING 1 |
| 63 | +) |
| 64 | +SELECT EXISTS (SELECT 1 FROM deleted) AS can_delete_from_decrypted_secrets; |
| 65 | + can_delete_from_decrypted_secrets |
| 66 | +----------------------------------- |
| 67 | + f |
| 68 | +(1 row) |
| 69 | + |
| 70 | +WITH secret_id AS ( |
| 71 | + SELECT id FROM vault.secrets ORDER BY created_at DESC LIMIT 1 |
| 72 | +) |
| 73 | +SELECT EXISTS ( |
| 74 | + SELECT 1 FROM vault.update_secret( |
| 75 | + (SELECT id FROM secret_id), |
| 76 | + 'updated_secret' |
| 77 | + ) |
| 78 | +) AS can_update_secret; |
| 79 | + can_update_secret |
| 80 | +------------------- |
| 81 | + t |
| 82 | +(1 row) |
| 83 | + |
| 84 | +WITH encrypted_value AS ( |
| 85 | + SELECT secret FROM vault.secrets ORDER BY created_at DESC LIMIT 1 |
| 86 | +) |
| 87 | +SELECT EXISTS ( |
| 88 | + SELECT 1 FROM vault._crypto_aead_det_decrypt( |
| 89 | + decode((SELECT secret FROM encrypted_value), 'base64'), |
| 90 | + convert_to((SELECT id FROM vault.secrets ORDER BY created_at DESC LIMIT 1)::text, 'utf8'), |
| 91 | + 0, |
| 92 | + 'pgsodium'::bytea, |
| 93 | + (SELECT nonce FROM vault.secrets ORDER BY created_at DESC LIMIT 1) |
| 94 | + ) |
| 95 | +) AS can_decrypt; |
| 96 | + can_decrypt |
| 97 | +------------- |
| 98 | + t |
| 99 | +(1 row) |
| 100 | + |
| 101 | +RESET ROLE; |
0 commit comments