From 0aab056731f2cf91b0696902d7d4f943945f5098 Mon Sep 17 00:00:00 2001 From: Codex Date: Wed, 30 Sep 2026 23:26:45 -0500 Subject: [PATCH] cli: Announce recovery secret switch Entering a complete valid secret during interactive share recovery intentionally supersedes the partial share set. Previously that mode switch happened silently, which made correct behavior look like discarded input. Emit one explicit notice only when shares were already accepted, and pin the behavior in the existing interactive recovery regression. Refs #38 --- src/codex32/_cli_input.py | 2 ++ tests/test_cli.py | 1 + 2 files changed, 3 insertions(+) diff --git a/src/codex32/_cli_input.py b/src/codex32/_cli_input.py index 53ba5b9..eb13b4f 100644 --- a/src/codex32/_cli_input.py +++ b/src/codex32/_cli_input.py @@ -805,6 +805,8 @@ def allowed(candidate: CorrectionCandidate) -> bool: if one: return [artifact] if isinstance(artifact, Secret) and not basis: + if accepted: + _stderr("Complete secret supplied; using it instead of the accepted shares.") return [artifact] if not accepted: required = artifact.header.threshold diff --git a/tests/test_cli.py b/tests/test_cli.py index 5df5f97..bf8477d 100644 --- a/tests/test_cli.py +++ b/tests/test_cli.py @@ -1155,6 +1155,7 @@ def answer(prompt: str) -> str: assert "Rejected:" not in captured.err assert "Share 1 of 3 accepted." in captured.err assert "Share 2 of 3 accepted." in captured.err + assert "Complete secret supplied; using it instead of the accepted shares." in captured.err first_prompt = ( "Enter a codex32 string:\n> " if command[0] == "secret" else "Enter a codex32 string:\n> MS1" )