Skip to content

fix: Tighten macOS keychain adapter - #142

Closed
lox wants to merge 3 commits into
99designs:masterfrom
lox:lox/spring-clean
Closed

lox wants to merge 3 commits into
99designs:masterfrom
lox:lox/spring-clean

Conversation

@lox

@lox lox commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

The macOS keychain adapter has a couple of drift points that make custom keychains less reliable: KeychainSynchronizable is exposed in Config but was not copied into the adapter, and metadata lookups did not use the configured keychain search list even though reads, writes, deletes, and key listing did.

This makes custom-keychain callers more predictable. For example, an item written through Open(Config{KeychainName: ...}) can now have its metadata read from the same keychain, and synchronizable keychain configuration reaches the item setup path.

The implementation centralizes the repeated generic-password item and query setup in the macOS adapter, keeps existing legacy keychain behavior intact, and tightens missing-key handling so only known missing item or keychain Security errors map to ErrKeyNotFound. The macOS tests now go through Open(Config) for the config and metadata regressions and clean up temporary keychains reliably.

@lox

lox commented Jun 13, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #143. I opened this from the broader spring-clean branch by mistake; #143 contains only the scoped macOS keychain cleanup.

@lox lox closed this Jun 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant