From 3d8510a26ebae103a3994dd9fe5222a5efd89608 Mon Sep 17 00:00:00 2001 From: Codex Date: Wed, 30 Sep 2026 23:26:45 -0500 Subject: [PATCH] cli: Announce recovery secret switch Entering a complete valid secret during interactive share recovery intentionally supersedes the partial share set. Previously that mode switch happened silently, which made correct behavior look like discarded input. Emit one explicit notice only when shares were already accepted, and pin the behavior in the existing interactive recovery regression. Refs #38 --- src/codex32/_cli_input.py | 2 ++ tests/test_cli.py | 1 + 2 files changed, 3 insertions(+) diff --git a/src/codex32/_cli_input.py b/src/codex32/_cli_input.py index 53ba5b9..eb13b4f 100644 --- a/src/codex32/_cli_input.py +++ b/src/codex32/_cli_input.py @@ -805,6 +805,8 @@ def allowed(candidate: CorrectionCandidate) -> bool: if one: return [artifact] if isinstance(artifact, Secret) and not basis: + if accepted: + _stderr("Complete secret supplied; using it instead of the accepted shares.") return [artifact] if not accepted: required = artifact.header.threshold diff --git a/tests/test_cli.py b/tests/test_cli.py index 2978174..b1ba660 100644 --- a/tests/test_cli.py +++ b/tests/test_cli.py @@ -1094,6 +1094,7 @@ def answer(prompt: str) -> str: assert "Rejected:" not in captured.err assert "Share 1 of 3 accepted." in captured.err assert "Share 2 of 3 accepted." in captured.err + assert "Complete secret supplied; using it instead of the accepted shares." in captured.err first_prompt = ( "Enter a codex32 string:\n> " if command[0] == "secret" else "Enter a codex32 string:\n> MS1" )