package envelope_test import ( "context" "os" "path/filepath" "testing" "atlas9.dev/c/core/assert" "atlas9.dev/c/core/envelope" ) func TestKeyFile_RoundTrip(t *testing.T) { ctx := context.Background() path := filepath.Join(t.TempDir(), "kek") // 32-byte key, hex-encoded assert.Ok(t, os.WriteFile(path, []byte("0102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f20"), 0600)) w, err := envelope.LoadKeyFile(path) assert.Ok(t, err) wrapped, err := w.Wrap(ctx, []byte("0123456789abcdef0123456789abcdef")) assert.Ok(t, err) got, err := w.Unwrap(ctx, wrapped) assert.Ok(t, err) assert.Eq(t, string(got), "0123456789abcdef0123456789abcdef") } func TestKeyFile_LoadRejectsWrongLength(t *testing.T) { path := filepath.Join(t.TempDir(), "kek") // 16 bytes hex-encoded, not the required 32. assert.Ok(t, os.WriteFile(path, []byte("00112233445566778899aabbccddeeff"), 0600)) _, err := envelope.LoadKeyFile(path) assert.Eq(t, err != nil, true) }