diff --git a/tests/nip46_e2e.rs b/tests/nip46_e2e.rs index 470b7e7..c166a5f 100644 --- a/tests/nip46_e2e.rs +++ b/tests/nip46_e2e.rs @@ -342,9 +342,14 @@ async fn nip46_client_handshake_and_sign_against_fake_amber() { let app = { let _guard = VAULT_ENV_LOCK.lock().unwrap(); let tmp = std::env::temp_dir().join(format!("keynectr-e2e-{}", std::process::id())); - std::fs::create_dir_all(&tmp).unwrap(); + // data_dir() is $XDG_DATA_HOME/keynectr — the isolation vault must + // live there. Writing it one level too shallow left the app finding + // NO vault at the real path, which silently migrated the legacy + // repo vault (with the user's real keys!) into the test instead. + let app_dir = tmp.join("keynectr"); + std::fs::create_dir_all(&app_dir).unwrap(); std::fs::write( - tmp.join("profiles_vault.json"), + app_dir.join("profiles_vault.json"), serde_json::to_string(&Vault::empty()).unwrap(), ) .unwrap(); @@ -634,9 +639,13 @@ async fn run_qr_pairing(connect_shape: &'static str) { std::process::id(), connect_shape )); - std::fs::create_dir_all(&tmp).unwrap(); + // Must be $XDG_DATA_HOME/keynectr/profiles_vault.json (see the + // sibling test above): the old shallow path let every e2e run + // migrate the real legacy repo vault into the test process. + let app_dir = tmp.join("keynectr"); + std::fs::create_dir_all(&app_dir).unwrap(); std::fs::write( - tmp.join("profiles_vault.json"), + app_dir.join("profiles_vault.json"), serde_json::to_string(&Vault::empty()).unwrap(), ) .unwrap();