diff --git a/tests/nip46_e2e.rs b/tests/nip46_e2e.rs index c166a5f..a937613 100644 --- a/tests/nip46_e2e.rs +++ b/tests/nip46_e2e.rs @@ -354,7 +354,16 @@ async fn nip46_client_handshake_and_sign_against_fake_amber() { ) .unwrap(); std::env::set_var("XDG_DATA_HOME", &tmp); - std::sync::Arc::new(Mutex::new(App::load().expect("load app"))) + let app = std::sync::Arc::new(Mutex::new(App::load().expect("load app"))); + // Guard: if seeding ever misses the real data_dir path again, + // load_vault() silently migrates the legacy repo vault (real user + // keys) into the test. An isolated run must load an EMPTY vault. + assert!( + app.try_lock().unwrap().vault.profiles.is_empty(), + "e2e vault isolation failed: a non-empty vault was loaded — \ + the seeded vault is not where data_dir() looks" + ); + app }; // Amber's keys: `comms` is the per-connection key in the bunker:// URI; @@ -650,7 +659,14 @@ async fn run_qr_pairing(connect_shape: &'static str) { ) .unwrap(); std::env::set_var("XDG_DATA_HOME", &tmp); - std::sync::Arc::new(Mutex::new(App::load().expect("load app"))) + let app = std::sync::Arc::new(Mutex::new(App::load().expect("load app"))); + // Same empty-vault guard as the sibling test above. + assert!( + app.try_lock().unwrap().vault.profiles.is_empty(), + "e2e vault isolation failed: a non-empty vault was loaded — \ + the seeded vault is not where data_dir() looks" + ); + app }; { let mut a = app.lock().await;