module

Secrets::Editor

secrets edit helper: write plaintext to a mode-0600 tempfile, spawn $EDITOR (default vi) on it, return the edited buffer. The tempfile is wiped (best-effort) and deleted in ensure, whether the editor succeeded or not.

Why not stream through the editor? Most editors don't accept stdin/stdout for buffer editing — they need a file path. The tempfile is on /tmp (or $TMPDIR) for the duration of the edit, mode 0600 so other users on the box can't peek.

Instance methods

default_editor
Source
edit(plaintext : String, suffix : String = ".toml") : String

Open plaintext in $EDITOR, return what the user wrote. Raises Secrets::Error if the editor exits non-zero (the caller treats this as "user aborted, do not save").

Source
tmpdir
Source