#!/usr/bin/env bash
# A stand-in for libsecret's secret-tool, used only to capture screenshots.
#
# Without this the fixture shell talks to the real OS keyring: it would read
# the operator's actual Bitwarden session into the demo panel, and the shots
# would depend on whether that entry happened to exist. Neither belongs in a
# screenshot harness, so the keyring is faked too.
#
# A session lookup succeeds with an obvious placeholder -- the panel needs a
# non-empty session before it will load any items -- and every other lookup
# reports "not stored", so PIN and fingerprint unlock show as unconfigured.
#
# The placeholder carries the running boot id, because that is the shape the
# panel now demands of a remembered session: a token from another boot is
# refused and cleared. Without the prefix the fixture shell would come up on
# the lock screen and there would be nothing to photograph.
set -uo pipefail

account=""
prev=""
for arg in "$@"; do
  [[ "$prev" == "account" ]] && account="$arg"
  prev="$arg"
done

case "${1:-}" in
  lookup)
    if [[ "$account" == "session" ]]; then
      echo "$(cat /proc/sys/kernel/random/boot_id) demo-session-token-not-real"
      exit 0
    fi
    exit 1 ;;
  store) cat >/dev/null; exit 0 ;;
  clear) exit 0 ;;
  *)     exit 1 ;;
esac
