|
UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
|
How a credential is sent — Phase 23, E16. More...
import type;Variables | |
| export type | AuthScheme = 'bearer' | 'header' | 'basic' | 'query' | 'cookie' |
| The ways a credential can be attached to a request. | |
| export interface | AuthHeader |
| One header, as a name and a value. | |
| value | __pad0__ |
How a credential is sent — Phase 23, E16.
@description The twin of unv-cli/src/authreq.rs, pinned by tests/fixtures/parity/auth-request.json and asserted from both sides.
How to send it is part of the credential, and it was nowhere in the model. Two entries holding the same-looking string are used completely differently: one goes in Authorization: Bearer, one in X-Api-Key, one in ?api_key=, one is the password half of HTTP basic. The vault knew the secret and not the one other thing you need in order to use it, so the user was left to remember which service wants which — and to get it wrong at 3am against an API that answers 401 either way.
auth_scheme + auth_param are what turn a stored string into a working request, and they are what the curl export needs anyway.
A cookie, a User-Agent or a password containing ‘’breaks-H '…', and the value is vault data, i.e. untrusted input (invariant 4).shellQuote` is POSIX single-quoting with the one escape that form allows, so a value can never end the quoted string and start a command.
The ways a credential can be attached to a request.
| export interface AuthHeader |
One header, as a name and a value.
| value __pad0__ |