|
UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
|
import type;Functions | |
| function export | activeChunks (project:Project) |
| The chunks an export should actually emit. | |
| function | xv (value:string|undefined|null) |
Resolve a ${ref} for an exporter, falling back to the literal on failure. | |
| function | roleKey (raw:string) |
Resolve a named field from a vault entry: aliases, then the built-in field, then extra_vars. | |
| if (!match) return | |
| if (refName.startsWith('bundle:')) | |
| if (refName.startsWith('chunk:')) | |
| if (slashIdx >=0) | |
| if (entry) | |
| Parses an expression. | |
| for (const project of st.vault.projects) | |
| function export | domainFromCertPath (path:string) |
| Returns the field formatted in its native config syntax for clipboard. | |
| function export | certEntryForDomain (domain:string) |
Find a certificate vault entry whose site (provider) matches the domain. | |
| function export | renderNginxCertCard (domain:string) |
| Big canonical card for a domain's certificate in the nginx view: full fullchain + privkey, or a create prompt. | |
| function export | exportNginx (project:Project) |
Base64 of a string's UTF-8 bytes, as Kubernetes Secret.data requires. | |
Variables | |
| export *from chunks | starters |
| export *from chunks | parsers |
| export *from chunks edit | modal |
| export *from chunks env | link |
| const | REFERENCE_DENY |
Entry fields no ${…} may ever resolve to. | |
| const | version_history |
| const | projectIds |
| const | categories |
| const | refName = match[1] |
| const | slashIdx = refName.indexOf('/') |
| const | entry = findEntryByRef(refName) |
| return { resolved: null, refName, unresolved: true, source: null } | |
| function export activeChunks | ( | project:Project | ) |
The chunks an export should actually emit.
disabled is documented as "excluded from exports", and the later exporters (apache, haproxy, ansible, postgres) each check it inline. The four that people actually deploy — WireGuard, Compose, nginx, k8s — did not, so disabling a peer or a service in the UI greyed the card out and then shipped it anyway. Disabling a WireGuard peer and still writing it into wg0.conf means the tunnel keeps trusting a peer the user believes they removed.
| function xv | ( | value:string|undefined| | null | ) |
Resolve a ${ref} for an exporter, falling back to the literal on failure.
Six of the seven experimental exporters interpolated f.value raw, so a ${Provider/field} reached the generated config as literal text: a .pgpass line whose password is the string ${DB/password}, an Apache SSLCertificateFile pointing at nothing. That is invariant 5, and it is the same bug that was found in exportNginx during Phase 13 — found there by a golden fixture, missed here because these types had no fixture.
true selects the env-copy field, matching every other exporter that materialises a real config file. Canonical names for well-known field suffixes used in env var naming conventions. Reference alias → the vault-entry JSON field name it resolves to.
The values are the JSON names (api_key, not key) so this table and canonical_field in unv-cli/src/refs.rs are the same table written twice rather than two tables that happen to agree. Pinned from both sides by tests/fixtures/parity/field-aliases.json.
| function roleKey | ( | raw:string | ) |
Resolve a named field from a vault entry: aliases, then the built-in field, then extra_vars.
The fall-through from an empty built-in to extra_vars matches entry_field() in unv-cli/src/refs.rs — without it ${Spotify/ID} would resolve in the CLI and come back empty here for the entry that keeps its client id in a var. Normalise a role or a reference field for comparison — account_sid, ACCOUNT-SID and Account Sid are one name. Twin: role_key in unv-cli/src/refs.rs. Whether the reference target is explicitly public; unknown values fail closed. Find the entry a bare ${NAME} or a ${NAME/field} prefix addresses.
Three attempts, in this order, and ambiguity is refused rather than guessed (E9):
${SPOTIFY_V2} names the entry whose version is 2, which is the whole point of putting versions and labels into the name.Provider_keyid split on the last underscore.2 and 3 occupy the same syntactic position, so a vault holding both a SPOTIFY entry with key_id: V2 and a SPOTIFY entry with version: 2 has two honest answers for ${SPOTIFY_V2}. Returning either would be a silent wrong value written into a config — the defect class Phase 21 was about — so this returns nothing and every exporter reports it unresolved. The explicit ${Provider/field} form is never ambiguous and is what the docs recommend.
Twin: find_entry in unv-cli/src/refs.rs, pinned by the reference_lookup section of tests/fixtures/parity/env-names.json. ${bundle:Name}, ${bundle:Name/slot}, ${bundle:Name/slot/field} and ${bundle:Name/local}. Twin of resolve_bundle_ref in unv-cli/src/refs.rs. An ambiguous bundle name or an unknown slot is unresolved, never a guess.
| if | ( | ! | match | ) |
| if | ( | refName. | startsWith 'bundle:' | ) |
| if | ( | refName. | startsWith 'chunk:' | ) |
| if | ( | slashIdx >= | 0 | ) |
|
new |
Parses an expression.
Throws with a readable message on malformed input.
| for | ( | const project of st.vault. | projects | ) |
| function export domainFromCertPath | ( | path:string | ) |
Returns the field formatted in its native config syntax for clipboard.
Rewrites every ${PROVIDER…} chunk reference after an entry is renamed.
References resolve by provider name (see resolveFieldRef), so renaming an entry used to break every chunk field pointing at it — silently, with the field simply starting to render unresolved. The security audit could already detect the resulting stale refs; nothing prevented them. Projects and categories cascade their renames, and this brings entries in line.
Handles all four reference spellings: ${Provider}, ${Provider/field}, ${Provider_KeyId} and ${Provider_KeyId/field}. Leaves ${chunk:…} alone — those address a chunk, not an entry.
| function export certEntryForDomain | ( | domain:string | ) |
Find a certificate vault entry whose site (provider) matches the domain.
Create (if missing) a stub certificate vault entry for a domain. Returns the entry. Does not save. IDs of nginx_key chunks whose PEM content duplicates a shown cert entry (fullchain/privkey).
| function export renderNginxCertCard | ( | domain:string | ) |
Big canonical card for a domain's certificate in the nginx view: full fullchain + privkey, or a create prompt.
Render an nginx listen directive as a badge row. Render server_name value as individual hostname badges. Render an nginx return directive as a redirect badge. The file a stack integration (Prometheus, Grafana, Homepage) produces.
| function export exportNginx | ( | project:Project | ) |
Base64 of a string's UTF-8 bytes, as Kubernetes Secret.data requires.
btoa operates on Latin-1 code units, which broke this two ways: any character above U+00FF (an emoji, CJK, anything outside Latin-1) threw InvalidCharacterError and took the whole export down, and a character in U+0080–U+00FF — é, £, ü — encoded its Latin-1 byte instead of its UTF-8 bytes, so the cluster silently decoded a different secret than the one stored. The quiet corruption is the worse of the two. Comma/whitespace separated list; identical to the Rust split_k8s_list.
| export* from chunks starters |
| export* from chunks parsers |
| export* from chunks edit modal |
| export* from chunks env link |
| const REFERENCE_DENY |
Entry fields no ${…} may ever resolve to.
Metadata, not values: id is the row's UUID and the other three are lists that would stringify into something no config format wants. Checked before the lookup, so an extra_vars entry keyed id is unreachable too — ${X/id} has to mean one thing everywhere, and making it depend on the entry's own vars is the divergence this closes.
Twin of REFERENCE_DENY in unv-cli/src/refs.rs.
| const version_history |
| const projectIds |
| const categories |
| const refName = match[1] |
| const slashIdx = refName.indexOf('/') |
| const entry = findEntryByRef(refName) |