UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
Loading...
Searching...
No Matches
chunk-ops.ts File Reference
import type;

Functions

function export activeChunks (project:Project)
 The chunks an export should actually emit.
 
function xv (value:string|undefined|null)
 Resolve a ${ref} for an exporter, falling back to the literal on failure.
 
function roleKey (raw:string)
 Resolve a named field from a vault entry: aliases, then the built-in field, then extra_vars.
 
 if (!match) return
 
 if (refName.startsWith('bundle:'))
 
 if (refName.startsWith('chunk:'))
 
 if (slashIdx >=0)
 
 if (entry)
 Parses an expression.
 
 for (const project of st.vault.projects)
 
function export domainFromCertPath (path:string)
 Returns the field formatted in its native config syntax for clipboard.
 
function export certEntryForDomain (domain:string)
 Find a certificate vault entry whose site (provider) matches the domain.
 
function export renderNginxCertCard (domain:string)
 Big canonical card for a domain's certificate in the nginx view: full fullchain + privkey, or a create prompt.
 
function export exportNginx (project:Project)
 Base64 of a string's UTF-8 bytes, as Kubernetes Secret.data requires.
 

Variables

export *from chunks starters
 
export *from chunks parsers
 
export *from chunks edit modal
 
export *from chunks env link
 
const REFERENCE_DENY
 Entry fields no ${…} may ever resolve to.
 
const version_history
 
const projectIds
 
const categories
 
const refName = match[1]
 
const slashIdx = refName.indexOf('/')
 
const entry = findEntryByRef(refName)
 
 return { resolved: null, refName, unresolved: true, source: null }
 

Function Documentation

◆ activeChunks()

function export activeChunks (   project:Project)

The chunks an export should actually emit.

disabled is documented as "excluded from exports", and the later exporters (apache, haproxy, ansible, postgres) each check it inline. The four that people actually deploy — WireGuard, Compose, nginx, k8s — did not, so disabling a peer or a service in the UI greyed the card out and then shipped it anyway. Disabling a WireGuard peer and still writing it into wg0.conf means the tunnel keeps trusting a peer the user believes they removed.

◆ xv()

function xv ( value:string|undefined|  null)

Resolve a ${ref} for an exporter, falling back to the literal on failure.

Six of the seven experimental exporters interpolated f.value raw, so a ${Provider/field} reached the generated config as literal text: a .pgpass line whose password is the string ${DB/password}, an Apache SSLCertificateFile pointing at nothing. That is invariant 5, and it is the same bug that was found in exportNginx during Phase 13 — found there by a golden fixture, missed here because these types had no fixture.

true selects the env-copy field, matching every other exporter that materialises a real config file. Canonical names for well-known field suffixes used in env var naming conventions. Reference alias → the vault-entry JSON field name it resolves to.

The values are the JSON names (api_key, not key) so this table and canonical_field in unv-cli/src/refs.rs are the same table written twice rather than two tables that happen to agree. Pinned from both sides by tests/fixtures/parity/field-aliases.json.

◆ roleKey()

function roleKey (   raw:string)

Resolve a named field from a vault entry: aliases, then the built-in field, then extra_vars.

The fall-through from an empty built-in to extra_vars matches entry_field() in unv-cli/src/refs.rs — without it ${Spotify/ID} would resolve in the CLI and come back empty here for the entry that keeps its client id in a var. Normalise a role or a reference field for comparison — account_sid, ACCOUNT-SID and Account Sid are one name. Twin: role_key in unv-cli/src/refs.rs. Whether the reference target is explicitly public; unknown values fail closed. Find the entry a bare ${NAME} or a ${NAME/field} prefix addresses.

Three attempts, in this order, and ambiguity is refused rather than guessed (E9):

  1. An exact provider match, which is what a reference written by hand means.
  2. A generated-name match — the Phase 23 template. ${SPOTIFY_V2} names the entry whose version is 2, which is the whole point of putting versions and labels into the name.
  3. The legacy Provider_keyid split on the last underscore.

2 and 3 occupy the same syntactic position, so a vault holding both a SPOTIFY entry with key_id: V2 and a SPOTIFY entry with version: 2 has two honest answers for ${SPOTIFY_V2}. Returning either would be a silent wrong value written into a config — the defect class Phase 21 was about — so this returns nothing and every exporter reports it unresolved. The explicit ${Provider/field} form is never ambiguous and is what the docs recommend.

Twin: find_entry in unv-cli/src/refs.rs, pinned by the reference_lookup section of tests/fixtures/parity/env-names.json. ${bundle:Name}, ${bundle:Name/slot}, ${bundle:Name/slot/field} and ${bundle:Name/local}. Twin of resolve_bundle_ref in unv-cli/src/refs.rs. An ambiguous bundle name or an unknown slot is unresolved, never a guess.

◆ if() [1/5]

if ( !  match)

◆ if() [2/5]

if ( refName.  startsWith 'bundle:')

◆ if() [3/5]

if ( refName.  startsWith 'chunk:')

◆ if() [4/5]

if ( slashIdx >=  0)

◆ if() [5/5]

if ( pos !  pos ! = =toks.length)
new

Parses an expression.

Throws with a readable message on malformed input.

◆ for()

for ( const project of st.vault.  projects)

◆ domainFromCertPath()

function export domainFromCertPath (   path:string)

Returns the field formatted in its native config syntax for clipboard.

Rewrites every ${PROVIDER…} chunk reference after an entry is renamed.

References resolve by provider name (see resolveFieldRef), so renaming an entry used to break every chunk field pointing at it — silently, with the field simply starting to render unresolved. The security audit could already detect the resulting stale refs; nothing prevented them. Projects and categories cascade their renames, and this brings entries in line.

Handles all four reference spellings: ${Provider}, ${Provider/field}, ${Provider_KeyId} and ${Provider_KeyId/field}. Leaves ${chunk:…} alone — those address a chunk, not an entry.

Returns
how many fields were rewritten. Find a vault cert entry linked to a field value (${REF} or path pattern). Render a certificate info panel for a linked vault cert entry. Extract a domain from a letsencrypt-style path, e.g. ".../live/darthdemono.com/fullchain.pem". All cert domains an nginx project references: project name, server_name values, ssl paths, nginx_key paths.

◆ certEntryForDomain()

function export certEntryForDomain (   domain:string)

Find a certificate vault entry whose site (provider) matches the domain.

Create (if missing) a stub certificate vault entry for a domain. Returns the entry. Does not save. IDs of nginx_key chunks whose PEM content duplicates a shown cert entry (fullchain/privkey).

◆ renderNginxCertCard()

function export renderNginxCertCard (   domain:string)

Big canonical card for a domain's certificate in the nginx view: full fullchain + privkey, or a create prompt.

Render an nginx listen directive as a badge row. Render server_name value as individual hostname badges. Render an nginx return directive as a redirect badge. The file a stack integration (Prometheus, Grafana, Homepage) produces.

◆ exportNginx()

function export exportNginx (   project:Project)

Base64 of a string's UTF-8 bytes, as Kubernetes Secret.data requires.

btoa operates on Latin-1 code units, which broke this two ways: any character above U+00FF (an emoji, CJK, anything outside Latin-1) threw InvalidCharacterError and took the whole export down, and a character in U+0080–U+00FF — é, £, ü — encoded its Latin-1 byte instead of its UTF-8 bytes, so the cluster silently decoded a different secret than the one stored. The quiet corruption is the worse of the two. Comma/whitespace separated list; identical to the Rust split_k8s_list.

Variable Documentation

◆ starters

export* from chunks starters

◆ parsers

export* from chunks parsers

◆ modal

export* from chunks edit modal

◆ link

export* from chunks env link

◆ REFERENCE_DENY

const REFERENCE_DENY

Entry fields no ${…} may ever resolve to.

Metadata, not values: id is the row's UUID and the other three are lists that would stringify into something no config format wants. Checked before the lookup, so an extra_vars entry keyed id is unreachable too — ${X/id} has to mean one thing everywhere, and making it depend on the entry's own vars is the divergence this closes.

Twin of REFERENCE_DENY in unv-cli/src/refs.rs.

◆ version_history

const version_history

◆ projectIds

const projectIds

◆ categories

const categories

◆ refName

const refName = match[1]

◆ slashIdx

const slashIdx = refName.indexOf('/')

◆ entry

const entry = findEntryByRef(refName)

◆ return

return { resolved: null, refName, unresolved: true, source: null }