UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
Loading...
Searching...
No Matches
composite.ts File Reference

Composite secrets (Phase 24.1) — one value with secrets inside it. More...

Variables

export type CompositeKind = 'link' | 'signed_link' | 'connection' | 'custom' | (string & {})
 What a composite template is — decides encoding and whether Open is offered.
 
export interface CompositePart
 One named {part} and the raw value it holds.
 
value __pad0__
 
export interface RenderedComposite
 
used __pad1__
 Placeholder names actually found in the template, in first-use order.
 
unused __pad2__
 Parts supplied but never referenced by the template — a warning, not an error.
 
export type RenderError
 

Detailed Description

Composite secrets (Phase 24.1) — one value with secrets inside it.

@description The motivating case is a calendar-sharing URL, https://outlook.office365.com/owa/calendar/{mailbox_id}@inf.elte.hu/{calendar_key}/calendar.ics, where two path segments are credentials and the rest is structure. The root is the template; each placeholder is a part. Parts are ordinary extra_vars — key is the placeholder name, value is the secret — because that shape already has fail-closed masking with a public opt-out (E5), per-name history (E8), env naming and ${X/NAME} references. A second array would re-implement all four for no reason.

This is a twin pair with vault-core/src/composite.rs, pinned by tests/fixtures/parity/composite.json. The form needs a live preview as the user types, so rendering exists in both languages, and two implementations of one template language drift silently if nothing asserts they agree — see tests/composite.test.ts and vault-core/tests.

Encoding

Parts are stored raw; the renderer classifies each placeholder's zone from the template's own structure (never from a URL built out of real values, which would already contain a possibly /-or-@-bearing part) and percent-encodes using exactly RFC 3986's unreserved set. Deliberately not the built-in encodeURIComponent — it leaves ‘! ~ * ’ ( )` unescaped in addition to the RFC set, and the Rust side must byte-for-byte agree with whatever this does.

Variable Documentation

◆ CompositeKind

export type CompositeKind = 'link' | 'signed_link' | 'connection' | 'custom' | (string & {})

What a composite template is — decides encoding and whether Open is offered.

◆ CompositePart

export interface CompositePart
Initial value:
{
key: string
let key
Definition bundle-import.ts:252

One named {part} and the raw value it holds.

◆ __pad0__

value __pad0__

◆ RenderedComposite

export interface RenderedComposite
Initial value:
{
text: string
imported as source text
Definition bundle-import.ts:248

◆ __pad1__

used __pad1__

Placeholder names actually found in the template, in first-use order.

◆ __pad2__

unused __pad2__

Parts supplied but never referenced by the template — a warning, not an error.

◆ RenderError

export type RenderError
Initial value:
=
| { kind: 'unfilled_placeholder'; name: string }
| { kind: 'unbalanced_brace'; at: number }
| { kind: 'control_character_in_part'; name: string }
let kind
Definition bundle-import.ts:196