UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
Loading...
Searching...
No Matches
copy-profile.ts File Reference

Copy profiles — how much of an entry a copy or an export actually emits. More...

import type;
Include dependency graph for copy-profile.ts:

Functions

function join (list:unknown)
 The metadata a profile adds, in a fixed order.
 

Variables

export type CopyProfile = 'basic' | 'extended' | 'full'
 How much of an entry a copy emits.
 
export type MetadataStyle = 'comment' | 'var'
 Where the metadata goes.
 
export interface CopyOpts
 
metadataStyle __pad0__
 
case __pad1__
 
includePrefix __pad2__
 
value __pad3__
 

Detailed Description

Copy profiles — how much of an entry a copy or an export actually emits.

@description Phase 23, step 3.

The complaint this answers

Copy carried three fields. Version, expiry, rate limit, scopes, environment, account, pool, purpose and every extra_vars entry were dropped, whatever the user was copying for — so the credential arrived somewhere useful and every fact about how to use it stayed in the vault.

Three profiles, and the setting is a default rather than a wall: the copy button's caret menu offers the other two plus "Value only" on every card.

Profile Emits
basic Primary value, api_secret, api_url, every extra_vars entry.
extended basic + version, expiry, rate limit, scopes, environment, account, pool.
full extended + description, purpose, tags, categories, projects, timestamps, rotation, compromised.

Metadata is comments by default

A .env is loaded into a process. Injecting six non-functional variables per credential into every container is a cost the user did not ask for by pressing Copy, so metadataStyle defaults to comment and var is the opt-in for people who genuinely want them in the environment.

Comment mode writes one # name: value line per field rather than joining them into a single line: full adds nine of them, a .env comment does not wrap, and a 300-character line is not a thing anybody reads.

This emits real values, and that is deliberate

The builder has no masker and no reveal flag. Redaction is the caller's job and it is decided by the Phase 14 rule that already governs every other artefact: unv get --profile refuses to stdout unless --reveal and writes the real thing with --out, exactly as unv export does; the app's Copy button is the UI's --reveal. Putting a masker in here would mean a second redaction policy to keep in step with out.rs, which is the shape that produced the two-lists-of-secret-fields leak in Phase 22.

Twin: unv-cli/src/profile.rs, pinned by tests/fixtures/parity/copy-profiles.json and asserted from both sides.

Function Documentation

◆ join()

function join (   list:unknown)

The metadata a profile adds, in a fixed order.

Fixed because it is asserted byte for byte from two implementations, and because a copy whose line order depends on object-key iteration produces a diff every time anybody touches the type.

Variable Documentation

◆ CopyProfile

export type CopyProfile = 'basic' | 'extended' | 'full'

How much of an entry a copy emits.

◆ MetadataStyle

export type MetadataStyle = 'comment' | 'var'

Where the metadata goes.

◆ CopyOpts

export interface CopyOpts
Initial value:
{
profile?: CopyProfile
export type CopyProfile
How much of an entry a copy emits.
Definition copy-profile.ts:62

◆ __pad0__

metadataStyle __pad0__

◆ __pad1__

case __pad1__

◆ __pad2__

includePrefix __pad2__

◆ __pad3__

value __pad3__