UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
Loading...
Searching...
No Matches
file-cred.ts File Reference

File-shaped credentials — Phase 23, E17. More...

import type;
Include dependency graph for file-cred.ts:

Functions

function export isFileShaped (entry:VaultEntry)
 True when this entry's payload is a file rather than a string.
 
 if (entry.certificate_data) return
 

Variables

export const BLOB_MAX_BYTES = 128 * 1024
 The cap on stored file contents.
 
 null
 

Detailed Description

File-shaped credentials — Phase 23, E17.

@description The twin of unv-cli/src/filecred.rs, pinned by tests/fixtures/parity/file-creds.json.

Some credentials are a file, and the variable names the path

A GCP service-account JSON, an Apple .p8, an mTLS bundle and a kubeconfig are consumed by pointing at them: GOOGLE_APPLICATION_CREDENTIALS=/etc/gcp/sa.json. Copy-to-clipboard is the wrong verb for all of them — pasting a 2 KB JSON blob into a .env produces a variable the library will try to open() as a path, and the error names the blob rather than the mistake.

Two fields that had each solved half of it: blob_ref held a path and not the file, so a fresh machine had the reference and not the credential; certificate_data held the PEM and no path, so exporting it for a consumer that wants a file had nowhere to write. This separates what is stored from how it is delivered and lets one entry do both.

Materialising by construction

Writing the file is the delivery, so this is a Resolver::materialising path by construction and the Phase 14 rule needs no special case: an exporter that cannot get a materialising resolver simply cannot write the file. The .env line this emits names the path, never the contents.

Function Documentation

◆ isFileShaped()

function export isFileShaped (   entry:VaultEntry)

True when this entry's payload is a file rather than a string.

The contents this entry would write, and the extension they want.

blob_data first: it is the general case and the one E17 added. certificate_data is the pre-existing shape, and it is kept working rather than migrated — a certificate entry that has worked for twenty phases must not need editing to keep working.

◆ if()

if ( entry.  certificate_data)

Variable Documentation

◆ BLOB_MAX_BYTES

export const BLOB_MAX_BYTES = 128 * 1024

The cap on stored file contents.

A service-account JSON is ~2.3 KB and an embedded icon is already allowed 96 KB, so storing content is cheap. A kubeconfig with several clusters or a full chain bundle is a different promise, and refusing above the cap beats silently storing a truncated credential — which would fail at deploy time with an error about malformed JSON rather than about a vault.

◆ null

return null
Initial value:
{
if (entry.blob_data) return { text: entry.blob_data, ext: guessExt(entry.blob_data) }
imported as source text
Definition bundle-import.ts:248
const entry
Definition chunk-ops.ts:480
ext ext
Definition totp-io.ts:56