|
UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
|
File-shaped credentials — Phase 23, E17. More...
import type;Functions | |
| function export | isFileShaped (entry:VaultEntry) |
| True when this entry's payload is a file rather than a string. | |
| if (entry.certificate_data) return | |
Variables | |
| export const | BLOB_MAX_BYTES = 128 * 1024 |
| The cap on stored file contents. | |
| null | |
File-shaped credentials — Phase 23, E17.
@description The twin of unv-cli/src/filecred.rs, pinned by tests/fixtures/parity/file-creds.json.
A GCP service-account JSON, an Apple .p8, an mTLS bundle and a kubeconfig are consumed by pointing at them: GOOGLE_APPLICATION_CREDENTIALS=/etc/gcp/sa.json. Copy-to-clipboard is the wrong verb for all of them — pasting a 2 KB JSON blob into a .env produces a variable the library will try to open() as a path, and the error names the blob rather than the mistake.
Two fields that had each solved half of it: blob_ref held a path and not the file, so a fresh machine had the reference and not the credential; certificate_data held the PEM and no path, so exporting it for a consumer that wants a file had nowhere to write. This separates what is stored from how it is delivered and lets one entry do both.
Writing the file is the delivery, so this is a Resolver::materialising path by construction and the Phase 14 rule needs no special case: an exporter that cannot get a materialising resolver simply cannot write the file. The .env line this emits names the path, never the contents.
| function export isFileShaped | ( | entry:VaultEntry | ) |
True when this entry's payload is a file rather than a string.
The contents this entry would write, and the extension they want.
blob_data first: it is the general case and the one E17 added. certificate_data is the pre-existing shape, and it is kept working rather than migrated — a certificate entry that has worked for twenty phases must not need editing to keep working.
| if | ( | entry. | certificate_data | ) |
| export const BLOB_MAX_BYTES = 128 * 1024 |
The cap on stored file contents.
A service-account JSON is ~2.3 KB and an embedded icon is already allowed 96 KB, so storing content is cheap. A kubeconfig with several clusters or a full chain bundle is a different promise, and refusing above the cap beats silently storing a truncated credential — which would fail at deploy time with an error about malformed JSON rather than about a vault.