pub fn entry_ck(entry: &Value) -> StringExpand description
Canonical identity key for a vault entry.
Prefers the stable id (a UUID the frontend assigns on creation and never
mutates). Falls back to provider|account_name|key_id for entries written
before id existed.
Every consumer must use this one function. save_vault and
merge_user_vault_write previously disagreed — the former ignored
key_id, so two entries sharing provider+account collapsed into one key and
version_history / audit rows landed on the wrong entry, while the RBAC
merge treated them as distinct.