fix(config): accept raw environment secret lookup

This commit is contained in:
2026-07-12 11:07:22 +02:00
parent 5fe74612fb
commit 390cfd24b5
+11 -3
View File
@@ -30,6 +30,8 @@ const MAX_LINE_BYTES = 16 * 1024;
export interface SecretBundleConfig {
secretsFile?: string;
secretFiles?: Readonly<Record<string, string | undefined>>;
/** Accepted for callers that pass the raw process environment. */
THT_SECRETS_FILE?: string;
}
function unavailable(): Error { return new Error("secret bundle is unavailable"); }
@@ -89,12 +91,18 @@ export function loadSecretBundle(file: string): ReadonlyMap<string, string> {
/** Resolve a value from the bundle, with the pre-bundle *_SECRET_FILE fallback. */
export function secretValue(config: SecretBundleConfig, key: string): string | undefined {
if (config.secretsFile) {
const found = loadSecretBundle(config.secretsFile).get(key);
const bundlePath = config.secretsFile ?? config.THT_SECRETS_FILE;
if (bundlePath) {
const found = loadSecretBundle(bundlePath).get(key);
if (found !== undefined) return found;
}
const legacyName = LEGACY_FILES[key];
const legacyPath = legacyName ? config.secretFiles?.[legacyName] : undefined;
const legacyPath = legacyName
? config.secretFiles?.[legacyName] ?? (() => {
const raw = (config as unknown as Record<string, unknown>)[legacyName];
return typeof raw === "string" ? raw : undefined;
})()
: undefined;
if (!legacyPath) return undefined;
const value = readSecure(legacyPath);
if (!value || /\s/.test(value)) throw unavailable();