fix(config): accept raw environment secret lookup
This commit is contained in:
@@ -30,6 +30,8 @@ const MAX_LINE_BYTES = 16 * 1024;
|
||||
export interface SecretBundleConfig {
|
||||
secretsFile?: string;
|
||||
secretFiles?: Readonly<Record<string, string | undefined>>;
|
||||
/** Accepted for callers that pass the raw process environment. */
|
||||
THT_SECRETS_FILE?: string;
|
||||
}
|
||||
|
||||
function unavailable(): Error { return new Error("secret bundle is unavailable"); }
|
||||
@@ -89,12 +91,18 @@ export function loadSecretBundle(file: string): ReadonlyMap<string, string> {
|
||||
|
||||
/** Resolve a value from the bundle, with the pre-bundle *_SECRET_FILE fallback. */
|
||||
export function secretValue(config: SecretBundleConfig, key: string): string | undefined {
|
||||
if (config.secretsFile) {
|
||||
const found = loadSecretBundle(config.secretsFile).get(key);
|
||||
const bundlePath = config.secretsFile ?? config.THT_SECRETS_FILE;
|
||||
if (bundlePath) {
|
||||
const found = loadSecretBundle(bundlePath).get(key);
|
||||
if (found !== undefined) return found;
|
||||
}
|
||||
const legacyName = LEGACY_FILES[key];
|
||||
const legacyPath = legacyName ? config.secretFiles?.[legacyName] : undefined;
|
||||
const legacyPath = legacyName
|
||||
? config.secretFiles?.[legacyName] ?? (() => {
|
||||
const raw = (config as unknown as Record<string, unknown>)[legacyName];
|
||||
return typeof raw === "string" ? raw : undefined;
|
||||
})()
|
||||
: undefined;
|
||||
if (!legacyPath) return undefined;
|
||||
const value = readSecure(legacyPath);
|
||||
if (!value || /\s/.test(value)) throw unavailable();
|
||||
|
||||
Reference in New Issue
Block a user