fix(vector): close local pgvector final review

This commit is contained in:
2026-07-12 02:48:10 +02:00
parent 407c4a6faf
commit 6c67235caf
16 changed files with 265 additions and 28 deletions
+21 -1
View File
@@ -36,6 +36,26 @@ def _expand_env(value: Any) -> Any:
return value
def _resolve_secret_files(value: Any) -> Any:
if isinstance(value, dict):
resolved = {key: _resolve_secret_files(item) for key, item in value.items()}
if "password_file" in resolved:
if "password" in resolved:
raise ConfigError("password and password_file are mutually exclusive")
path = Path(resolved.pop("password_file"))
try:
secret = path.read_text()
except (OSError, UnicodeError) as exc:
raise ConfigError(f"Cannot read secret file: {path}") from exc
if not secret or any(char.isspace() for char in secret) or "\x00" in secret:
raise ConfigError(f"Invalid secret file: {path}")
resolved["password"] = secret
return resolved
if isinstance(value, list):
return [_resolve_secret_files(item) for item in value]
return value
class DatabaseConfig(BaseModel):
host: str = "localhost"
port: int = 5432
@@ -254,7 +274,7 @@ def load_config(path: Path) -> Config:
raw = yaml.safe_load(path.read_text())
if not isinstance(raw, dict):
raise ConfigError(f"Configurazione non valida (atteso un mapping YAML): {path}")
expanded = _expand_env(raw)
expanded = _resolve_secret_files(_expand_env(raw))
translated, used_legacy = translate_legacy_config(expanded)
_populate_legacy_views(translated)
try: