diff --git a/harness/tht/config.py b/harness/tht/config.py index 67adb207..77c7f797 100644 --- a/harness/tht/config.py +++ b/harness/tht/config.py @@ -166,11 +166,28 @@ class RestConfig(BaseModel): """Accesso al DWH via Supabase/PostgREST. base_url es. https://host/dwh/ .""" base_url: str - api_key: str + api_key: str | None = None + # Installazione-local file path: il contenuto non entra mai in repo/descriptor/config + # renderizzata; viene letto solo a runtime dal processo che esegue il comando. + api_key_file: str | None = None timeout: int = 30 connect_timeout: int = 5 ssl_ca: str | None = None # path al certificato CA (per server con CA interna) + @model_validator(mode="after") + def resolve_api_key(self) -> "RestConfig": + if self.api_key is None and self.api_key_file is not None: + path = Path(self.api_key_file) + if not path.is_file() or path.is_symlink(): + raise ValueError("api_key_file is unavailable") + value = path.read_text(encoding="utf-8").strip() + if not value: + raise ValueError("api_key_file is empty") + self.api_key = value + if self.api_key is None: + raise ValueError("api_key or api_key_file is required") + return self + class DatabaseIdentityConfig(BaseModel): database: str