yera.cli.resources.creds

Credential-related helpers shared across CLI commands.

Symbols

def ensure_authorised_credential_group — Resolve or create an authorized version-two credential group.
def raise_if_bare_leaf_for_prefix_command — Reject a single credential leaf where a namespace is required.
def read_json_object_from_cli — Resolve JSON input from inline string or file path.
def read_json_raw_from_path_or_stdin — Read raw text from a filesystem path, or stdin when *path_or_dash* is ``'-'``.
def require_authorised_credential_group — Resolve an existing credential group authorized for this project.
def tool_secret_info — List ordinary tool secrets owned by a credential group.

ensure_authorised_credential_group

ensure_authorised_credential_group(
    ctx: AppContext,
    group_name: str,
) → CredentialGroupInfo

Resolve or create an authorized version-two credential group.

Parameters

ctx
type: AppContext

Active CLI application context.

group_name
type: str

Configured credential-group name.

Returns

type: CredentialGroupInfo

Non-sensitive metadata for the authorized group.

Raises

CredentialGroupNotAuthorisedError

If an existing group does not authorize the current project root.

raise_if_bare_leaf_for_prefix_command

raise_if_bare_leaf_for_prefix_command(
    path: str,
    creds: CredentialGroupMap,
    single_leaf_command: str,
    purpose_phrase: str,
) → None

Reject a single credential leaf where a namespace is required.

Parameters

path
type: str

Dotted credential path supplied to the prefix operation.

creds
type: CredentialGroupMap

Credential mapping in which to classify the path.

single_leaf_command
type: str

Suggested command for operating on the leaf, such as yera cred put my.key.

purpose_phrase
type: str

Description appended to the recovery message, such as single-leaf writes.

Raises

CredentialKeyError

If the path identifies a leaf but not a namespace.

read_json_object_from_cli

read_json_object_from_cli(
    json_str: str | None,
    from_file: str | None,
) → dict[str, Any]

Resolve JSON input from inline string or file path.

Exactly one of json_str or from_file must be provided. --from-file - reads from sys.stdin.

read_json_raw_from_path_or_stdin

read_json_raw_from_path_or_stdin(
    path_or_dash: str,
) → str

Read raw text from a filesystem path, or stdin when path_or_dash is '-'.

require_authorised_credential_group

require_authorised_credential_group(
    ctx: AppContext,
    group_name: str,
) → CredentialGroupInfo

Resolve an existing credential group authorized for this project.

Parameters

ctx
type: AppContext

Active CLI application context.

group_name
type: str

Configured credential-group name.

Returns

type: CredentialGroupInfo

Non-sensitive metadata for the authorized group.

Raises

CredentialGroupNotFoundError

If the group does not exist.

CredentialGroupNotAuthorisedError

If the current project is not authorized for the group.

tool_secret_info

tool_secret_info(
    ctx: AppContext,
    owner_id: str,
) → tuple[SecretInfo, ...]

List ordinary tool secrets owned by a credential group.

Parameters

ctx
type: AppContext

Active CLI application context.

owner_id
type: str

Stable credential-group identity.

Returns

type: tuple[SecretInfo, ...]

Tool-secret metadata ordered by credential name.