Skip to content

httpd,sysconf: extract common code for credentails/auth handling - #143

Open
mvo5 wants to merge 4 commits into
systemd:mainfrom
mvo5:sysconf-auth-helpers
Open

mvo5 wants to merge 4 commits into
systemd:mainfrom
mvo5:sysconf-auth-helpers

Conversation

@mvo5

@mvo5 mvo5 commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Entropy was acquired over time in the credentials and auth handling - so this PR is a first step to reduce it (well, hopefully). It moves duplicated code into sysconf and simplifies things. See the individual commits.

In summary:

  • CredentialsLoader is now passed around not the naked credentials directory
  • Duplicated ways to find credentials are now unified via CredentialsLoader::find()
  • The code in sysconf that returns a path returns a Path{,Buf} now instead of naked strings

Note that this is just the first step, e.g. the mtime cache and the source discovery is nearly identical between the auth methods (and probably more).

We now have a shared credentials loader in the sysconf module.
Use that instead of the duplicated code in sshauth.

No behavior change.
The credentials loader was not helping the upper code layers much,
there was still a lot of manual path wigglin needed.

This commit adds a new high level API: a find() that takes a list
of credentails (with `*` suffix support) and returns the list of
credentails paths that are found. And the same with "find_with()"
so that can be used to run a clousure with the found credential.

With `find_with()` we can easily print the list of unconsumed
credentails and `find()` replaces the hand-rolled credential
collection in auth_ssh.rs and auth_api_key.rs and they behave
the same now.
The httpd code around the credentials grew a bit around the
wrong type: we used `String` for the path handling when a
`Path` (or `PathBuf`) would have been the appropriate type.

This commit fixes this mistake. Mostly mechanical.
Simplify the CredentialsLoader by adding a new from_env()
constructor instead of the previous two-call shape of
path_from_env() and from_dir(). This makes using the
CredentialsLoader simpler and we can make `from_dir()` test
only.

This also means that now we can pass around the CredentialsLoader
instead of the previous way where we passed a directory and then
with that dir we build a new CredentialsLoader every time we
needed one.

Along the way we can also simplify how the current set of auth
files is collected: a shared sysconf::current_key_sources() helper
that takes the fixed paths from the auth method and the credential
loader and patterns.

One small wrinkle: we need a new CredentialsLoader::expected_path()
now for the TLS config and import_ssh as we now hide the path, but
arguably that is an improvement (even though the API of
CredentialsLoader got bigger by one function).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant