Repository navigation
Conversation
We now have a shared credentials loader in the sysconf module. Use that instead of the duplicated code in sshauth. No behavior change.
The credentials loader was not helping the upper code layers much, there was still a lot of manual path wigglin needed. This commit adds a new high level API: a find() that takes a list of credentails (with `*` suffix support) and returns the list of credentails paths that are found. And the same with "find_with()" so that can be used to run a clousure with the found credential. With `find_with()` we can easily print the list of unconsumed credentails and `find()` replaces the hand-rolled credential collection in auth_ssh.rs and auth_api_key.rs and they behave the same now.
The httpd code around the credentials grew a bit around the wrong type: we used `String` for the path handling when a `Path` (or `PathBuf`) would have been the appropriate type. This commit fixes this mistake. Mostly mechanical.
Simplify the CredentialsLoader by adding a new from_env() constructor instead of the previous two-call shape of path_from_env() and from_dir(). This makes using the CredentialsLoader simpler and we can make `from_dir()` test only. This also means that now we can pass around the CredentialsLoader instead of the previous way where we passed a directory and then with that dir we build a new CredentialsLoader every time we needed one. Along the way we can also simplify how the current set of auth files is collected: a shared sysconf::current_key_sources() helper that takes the fixed paths from the auth method and the credential loader and patterns. One small wrinkle: we need a new CredentialsLoader::expected_path() now for the TLS config and import_ssh as we now hide the path, but arguably that is an improvement (even though the API of CredentialsLoader got bigger by one function).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Entropy was acquired over time in the credentials and auth handling - so this PR is a first step to reduce it (well, hopefully). It moves duplicated code into sysconf and simplifies things. See the individual commits.
In summary:
Note that this is just the first step, e.g. the mtime cache and the source discovery is nearly identical between the auth methods (and probably more).