secrets

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: MIT Imports: 11 Imported by: 0

Documentation

Overview

Package secrets stores credentials in the OS credential store (macOS Keychain, Windows Credential Manager, Secret Service on Linux) and falls back silently to a 0600 JSON file in the config dir when that store is unavailable, as on headless servers and in containers.

Keys in use: "api_token" (set with `audd config set token`), "login_api_token" (fetched by `audd login`), "oauth" (JSON of oauth.Tokens), "oauth_pending" (an unfinished login).

Index

Constants

This section is empty.

Variables

View Source
var ErrKeyringDelete = errors.New("could not remove it from the system credential store")

ErrKeyringDelete means a secret is still in the system credential store because deleting it there failed (a locked keychain, a dismissed prompt). The file copy, if any, was deleted.

View Source
var ErrNotFound = errors.New("secret not found")

ErrNotFound is returned by Get when no value is stored.

Functions

func WriteFileAtomic

func WriteFileAtomic(path string, data []byte, perm os.FileMode) error

WriteFileAtomic writes data to a temp file in the same dir and renames it over path, so readers never see a partial file.

Types

type File

type File struct {
	// contains filtered or unexported fields
}

File stores secrets in a JSON file readable only by the user (0600).

func NewFile

func NewFile(path string) *File

NewFile returns a file-backed Store at path.

func (*File) Delete

func (f *File) Delete(profile, key string) error

func (*File) Get

func (f *File) Get(profile, key string) (string, error)

func (*File) Set

func (f *File) Set(profile, key, value string) error

type Memory

type Memory struct {
	// contains filtered or unexported fields
}

Memory is an in-memory Store for tests.

func NewMemory

func NewMemory() *Memory

NewMemory returns an empty in-memory Store.

func (*Memory) Delete

func (m *Memory) Delete(profile, key string) error

func (*Memory) Get

func (m *Memory) Get(profile, key string) (string, error)

func (*Memory) Set

func (m *Memory) Set(profile, key, value string) error

type Store

type Store interface {
	Get(profile, key string) (string, error) // ErrNotFound when absent
	Set(profile, key, value string) error
	Delete(profile, key string) error // deleting a missing key is not an error
}

Store keeps secrets per profile.

func Default

func Default() Store

Default returns the OS credential store with a silent fallback to <config dir>/credentials.json. AUDD_NO_KEYRING=1 uses the file only.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL