resolver

package
v1.5.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 7, 2026 License: MPL-2.0 Imports: 3 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrInvalidJSON        = resolve.ErrInvalidJSON
	ErrFieldNotFound      = resolve.ErrFieldNotFound
	ErrMalformedReference = resolve.ErrMalformedReference
)

Functions

func ContainsReferences

func ContainsReferences(rawJSON []byte) bool

ContainsReferences reports whether rawJSON contains any KV reference.

func ContainsReferencesString

func ContainsReferencesString(s string) bool

ContainsReferencesString reports whether s contains any KV reference.

func ValidateSyntax

func ValidateSyntax(s string) error

ValidateSyntax reports whether s is free of malformed KV references, without resolving anything or contacting a store. It returns nil for a string with no KV syntax and for one whose kv:// and $kv{} references are all well-formed; it returns an error wrapping ErrMalformedReference for the first malformed reference found.

func ValidateSyntaxAll

func ValidateSyntaxAll(rawJSON []byte) error

ValidateSyntaxAll walks a raw JSON document and validates the KV reference syntax of every string value at any depth, without resolving anything or contacting a store. It returns nil when every reference (in any field, not only URL fields) is well-formed, an error wrapping ErrMalformedReference for the first malformed reference, or ErrInvalidJSON if the document cannot be parsed.

Types

type Reference

type Reference struct {
	// Store is the registry store name
	Store string

	// Path is the provider-specific key or path within the store.
	Path string

	// Field is the optional "#field" fragment; empty when absent.
	Field string
}

Reference is a parsed kv:// whole-value reference of the form "kv://<store>/<path>[#<field>]".

func ParseReference

func ParseReference(s string) (Reference, bool, error)

ParseReference parses a kv:// whole-value reference into its parts without resolving it — for callers (e.g. a write-back path) that must route to a store by name rather than read a value.

ok reports whether s is a kv:// whole-value reference at all. For a string that is not one — a legacy scheme (vault://, consul://), a plain literal, or an inline "$kv{...}" token — ok is false and err is nil. For a kv:// reference that is malformed (missing path separator, empty store or path), ok is true and err wraps ErrMalformedReference.

type Resolver

type Resolver interface {
	// Resolve processes the input string and replaces any KV references with
	// their resolved values from the configured stores.
	//
	// Returns the resolved string with all KV references replaced, or an error
	// if any reference cannot be resolved. When several inline tokens fail,
	// all failures are reported in a single joined error.
	//
	// If the input contains no KV references, it is returned unchanged.
	//
	// Precedence: an input starting with "kv://" is treated as a whole-value
	// reference — everything after the store name is the path, including any
	// "$kv{...}" text, which is NOT expanded. Inline tokens are only processed
	// in strings that do not start with "kv://". An inline path cannot contain
	// "}" — use the whole-value form for such keys.
	Resolve(ctx context.Context, input string) (string, error)

	// ResolveAll walks a raw JSON document recursively and applies Resolve to
	// every string value found at any depth, including inside nested objects
	// and arrays. Non-string scalars (numbers, booleans, null) are left as-is;
	// number values preserve their exact representation (no float64 precision
	// loss for large integers).
	//
	// Returns the re-serialized document with all KV references replaced, or an
	// error if any reference cannot be resolved. On error the document is not
	// partially written.
	//
	// If the input is not valid JSON, ErrInvalidJSON is returned. A valid
	// document containing no KV syntax (no "kv://" or "$kv{" substrings) is
	// returned byte-for-byte unchanged. Documents that do contain KV syntax
	// are re-serialized: the output normalizes formatting (object keys sorted,
	// insignificant whitespace removed) while preserving all values.
	// HTML characters (&, <, >) are NOT escaped in the output.
	ResolveAll(ctx context.Context, rawJSON []byte) ([]byte, error)
}

Resolver handles string replacement for KV references in configuration strings. It supports two syntax patterns:

  • Whole-value references: "kv://store-name/path/to/secret#field"
  • Inline references: "https://$kv{store-name:path/to/secret#field}/api/v1"

The resolver works against a registry of named stores, allowing the same syntax to work across different provider types (Vault, Consul, AWS, etc.).

JSON field extraction is supported via the #field syntax using JSON Pointer notation for nested field access.

func NewResolver

func NewResolver(registry kv.StoreGetter) Resolver

NewResolver returns a Resolver that resolves references against the given store getter (typically *registry.Registry). Unresolvable references are always errors.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL