MCPcopy Create free account
hub / github.com/NVIDIA/OpenShell / resolve_placeholder

Method resolve_placeholder

crates/openshell-core/src/secrets.rs:225–254  ·  view source on GitHub ↗

Resolve a placeholder string to the real secret value. Returns `None` if the placeholder is unknown or the resolved value contains prohibited control characters (CRLF, null byte).

(&self, value: &str)

Source from the content-addressed store, hash-verified

223 /// Returns `None` if the placeholder is unknown or the resolved value
224 /// contains prohibited control characters (CRLF, null byte).
225 pub fn resolve_placeholder(&self, value: &str) -> Option<&str> {
226 let secret = if let Some(secret) = self.by_placeholder.get(value) {
227 secret
228 } else {
229 // Once an old generation ages out, the revision number is only a
230 // namespace marker. Fall back by key to the current credential so
231 // long-running child processes survive provider credential refresh.
232 let key = revisioned_placeholder_env_key(value).or_else(|| alias_env_key(value))?;
233 let canonical = placeholder_for_env_key(key);
234 self.by_placeholder.get(&canonical)?
235 };
236 if secret.expires_at_ms > 0 && secret.expires_at_ms <= now_ms() {
237 tracing::warn!(
238 location = "resolve_placeholder",
239 "credential resolution rejected: credential is expired"
240 );
241 return None;
242 }
243 match validate_resolved_secret(&secret.value) {
244 Ok(s) => Some(s),
245 Err(reason) => {
246 tracing::warn!(
247 location = "resolve_placeholder",
248 reason,
249 "credential resolution rejected: resolved value contains prohibited characters"
250 );
251 None
252 }
253 }
254 }
255
256 pub fn expires_at_ms_for_placeholder(&self, placeholder: &str) -> Option<i64> {
257 self.by_placeholder

Callers 8

gcp_token_responseMethod · 0.80
rewrite_header_valueMethod · 0.80
rewrite_path_segmentFunction · 0.80
handle_envFunction · 0.80

Calls 6

alias_env_keyFunction · 0.85
placeholder_for_env_keyFunction · 0.85
now_msFunction · 0.85
validate_resolved_secretFunction · 0.85
getMethod · 0.45

Tested by

no test coverage detected