MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / check_push_credentials

Function check_push_credentials

atomic-cli/src/commands/auth.rs:538–568  ·  view source on GitHub ↗

Verify, before a push begins, that the client can produce credentials for `remote_url`. Fails fast with an actionable error instead of letting the push proceed into a confusing 404 (which the server returns for private projects the caller isn't authorized to see). Returns `Ok(())` when an identity is resolvable (from `--identity`, the URL, or the default identity), exists in the local store, and

(remote_url: &str, identity_override: Option<&str>)

Source from the content-addressed store, hash-verified

536/// `--identity` explicitly names an identity that doesn't exist — that is a
537/// clear error, not a silent substitution.
538pub fn check_push_credentials(remote_url: &str, identity_override: Option<&str>) -> CliResult<()> {
539 let store = IdentityStore::open_default()
540 .map_err(|e| CliError::Internal(anyhow::anyhow!("Failed to open identity store: {e}")))?;
541
542 let inferred = resolve_identity_name_with_override(remote_url, identity_override);
543 let explicit = identity_override.is_some();
544
545 // Resolve a concrete identity, falling back to the default when the
546 // inferred name doesn't match (and the name didn't come from --identity).
547 let identity =
548 resolve_identity_with_default_fallback(&store, inferred.as_deref(), explicit, "push");
549 let resolved_name = identity.as_ref().map(|id| id.name.clone());
550
551 let issue = evaluate_push_credentials(
552 explicit,
553 inferred.as_deref(),
554 resolved_name.as_deref(),
555 |name| {
556 load_identity_lenient(&store, name)
557 .map(|id| store.load_keypair(&id.id, None).is_ok())
558 .unwrap_or(false)
559 },
560 );
561
562 match issue {
563 Some(issue) => Err(CliError::AuthenticationFailed {
564 remote: format!("{remote_url}: {}", issue.message()),
565 }),
566 None => Ok(()),
567 }
568}
569
570/// Pure decision core for [`check_push_credentials`], split out so it can be
571/// unit-tested without touching the on-disk identity store.

Callers 1

run_asyncMethod · 0.85

Calls 7

load_identity_lenientFunction · 0.85
as_refMethod · 0.80
load_keypairMethod · 0.80
cloneMethod · 0.45

Tested by

no test coverage detected