Pure decision core for [`check_push_credentials`], split out so it can be unit-tested without touching the on-disk identity store. `explicit` — whether `--identity` was passed. `inferred` — the name inferred from the URL/flag (before fallback); used only to name the missing identity in the error message. `resolved_name` — the identity name to use **after** the default fallback (`None` when nothin
(
explicit: bool,
inferred: Option<&str>,
resolved_name: Option<&str>,
keypair_loadable: impl Fn(&str) -> bool,
)
| 580 | /// Returns `None` when credentials are usable, or `Some(issue)` describing the |
| 581 | /// problem. |
| 582 | fn evaluate_push_credentials( |
| 583 | explicit: bool, |
| 584 | inferred: Option<&str>, |
| 585 | resolved_name: Option<&str>, |
| 586 | keypair_loadable: impl Fn(&str) -> bool, |
| 587 | ) -> Option<CredentialIssue> { |
| 588 | match resolved_name { |
| 589 | Some(name) => { |
| 590 | if !keypair_loadable(name) { |
| 591 | return Some(CredentialIssue::KeypairUnavailable { |
| 592 | name: name.to_string(), |
| 593 | }); |
| 594 | } |
| 595 | None |
| 596 | } |
| 597 | None => { |
| 598 | // No usable identity. If --identity was explicit, name the missing |
| 599 | // identity so the user knows which input was wrong. Otherwise the |
| 600 | // fallback to default also failed (no default) — report that. |
| 601 | if explicit { |
| 602 | Some(CredentialIssue::ExplicitIdentityNotFound { |
| 603 | name: inferred.unwrap_or_default().to_string(), |
| 604 | }) |
| 605 | } else { |
| 606 | Some(CredentialIssue::NoIdentity) |
| 607 | } |
| 608 | } |
| 609 | } |
| 610 | } |
| 611 | |
| 612 | /// Derive the apex server URL (scheme + host without the leading subdomain |
| 613 | /// label + port) from a tenant-scoped remote URL. |
no outgoing calls