yera.creds.file_protection

Protected filesystem operations for credential storage.

Symbols

def ensure_secret_directory — Create or validate a credential directory private to the current user.
def read_secret_file — Read bytes from an existing protected secret file.
def write_secret_file — Create a protected secret file containing opaque bytes.

ensure_secret_directory

ensure_secret_directory(
    path: Path,
) → None

Create or validate a credential directory private to the current user.

Parameters

path
type: Path

Directory used to contain protected credential files.

Raises

SecretStoreUnsafeError

If the path is not a safe private directory.

read_secret_file

read_secret_file(
    path: Path,
) → bytes

Read bytes from an existing protected secret file.

Parameters

path
type: Path

Protected credential-file path.

Returns

type: bytes

The stored opaque bytes.

Raises

FileNotFoundError

If the secret file does not exist.

SecretStoreUnsafeError

If its directory or file is unsafe.

write_secret_file

write_secret_file(
    path: Path,
    content: bytes,
) → None

Create a protected secret file containing opaque bytes.

Parameters

path
type: Path

Destination credential-file path.

content
type: bytes

Serialized credential-store bytes.

Raises

FileExistsError

If the destination already exists.

SecretStoreUnsafeError

If the containing directory is unsafe.