yera.creds.policy
Policy operations for controlled secret access.
Symbols
require_authorized_credential_group
require_authorized_credential_group(
groups: Mapping[str, CredentialGroupRecord],
group_name: str,
project_root: Path,
) → strReturn a group's stable owner ID after project authorization.
Parameters
Credential groups keyed by mutable display name.
Configured credential-group name.
Project requesting access.
Returns
Stable owner ID used to resolve the group's ordinary secrets.
Raises
If the named group does not exist.
If the project is not authorized.
resolve_authorized_tool_secrets
resolve_authorized_tool_secrets(
store: SecretStore,
groups: Mapping[str, CredentialGroupRecord],
group_name: str,
project_root: Path,
names: list[str],
) → dict[str, SecretValue]Authorize a project and resolve its declared ordinary credentials.
Parameters
Secret backend containing opaque values.
Credential groups keyed by mutable display name.
Configured credential-group name.
Project requesting access.
Exact names or explicit .* namespaces declared by the tool.
Returns
Requested ordinary credential values keyed by name.
Raises
If the named group does not exist.
If the project is not authorized.
If a declared credential is absent.
resolve_tool_secrets
resolve_tool_secrets(
store: SecretStore,
owner_id: str,
names: list[str],
) → dict[str, SecretValue]Resolve declared ordinary credentials for one authorized tool group.
Parameters
Secret backend containing opaque values.
Stable identity of the authorized credential group.
Exact credential names declared by the tool.
Returns
Requested values keyed by their declared names.
Raises
If any declared ordinary credential is absent.