yera.creds.auth

Credential group resolution, authorisation, and TOFU for tool credentials.

Symbols

def canonical_authorised_root_key — Return a normalised path string for comparing authorised roots.
def project_root_authorised_in_roots — Return True when *project_root* is authorised (including ``'*'`` wildcard).
def require_resolved_credential_group — Return *resolved* or raise if no credential group is configured.
def resolve_active_credential_group — Resolve the active credential group name from ``pyproject.toml``.
class ResolvedCredentialGroup — Active credential group name from ``[tool.yera.overrides] cred-group``.

canonical_authorised_root_key

canonical_authorised_root_key(
    path: Path | str,
) → str

Return a normalised path string for comparing authorised roots.

Resolves . / .., trailing separators, and symlinks so the same directory stored under different spellings matches.

project_root_authorised_in_roots

project_root_authorised_in_roots(
    project_root: Path | None,
    authorised_roots: list[str],
) → bool

Return True when project_root is authorised (including '*' wildcard).

require_resolved_credential_group

require_resolved_credential_group(
    resolved: ResolvedCredentialGroup | None,
) → ResolvedCredentialGroup

Return resolved or raise if no credential group is configured.

resolve_active_credential_group

resolve_active_credential_group() → ResolvedCredentialGroup | None

Resolve the active credential group name from pyproject.toml.

Reads non-empty cred-group under [tool.yera.overrides]. Whitespace-only values are treated as absent. When no pyproject.toml is found or no value is set → None.

ResolvedCredentialGroup

Active credential group name from [tool.yera.overrides] cred-group.