Commit Graph

3 Commits

Author SHA1 Message Date
Teknium d4f2933262 refactor(agent/creds): unify secret-source CLI/cache/error plumbing in base and _cache
- base: run_cli (shared subprocess wrapper), classify_cli_error (rule tables),
  coerce_float, source_child_env, FetchResult.fail, SecretSource.token_env /
  token_env_key / default_token_env / override_existing_default so per-backend
  override_existing/protected_env_vars overrides collapse into the ABC;
  generic remediation is a kind->template table.
- _cache: atomic_write_json (mkstemp->0600->replace) and entry_from_payload
  shared by DiskCache and the bws encrypted cache; SecretCache = L1 dict + L2
  DiskCache with lookup/store/clear.
2026-09-02 13:29:46 -07:00
teknium1 19055492aa fix: route stray HERMES_HOME hardcodes through get_hermes_home() (profile + native-Windows safety) 2026-07-29 09:33:48 -07:00
Taylor H. Perkins db495b0fba refactor(secrets): extract shared cache/result substrate for secret sources
Pull the disk-cache + FetchResult substrate out of bitwarden.py into a new
agent/secret_sources/_cache.py: FetchResult, CachedFetch, is_valid_env_name,
and a generic DiskCache (atomic mkstemp -> chmod 0600 -> os.replace write,
0700 cache dir, TTL-gated read AND write). Bitwarden now consumes it via a
module-level DiskCache instance and thin wrappers, so the security-sensitive
atomic-write/0600/TTL logic lives in exactly one place instead of being
copy-pasted per backend (and drifting). Behavior is unchanged — the full
Bitwarden suite passes untouched.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 04:58:07 -07:00