|
| 1 | +"""Credential Provider Chain for Cloudsmith CLI. |
| 2 | +
|
| 3 | +Implements an AWS SDK-style credential resolution chain that evaluates |
| 4 | +credential sources sequentially and returns the first valid result. |
| 5 | +""" |
| 6 | + |
| 7 | +from __future__ import annotations |
| 8 | + |
| 9 | +import logging |
| 10 | +from dataclasses import dataclass, field |
| 11 | +from typing import Optional |
| 12 | + |
| 13 | +logger = logging.getLogger(__name__) |
| 14 | + |
| 15 | + |
| 16 | +@dataclass |
| 17 | +class CredentialContext: # pylint: disable=too-many-instance-attributes |
| 18 | + """Context passed to credential providers during resolution.""" |
| 19 | + |
| 20 | + api_host: str = "https://api.cloudsmith.io" |
| 21 | + config_file_path: str | None = None |
| 22 | + creds_file_path: str | None = None |
| 23 | + profile: str | None = None |
| 24 | + debug: bool = False |
| 25 | + # Pre-resolved values from CLI flags (highest priority) |
| 26 | + cli_api_key: str | None = None |
| 27 | + # API networking configuration |
| 28 | + proxy: str | None = None |
| 29 | + ssl_verify: bool = True |
| 30 | + user_agent: str | None = None |
| 31 | + headers: dict | None = None |
| 32 | + keyring_refresh_failed: bool = False |
| 33 | + |
| 34 | + |
| 35 | +@dataclass |
| 36 | +class CredentialResult: |
| 37 | + """Result from a successful credential resolution.""" |
| 38 | + |
| 39 | + api_key: str |
| 40 | + source_name: str |
| 41 | + source_detail: str | None = None |
| 42 | + auth_type: str = "api_key" |
| 43 | + |
| 44 | + |
| 45 | +class CredentialProvider: |
| 46 | + """Base class for credential providers.""" |
| 47 | + |
| 48 | + name: str = "base" |
| 49 | + |
| 50 | + def resolve(self, context: CredentialContext) -> CredentialResult | None: |
| 51 | + """Attempt to resolve credentials. Return CredentialResult or None.""" |
| 52 | + raise NotImplementedError |
| 53 | + |
| 54 | + |
| 55 | +class CredentialProviderChain: |
| 56 | + """Evaluates credential providers in order, returning the first valid result. |
| 57 | +
|
| 58 | + If no providers are given, uses the default chain: |
| 59 | + Keyring → CLIFlag → EnvironmentVariable → ConfigFile. |
| 60 | + """ |
| 61 | + |
| 62 | + def __init__(self, providers: list[CredentialProvider] | None = None): |
| 63 | + if providers is not None: |
| 64 | + self.providers = providers |
| 65 | + else: |
| 66 | + from .providers import ( |
| 67 | + CLIFlagProvider, |
| 68 | + ConfigFileProvider, |
| 69 | + EnvironmentVariableProvider, |
| 70 | + KeyringProvider, |
| 71 | + ) |
| 72 | + |
| 73 | + self.providers = [ |
| 74 | + KeyringProvider(), |
| 75 | + CLIFlagProvider(), |
| 76 | + EnvironmentVariableProvider(), |
| 77 | + ConfigFileProvider(), |
| 78 | + ] |
| 79 | + |
| 80 | + def resolve(self, context: CredentialContext) -> CredentialResult | None: |
| 81 | + """Evaluate each provider in order. Return the first successful result.""" |
| 82 | + for provider in self.providers: |
| 83 | + try: |
| 84 | + result = provider.resolve(context) |
| 85 | + if result is not None: |
| 86 | + if context.debug: |
| 87 | + logger.debug( |
| 88 | + "Credentials resolved by %s: %s", |
| 89 | + provider.name, |
| 90 | + result.source_detail or result.source_name, |
| 91 | + ) |
| 92 | + return result |
| 93 | + if context.debug: |
| 94 | + logger.debug( |
| 95 | + "Provider %s did not resolve credentials, trying next", |
| 96 | + provider.name, |
| 97 | + ) |
| 98 | + except Exception: # pylint: disable=broad-exception-caught |
| 99 | + # Intentionally broad - one provider failing shouldn't stop others |
| 100 | + logger.debug( |
| 101 | + "Provider %s raised an exception, skipping", |
| 102 | + provider.name, |
| 103 | + exc_info=True, |
| 104 | + ) |
| 105 | + continue |
| 106 | + return None |
0 commit comments