pub fn parse_env_ref(raw: &str) -> Option<&str>Expand description
The single brace/env-ref parse core shared by EVERY credential-resolution path (api_key, bearer token, basic password, oauth2 client_secret).
Returns Some(var_name) when raw is a secret REFERENCE — either the
"env:VAR" or the "${VAR}" form — and None for a plain literal (which the
caller uses verbatim). A malformed brace reference (e.g. "${}") is treated
as a reference to an empty name, i.e. Some(""), so the caller resolves it to
the empty string (omission) rather than shipping the literal ${}.
This consolidates the two brace parsers that previously existed (the inline
${-strip in the old api_key resolver in crate::http::auth and
expand_braced_var in crate::code_mode): all env-reference resolution now
flows through this one chokepoint so the discipline cannot drift per-variant.
§Why this is pub
The grammar is duplicated by necessity in pmcp-package’s
is_env_reference — that crate is the workspace-excluded leaf and neither
crate may depend on the other. The two implementations are held to a shared
accept/reject table asserted from an INTEGRATION test in each crate
(tests/env_ref_grammar_parity.rs here). An integration test is an external
consumer, so the reference implementation has to be reachable from outside
the crate for that parity claim to be checkable at all.
(It was previously pub(crate) with an #[allow(dead_code)], because in a
--no-default-features build neither http nor code-mode is compiled and
no in-crate caller exists. Being pub removes that need: the module is
still deliberately UNGATED, so the grammar is defined in one place that
compiles in every feature configuration.)