pub enum CredentialRef {
Custodian(CredentialName),
LegacyEnv {
var: String,
},
LegacyTag {
tag: String,
},
}Expand description
One parsed operator-config credential reference (DR-0053 Migration).
Five subsystems arrived at reference-not-value independently with four
spellings (env:OPENAI_API_KEY, secret:claude, credential:model,
credential:account:openai); this is the one namespace they unify onto.
credential:<name> names a custodian entry; every legacy spelling still
parses but resolves degraded at r0 — visible, never silent — and is
removed at the first release that requires a rung.
Variants§
Custodian(CredentialName)
credential:<name> — a custodian entry; the rung is whatever the
custodian derives from evidence.
LegacyEnv
env:<VAR> — the legacy environment shim: material read from whip’s
own environment, so the honest resolution is r0 and degraded.
LegacyTag
A pre-unification spelling (secret:<x>, credential:account:<x>,
or a legacy credential:<x> that names no custodian entry). Carried
as an opaque tag so existing bindings keep matching; r0 degraded.
Implementations§
Source§impl CredentialRef
impl CredentialRef
pub fn parse(raw: &str) -> Result<Self, String>
Sourcepub fn shim_rung(&self) -> (Rung, bool)
pub fn shim_rung(&self) -> (Rung, bool)
The honest rung/degraded pair this reference can claim WITHOUT asking
a custodian: legacy shims are r0 degraded by construction. For
Custodian references the truth is whatever the custodian’s reply
derives — this method reports the r0 floor and the caller must prefer
the reply’s values (credential-rung-evidence.maude: configuration
is not evidence).
Trait Implementations§
Source§impl Clone for CredentialRef
impl Clone for CredentialRef
Source§fn clone(&self) -> CredentialRef
fn clone(&self) -> CredentialRef
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more