Skip to main content

Module credentials

Module credentials 

Source
Expand description

credentials.toml — the per-publisher TDM API keys (#509).

docs/CONFIG.md §6 specified this file in full — schema, precedence, and a 0600 permission warning — and nothing read it. A user who followed a NORMATIVE document wrote their Elsevier key into a file doiget ignored, and the source then reported itself unavailable for want of a key. That is the #442 / #454 / #476 shape, landed on credentials.

§What this file carries, and what it deliberately does not

api_key: yes. A long-lived key is genuinely better off in a file than in the environment. It survives a shell restart, it is not visible in ps, and it does not leak into the environment of every subprocess. The 0600 check is then a real control rather than a sentence — which means it has to be visible, so it is an Advisory that config doctor prints rather than a tracing::warn! the default log level throws away.

agreed: no. docs/LEGAL.md §6a.2 makes the per-publisher agreement an enforced control, and part of why it is meaningful is that DOIGET_AGREE_TDM_<PUBLISHER>=1 is a variable the user sets in the session that runs the fetch. A boolean written once into a file and forgotten is a weaker act of consent, and weakening it as a side effect of adding a convenience is the kind of accident ADR-0048 was written about. So the key may come from either place; the agreement is environment-only, and an agreed key here is reported rather than silently discarded — a documented field with no reader is the defect this module exists to close.

§Precedence

DOIGET_KEY_<PUBLISHER> wins over [tdm.<publisher>] api_key, matching the docs/CONFIG.md §1 chain and the store_root / contact_email rungs (#441, #504).

Structs§

Credentials
Parsed credentials.toml.

Enums§

Advisory
Something worth telling the user that does not stop the rest of the file being used.
CredentialsError
Why credentials.toml could not be read.

Constants§

PUBLISHERS
Publisher slugs this file may carry, matching the [tdm.<slug>] tables in docs/CONFIG.md §6 and the tdm-<slug> Cargo features.

Functions§

load
Load credentials.toml from an explicit path, surfacing failures.
load_or_default
Load the credentials file, or the empty set.
path
<config_dir>/doiget/credentials.toml.