Expand description
credentials.toml — the per-publisher TDM API keys (#509).
docs/CONFIG.md §6 specified this file in full — schema, precedence, and
a 0600 permission warning — and nothing read it. A user who followed a
NORMATIVE document wrote their Elsevier key into a file doiget ignored,
and the source then reported itself unavailable for want of a key. That
is the #442 / #454 / #476 shape, landed on credentials.
§What this file carries, and what it deliberately does not
api_key: yes. A long-lived key is genuinely better off in a file
than in the environment. It survives a shell restart, it is not visible
in ps, and it does not leak into the environment of every subprocess.
The 0600 check is then a real control rather than a sentence — which
means it has to be visible, so it is an Advisory that config doctor prints rather than a tracing::warn! the default log level
throws away.
agreed: no. docs/LEGAL.md §6a.2 makes the per-publisher
agreement an enforced control, and part of why it is meaningful is
that DOIGET_AGREE_TDM_<PUBLISHER>=1 is a variable the user sets in the
session that runs the fetch. A boolean written once into a file and
forgotten is a weaker act of consent, and weakening it as a side effect
of adding a convenience is the kind of accident ADR-0048 was written
about. So the key may come from either place; the agreement is
environment-only, and an agreed key here is reported rather than
silently discarded — a documented field with no reader is the defect
this module exists to close.
§Precedence
DOIGET_KEY_<PUBLISHER> wins over [tdm.<publisher>] api_key, matching
the docs/CONFIG.md §1 chain and the store_root / contact_email
rungs (#441, #504).
Structs§
- Credentials
- Parsed
credentials.toml.
Enums§
- Advisory
- Something worth telling the user that does not stop the rest of the file being used.
- Credentials
Error - Why
credentials.tomlcould not be read.
Constants§
- PUBLISHERS
- Publisher slugs this file may carry, matching the
[tdm.<slug>]tables indocs/CONFIG.md§6 and thetdm-<slug>Cargo features.
Functions§
- load
- Load
credentials.tomlfrom an explicit path, surfacing failures. - load_
or_ default - Load the credentials file, or the empty set.
- path
<config_dir>/doiget/credentials.toml.