jmcore.secure_files
jmcore.secure_files
Private directory and atomic secret-file utilities.
Attributes
logger = logging.getLogger(__name__)
module-attribute
Functions:
atomic_write_private(path: Path, data: bytes) -> None
Atomically write bytes without exposing a permissively-mode temporary file.
Source code in jmcore/src/jmcore/secure_files.py
140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 | |
atomic_write_sensitive_file(path: Path, data: bytes) -> None
Atomically update a sensitive file while preserving configured aliases.
Source code in jmcore/src/jmcore/secure_files.py
170 171 172 | |
ensure_private_directory(path: Path) -> None
Create or tighten a secret-bearing directory to owner-only access.
Source code in jmcore/src/jmcore/secure_files.py
77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 | |
ensure_private_file(path: Path) -> None
Tighten an existing regular secret file to owner-only access.
Source code in jmcore/src/jmcore/secure_files.py
99 100 101 102 | |
ensure_sensitive_directory(path: Path) -> None
Create a missing application directory privately without changing an existing one.
Source code in jmcore/src/jmcore/secure_files.py
112 113 114 115 116 | |
ensure_sensitive_file(path: Path) -> None
Best-effort tighten a regular config or metadata file, following aliases.
Source code in jmcore/src/jmcore/secure_files.py
119 120 121 122 123 124 125 126 | |
read_private_file(path: Path) -> bytes
Read and tighten a regular secret file through one no-follow descriptor.
Source code in jmcore/src/jmcore/secure_files.py
105 106 107 108 109 | |
read_sensitive_file(path: Path) -> bytes
Read a regular config or metadata file, following aliases when configured.
Source code in jmcore/src/jmcore/secure_files.py
129 130 131 132 133 134 135 136 137 | |