INNER CODE UNIT · Python
_blank_secret
caura-ai/caura · core-api/src/core_api/app.py:145
def _blank_secret(value) -> bool: # type: ignore[no-untyped-def]
"""True when a secret is missing, empty, or only whitespace.
Unwraps FIRST, and that ordering is load-bearing for whitespace rather than
for emptiness: ``SecretStr("")`` is falsy (``__len__`` is the secret's
length), but ``SecretStr(" ")`` has length 3 and ``str()`` of it is the
mask ``'**********'`` — so BOTH halves of this predicate pass on the
wrapper and a whitespace secret sails through. ``SecretStr("x") == "x"`` is
False for the same reason, which bypassed the equality check below once
already.
Note ``str.strip()`` removes only ``str.isspace()`` characters, so a secret
of U+200B or a UTF-8 BOM still reads as non-blank. Left as-is deliberately:
it is the convention every guard here shares, and narrowing it in one place
would recreate the asymmetry this function has already been bitten by.
"""
return not str(_unwrap_secret(value) or "").strip()