INNER CODE UNIT · TypeScript
resolve
synthetic-sciences/openscience · backend/cli/src/auth/index.ts:75
export async function resolve(): Promise<Resolved> {
const data = await JsonStore.read(filepath)
const workspace = await WorkspaceCredentials.read()
// Synced model keys stay in the encrypted overlay, never process.env.
// These reviewed provider env names therefore belong to the local user,
// not the separately allowlisted cloud service env. Compare provenance,
// not secret values: even an equal local key remains locally owned.
const synced = Object.fromEntries(
Object.entries(workspace?.auth ?? {}).filter(
([id]) =>
!WorkspaceCredentials.providerEnv(id).some((name) => {
const key = process.env[name]
return key && !isAtlasApiKey(key)
}),
),
)
// This device's own entries, kept apart from the synced ones: provenance
// is decided by which store an id came from, never by object identity on