Skip to content

Move Vaults and Credentials out of store into vaults and vaultpg - #319

Merged
SaladDay merged 2 commits into
mainfrom
refactor/vaults-domain
Sep 30, 2026
Merged

SaladDay merged 2 commits into
mainfrom
refactor/vaults-domain

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Part of #1 (store layering), PR 5: Vaults and Credentials move out of store.

  • vaults domain package:
    • Vault/Credential vocabulary, rules and the MCP credential selection errors
    • A Service for create, update, delete, OAuth replace/refresh, ResolveMCPCredentials and MCPBearerToken
    • Storage/Reader/OAuthTx ports
  • persistence/postgres/vaultpg: the PostgreSQL adapter.
    • Audit rows are recorded in the same transaction via auditpg.
    • OAuth refreshes, replacements and deletions serialize on a row lock.
    • List reads use one snapshot.
  • api: Vaults (service) and VaultsReader (adapter) Dependencies fields, strict fakes, and the vaults error writer.
  • execution: frozen bindings are vaults.MCPCredentialBinding. The Worker opens bearer tokens through an explicit Dispatcher.Credentials port and no longer reaches into store. StartWorker requires Credentials.
  • cmd/server: wires vaultpg.New(units) and vaults.NewService(store, key, oauthClient). store no longer takes the OAuth client.
  • Deleted from store: the vault, credential, OAuth and MCP credential files and their tests. Coverage moved to vaults/vaultpg.

Behaviour changes:

  • Invalid audit provenance on vault or credential delete/update now returns 400 instead of 500.
  • Unstorable OAuth names, metadata and selection queries now return 400.
  • A credential create that races a vault deletion now returns 404 instead of 500.

Checks on the final head (d34e791 + 2):

  • go build ./... and go vet ./services/core/... across the whole module
  • vaults and vaultpg in full, including the OAuth refresh race tests
  • api, execution, cmd/server and sandbox/providers: the affected tests, by -run
  • store: by -run only (the audit and MCP credential publicHandler tests)
  • make openapi (no diff) and scripts/check-names.py

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit 2415c42 into main Sep 30, 2026
6 checks passed
@SaladDay
SaladDay deleted the refactor/vaults-domain branch September 30, 2026 17:26
The api handlers, the Session credential binding and the Dispatcher's MCP bearer lookup use the vaults service and the vaultpg adapter. The Vault and Credential code and tests leave store.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant