Skip to main content

dworshak-access is a light-weight library for local credential access. It exposes the get_secret() function, to allow a program to leverage credentials that have been established using the Drowshak CLI tool, which is a separate package.

Project description

dworshak-access is a light-weight library for local credential access. By adding dworshak-access as a dependency to your Python project, you enable your program or script to leverage credentials that have been established using the suster package, the Drowshak CLI tool.

Functions exposed in dworshak-access:

  • initialize_vault() -> VaultStatus – Create the vault directory, encryption key, and SQLite database. Safe to call multiple times.
  • check_vault() -> VaultStatus – Check the health of the vault.
  • store_secret(service: str, item: str, plaintext: str) – Encrypt and store a credential in the vault.
  • get_secret(service: str, item: str) -> str | None – Retrieve and decrypt a credential.
  • remove_secret(service: str, item: str) -> bool – Remove a credential from the vault.
  • list_credentials() -> list[tuple[str, str]] – List all stored service/item pairs.
  • export_vault(output_path: Path | str | None = None) -> str | None - Export vault to JSON file.

All secrets are stored Fernet-encrypted in the database under the secret column. No opaque blobs — every entry is meaningful and decryptable via the library.

Example

uv add dworshak-access
from dworshak_access import initialize_vault, store_secret, get_secret, list_credentials

# Initialize the vault (create key and DB if missing)
initialize_vault()

# Store credentials
store_secret("rjn_api", "username", "admin")
store_secret("rjn_api", "password", "s3cr3t")

# Retrieve credentials
username = get_secret("rjn_api", "username")
password = get_secret("rjn_api", "password")

# List stored items
for service, item in list_credentials():
    print(f"{service}/{item}")

Cryptography Library (When Building dworshak-access From Source or When Using It A Dependency in Your Project)

The only external Python library used is crytography, for the Fernet class.

On a Termux system, cryptography can (A) be built from source or (B) the precompiled python-crytography dedicated Termux package can be used.

A. Allow cryptography to build from source (uv is better at this compared to using pip)

pkg install rust binutils
uv sync

B. Use python-cryptography (This is faster but pollutes your local venv with other system site packages.)

pkg install python-cryptography
uv venv --system-site-packages
uv sync

uv venv --system-site-packages is a modern,faster alternative to python -m venv .venv --system-site-packages. Because uv manages the build-time dependencies (setuptools-rust and cffi) in an isolated environment and coordinates the hand-off to the Rust compiler more robustly than pip, it is the recommended way to install cryptography from source on Termux.


Sister Project:

CLI: Dworshak

GitHub: https://github.com/City-of-Memphis-Wastewater/dworshak

PyPI: https://pypi.org/project/dworshak/

pipx install dworshak

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dworshak_access-0.1.27.tar.gz (13.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dworshak_access-0.1.27-py3-none-any.whl (12.6 kB view details)

Uploaded Python 3

File details

Details for the file dworshak_access-0.1.27.tar.gz.

File metadata

  • Download URL: dworshak_access-0.1.27.tar.gz
  • Upload date:
  • Size: 13.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for dworshak_access-0.1.27.tar.gz
Algorithm Hash digest
SHA256 a65828448346d705aec02c39a44df452900c9c5f03e6ee48ab0a7905bdebf776
MD5 84f573147d30a10e451842eafca6f0b3
BLAKE2b-256 f5f00df4c10077f4616ed0800f849be1a7148a99e7d5442a7e49525faa93045d

See more details on using hashes here.

Provenance

The following attestation bundles were made for dworshak_access-0.1.27.tar.gz:

Publisher: publish.yml on City-of-Memphis-Wastewater/dworshak-access

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file dworshak_access-0.1.27-py3-none-any.whl.

File metadata

File hashes

Hashes for dworshak_access-0.1.27-py3-none-any.whl
Algorithm Hash digest
SHA256 8e48376f63d48c3feeefa0003aa3eb0845b61ccbd571a3abce0493bb9b018d72
MD5 242a69e4e8eb61adb863bf3071db9e1d
BLAKE2b-256 cfd034ec02b92bab3eb8dbab93b23a94708d400681cd61bd52941b678b2f3bed

See more details on using hashes here.

Provenance

The following attestation bundles were made for dworshak_access-0.1.27-py3-none-any.whl:

Publisher: publish.yml on City-of-Memphis-Wastewater/dworshak-access

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page