bellaPrivateKeyFromEnvValue function
Parses the value of BELLA_BAXTER_PRIVATE_KEY into PKCS#8 DER bytes.
Accepts a PKCS#8 PEM (what bella sdk run injects) or bare base64 PKCS#8
DER: the -----…----- armour and all whitespace (including CRLF) are
stripped before decoding, the same rule the JS, Java and .NET SDKs apply.
Returns null when value is null or blank — no device key is configured,
and the client generates an ephemeral key as it always has.
Throws a StateError naming BELLA_BAXTER_PRIVATE_KEY when a key IS
present but cannot be read as a P-256 private key. It never falls back to an
ephemeral key in that case (#989): silently presenting a key nobody
registered makes every read fail later with a 403 whose cause is invisible
from inside the application.
Implementation
Uint8List? bellaPrivateKeyFromEnvValue(String? value) {
if (value == null || value.trim().isEmpty) return null;
final body = value.replaceAll(RegExp(r'-----[A-Z ]+-----|\s'), '');
try {
final der = base64Decode(body);
// Parse it now, so a bad key fails here rather than on the first request.
e2eeKeyPairFromPkcs8(der);
return der;
} catch (_) {
throw StateError(
'BELLA_BAXTER_PRIVATE_KEY is set but is not a readable PKCS#8 P-256 '
'private key (PEM or base64 DER expected). Refusing to continue with a '
'throwaway key instead of your device key.\n'
' Unset it, or re-run: bella auth setup',
);
}
}