OctoSecretStateDto
Namespace: Meshmakers.Octo.Communication.Contracts.DataTransferObjects
Read-side state of a Secret attribute (AB#5528, concept §4.1): an API only ever tells
whether a secret is set, whether a stored value cannot be read because its key id is missing in
this environment's key ring, and when it was set - never the value. GraphQL type
OctoSecretState { isSet keyMissing setAt }; the JSON form is e.g. {"isSet":true}.
public sealed class OctoSecretStateDto
Inheritance Object → OctoSecretStateDto
Remarks:
Generated query DTOs (Sdk.SourceGeneration) expose Secret attributes as this type, so
code that read .Password as a string stops compiling instead of silently receiving
ciphertext. Writes use a plain string? on the mutation DTO and
MutationDto.ClearSecretAttributes to clear.
Properties
IsSet
True when the secret holds a value. Never carries the value itself.
public bool IsSet { get; set; }
Property Value
KeyMissing
True when a value is stored but cannot be read because its key id is not in this
environment's key ring (e.g. after a restore from another environment); OctoSecretStateDto.IsSet
is false then and the secret has to be entered again (decision 2026-10-06).
GraphQL field keyMissing. Not written when false, so the serialized form of a
readable or unset secret stays the marker {"isSet":…} that write paths accept as
"unchanged".
public bool KeyMissing { get; set; }
Property Value
SetAt
When the current value was set (UTC); null when not set or for values set before this
was recorded (legacy). GraphQL field setAt. Not written when null.
public Nullable<DateTime> SetAt { get; set; }
Property Value
Constructors
OctoSecretStateDto()
Creates a state that is not set (needed for deserialization).
public OctoSecretStateDto()
OctoSecretStateDto(Boolean)
Creates a state.
public OctoSecretStateDto(bool isSet)
Parameters
isSet Boolean
True when the secret holds a value
Methods
IsValueSet(Object)
Tells whether a runtime value found in a Secret attribute slot counts as set, classified without
a key ring (OctoSecretStateDto.Describe(Object, Func<String, Boolean>, Boolean) with null): a protected value, a non-empty pending
value and a legacy string (stored before the attribute became Secret) that is neither empty, a
legacy placeholder nor corrupt. null and "" are not set.
public static bool IsValueSet(object value)
Parameters
value Object
The raw attribute value
Returns
Boolean
True when set
FromValue(Object)
Builds the state of a runtime value found in a Secret attribute slot without key-ring knowledge:
OctoSecretStateDto.IsSet (see OctoSecretStateDto.IsValueSet(Object)) and OctoSecretStateDto.SetAt;
OctoSecretStateDto.KeyMissing stays false because it cannot be determined.
public static OctoSecretStateDto FromValue(object value)
Parameters
value Object
The raw attribute value
Returns
OctoSecretStateDto
The state; never the value
FromValue(Object, Func<String, Boolean>)
Builds the state of a runtime value found in a Secret attribute slot (AB#5534 round 2).
public static OctoSecretStateDto FromValue(object value, Func<string, bool> isKnownKeyId)
Parameters
value Object
The raw attribute value
isKnownKeyId Func<String, Boolean>
True when a key id is in the host's key ring (e.g. );
null = no key ring: protected values count as set and OctoSecretStateDto.KeyMissing stays false.
With a key ring, a protected value whose key id is unknown is isSet: false, keyMissing: true.
Returns
OctoSecretStateDto
The state; never the value
Describe(Object, Func<String, Boolean>)
Describes a raw runtime value found in a Secret attribute slot with the engine's classification (), never decrypting it. A plain string (a legacy value read without CK knowledge) is classified as legacy clear text; any other non-secret object counts as set.
public static SecretReadInfo Describe(object value, Func<string, bool> isKnownKeyId)
Parameters
value Object
The raw attribute value
isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring
Returns
SecretReadInfo
The description (state, form, key id, set-at)
Describe(Object, Func<String, Boolean>, Boolean)
Like OctoSecretStateDto.Describe(Object, Func<String, Boolean>, Boolean), plus whether the host's legacy enc:v1
key is configured (): without it a legacy
enc:v1 string is isSet: false, keyMissing: true with key id
, as in GraphQL and the secrets overview (AB#5532).
public static SecretReadInfo Describe(object value, Func<string, bool> isKnownKeyId, bool legacyV1KeyConfigured)
Parameters
value Object
The raw attribute value
isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring
legacyV1KeyConfigured Boolean
True when the legacy enc:v1 key is configured
Returns
SecretReadInfo
The description (state, form, key id, set-at)
ToString()
public string ToString()