Zum Hauptinhalt springen

OctoSecretStateDto

Namespace: Meshmakers.Octo.Communication.Contracts.DataTransferObjects

Read-side state of a Secret attribute (AB#5528, concept §4.1): an API only ever tells whether a secret is set, whether a stored value cannot be read because its key id is missing in this environment's key ring, and when it was set - never the value. GraphQL type OctoSecretState { isSet keyMissing setAt }; the JSON form is e.g. {"isSet":true}.

public sealed class OctoSecretStateDto

Inheritance Object → OctoSecretStateDto

Remarks:

Generated query DTOs (Sdk.SourceGeneration) expose Secret attributes as this type, so code that read .Password as a string stops compiling instead of silently receiving ciphertext. Writes use a plain string? on the mutation DTO and MutationDto.ClearSecretAttributes to clear.

Properties​

IsSet​

True when the secret holds a value. Never carries the value itself.

public bool IsSet { get; set; }

Property Value​

Boolean

KeyMissing​

True when a value is stored but cannot be read because its key id is not in this environment's key ring (e.g. after a restore from another environment); OctoSecretStateDto.IsSet is false then and the secret has to be entered again (decision 2026-10-06). GraphQL field keyMissing. Not written when false, so the serialized form of a readable or unset secret stays the marker {"isSet":…} that write paths accept as "unchanged".

public bool KeyMissing { get; set; }

Property Value​

Boolean

SetAt​

When the current value was set (UTC); null when not set or for values set before this was recorded (legacy). GraphQL field setAt. Not written when null.

public Nullable<DateTime> SetAt { get; set; }

Property Value​

Nullable<DateTime>

Constructors​

OctoSecretStateDto()​

Creates a state that is not set (needed for deserialization).

public OctoSecretStateDto()

OctoSecretStateDto(Boolean)​

Creates a state.

public OctoSecretStateDto(bool isSet)

Parameters​

isSet Boolean
True when the secret holds a value

Methods​

IsValueSet(Object)​

Tells whether a runtime value found in a Secret attribute slot counts as set, classified without a key ring (OctoSecretStateDto.Describe(Object, Func<String, Boolean>, Boolean) with null): a protected value, a non-empty pending value and a legacy string (stored before the attribute became Secret) that is neither empty, a legacy placeholder nor corrupt. null and "" are not set.

public static bool IsValueSet(object value)

Parameters​

value Object
The raw attribute value

Returns​

Boolean
True when set

FromValue(Object)​

Builds the state of a runtime value found in a Secret attribute slot without key-ring knowledge: OctoSecretStateDto.IsSet (see OctoSecretStateDto.IsValueSet(Object)) and OctoSecretStateDto.SetAt; OctoSecretStateDto.KeyMissing stays false because it cannot be determined.

public static OctoSecretStateDto FromValue(object value)

Parameters​

value Object
The raw attribute value

Returns​

OctoSecretStateDto
The state; never the value

FromValue(Object, Func<String, Boolean>)​

Builds the state of a runtime value found in a Secret attribute slot (AB#5534 round 2).

public static OctoSecretStateDto FromValue(object value, Func<string, bool> isKnownKeyId)

Parameters​

value Object
The raw attribute value

isKnownKeyId Func<String, Boolean>
True when a key id is in the host's key ring (e.g. ); null = no key ring: protected values count as set and OctoSecretStateDto.KeyMissing stays false. With a key ring, a protected value whose key id is unknown is isSet: false, keyMissing: true.

Returns​

OctoSecretStateDto
The state; never the value

Describe(Object, Func<String, Boolean>)​

Describes a raw runtime value found in a Secret attribute slot with the engine's classification (), never decrypting it. A plain string (a legacy value read without CK knowledge) is classified as legacy clear text; any other non-secret object counts as set.

public static SecretReadInfo Describe(object value, Func<string, bool> isKnownKeyId)

Parameters​

value Object
The raw attribute value

isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring

Returns​

SecretReadInfo
The description (state, form, key id, set-at)

Describe(Object, Func<String, Boolean>, Boolean)​

Like OctoSecretStateDto.Describe(Object, Func<String, Boolean>, Boolean), plus whether the host's legacy enc:v1 key is configured (): without it a legacy enc:v1 string is isSet: false, keyMissing: true with key id , as in GraphQL and the secrets overview (AB#5532).

public static SecretReadInfo Describe(object value, Func<string, bool> isKnownKeyId, bool legacyV1KeyConfigured)

Parameters​

value Object
The raw attribute value

isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring

legacyV1KeyConfigured Boolean
True when the legacy enc:v1 key is configured

Returns​

SecretReadInfo
The description (state, form, key id, set-at)

ToString()​

public string ToString()

Returns​

String