SecretSweepModeDto
Namespace: Meshmakers.Octo.Communication.Contracts.DataTransferObjects
Mode of a secret sweep (AB#5528 §5.2, bot-services AB#5539). Mirrors the engine's
SecretSweepMode (same names and numbers); serialized by name.
public enum SecretSweepModeDto
Inheritance Object → ValueType → Enum → SecretSweepModeDto
Implements IComparable, ISpanFormattable, IFormattable, IConvertible
Fields
| Name | Value | Description |
|---|---|---|
| Verify | 0 | Count the stored forms only; writes nothing. |
| Encrypt | 1 | Encrypt legacy clear text and enc:v1 values with the active key. |
| Reprotect | 2 | Re-encrypt every value that is not under the active key id (key rotation). |
| CleanupUnreadable | 3 | Delete values whose key id is not in the key ring (unreadable, typically after a restore from another environment). Irreversible except via the pre-sweep dump; requires confirm=true and the SecretManagement role. Every other mode keeps such values and lists them as re-entry tasks (SecretSweepReportDto.Unreadable). Replaces the former ClearUnknownKid (same number). |
| Decrypt | 4 | Emergency decryption back to clear text. Never offered through the bot API (the service answers 400, the client refuses it up front); listed only so reports stay readable. |