AttributeOwnershipDto
Namespace: Meshmakers.Octo.ConstructionKit.Contracts.DataTransferObjects
Declares who owns the value of a CK attribute and whether that value is part of the
entity's portable definition. Replaces the isRuntimeState boolean, which conflated
the two questions (AB#5187).
public enum AttributeOwnershipDto
Inheritance Object → ValueType → Enum → AttributeOwnershipDto
Implements IComparable, ISpanFormattable, IFormattable, IConvertible
Remarks:
The boolean answered "preserve on upsert?" and "exclude from ExportRt?" with a
single bit. That works for a rotating refresh token (preserve, never export) and for a
product endpoint (overwrite, export), but not for tenant master data — a tariff, an
IBAN, a market-partner id, a logo — which must be preserved AND exported.
AttributeOwnershipDto.TenantOwned is the value that combination needs.
The value on the attribute definition is the default; a type-attribute or
record-attribute assignment may override it (CkTypeAttributeDto.Ownership),
so a shared definition like ClientId can be AttributeOwnershipDto.Secret on
FinApiConfiguration and AttributeOwnershipDto.SeedOwned on
ServiceAccountConfiguration.
Author decision matrix — answer the first question that applies and stop:
Is it a credential, token, key or password — anything you would not paste into a ticket? → AttributeOwnershipDto.Secret
Is it written by a service, operator, pipeline or job rather than typed by a human (status, timestamps, counters, error history, cursors, rotated tokens, deployed hostname/chart version, debug toggles)? → AttributeOwnershipDto.RuntimeState
Would a tenant admin set this in the product and be right to be angry if a product update overwrote it (tariffs, IBAN, market ids, their mailbox/host/port, logo, colours, app title)? → AttributeOwnershipDto.TenantOwned
Otherwise it ships with the product and a new version must be able to correct it (endpoints the product owns, report template names, statutory defaults, well-known-name wiring, taxonomy). → AttributeOwnershipDto.SeedOwned
Tie-breaker: if you cannot name how a correction would reach every tenant, choose
AttributeOwnershipDto.SeedOwned — that is the reversible mistake. Marked does not mean frozen:
a CK migration Update action is the sanctioned, versioned, auditable way to
correct a tenant-owned value across tenants.
Fields
| Name | Value | Description |
|---|---|---|
| SeedOwned | 0 | The blueprint / seed author owns the value. A re-apply overwrites the tenant's value and the value is carried in an ExportRt. This is the default and it is what an attribute without any marker has always done (isRuntimeState: false / absent). |
| TenantOwned | 1 | The tenant owns the value; the seed may only initialise it. A re-apply keeps the tenant's existing value, and the value IS carried in an ExportRt because it is part of the entity's portable definition. defaultValues still seed a fresh tenant — "seed-initialised, then tenant-owned" is exactly this value. Typical: tariffs, IBAN and account holder, market-partner ids, a tenant's mailbox / host / port, branding, app title, logos, colours. |
| RuntimeState | 2 | A service, operator, pipeline or job owns the value at runtime. A re-apply keeps the existing value and the value is excluded from an ExportRt — it is instance-local live state, not part of the portable definition. Equivalent to the legacy isRuntimeState: true. Typical: deployment/communication status, last-error pairs, sync cursors, execution and statistics history, debug toggles, chart version / hostname written by the operator. |
| Secret | 3 | A credential. A re-apply keeps the existing value and the value is excluded from an ExportRt. Behaves identically to AttributeOwnershipDto.RuntimeState today; it exists so the model can say what the value actually is — an API key is not "runtime state" — so a later export opt-in can re-include AttributeOwnershipDto.RuntimeState while never including a secret, and so a later redaction / external-vault feature has something to hang off. Typical: client secrets, API keys, bot tokens, passwords, private keys, refresh tokens. |