RtSecretValue
Namespace: Meshmakers.Octo.Runtime.Contracts.RepositoryEntities
In-memory value of a Secret attribute (AB#5528, concept §3.3). It never hands out
its plaintext: RtSecretValue.ToString() returns ***, and the plaintext of a
RtSecretValueState.Pending or RtSecretValueState.LegacyPlaintext
value is only reachable through ISecretAttributeProtector (internal access).
public sealed class RtSecretValue : IEquatable<RtSecretValue>
Inheritance Object → RtSecretValue
Implements IEquatable<RtSecretValue>
Remarks:
Equality: two protected values are equal when their envelopes are equal (the same ciphertext, i.e. the value was carried over and not re-entered). Pending and legacy values compare by state and value. The hash code never derives from plaintext.
Fields
Mask
Text returned by RtSecretValue.ToString() - never the value.
public static string Mask;
Properties
SetAt
When the value of a RtSecretValueState.Protected secret was set (UTC), i.e. when new
input was protected (concept §2.1 / handover §7, "set at"). null for every other state, for
values converted from legacy storage (encrypt sweep, write step on a stored legacy string) and for
values stored before the timestamp existed. Carry-over, re-protect (key rotation), restore and the
sweeps keep it unchanged. Metadata only: it is not part of RtSecretValue.Equals(RtSecretValue) (the
envelope identifies the value) and not part of the serialised marker. Stored by the repository next
to the envelope (MongoDB: BSON field t).
public Nullable<DateTime> SetAt { get; }
Property Value
State
State of the value.
public RtSecretValueState State { get; }
Property Value
IsPending
True for RtSecretValueState.Pending.
public bool IsPending { get; }
Property Value
IsProtected
True for RtSecretValueState.Protected.
public bool IsProtected { get; }
Property Value
IsLegacyPlaintext
True for RtSecretValueState.LegacyPlaintext.
public bool IsLegacyPlaintext { get; }
Property Value
Envelope
The envelope of a protected value (ciphertext, safe to store and copy between
repositories of the same key ring); null for every other state.
public string Envelope { get; }
Property Value
KeyId
The key id of a protected value; null for every other state.
public string KeyId { get; }
Property Value
Methods
Pending(String)
Creates a pending value from a plaintext received on a write path.
public static RtSecretValue Pending(string plaintext)
Parameters
plaintext String
The plaintext
Returns
RtSecretValue
A pending value
Protected(String)
Creates a protected value from an enc:v2 envelope (e.g. read from the database).
public static RtSecretValue Protected(string envelope)
Parameters
envelope String
The envelope
Returns
RtSecretValue
A protected value
Exceptions
ArgumentException
The string is not a structurally valid enc:v2 envelope
Protected(String, Nullable<DateTime>)
Creates a protected value from an enc:v2 envelope with its "set at" timestamp
(RtSecretValue.SetAt, e.g. read from the database).
public static RtSecretValue Protected(string envelope, Nullable<DateTime> setAt)
Parameters
envelope String
The envelope
setAt Nullable<DateTime>
When the value was set; converted to UTC (an unspecified kind is taken as UTC)
Returns
RtSecretValue
A protected value
Exceptions
ArgumentException
The string is not a structurally valid enc:v2 envelope
WithSetAt(Nullable<DateTime>)
Returns this protected value with another RtSecretValue.SetAt (same envelope).
public RtSecretValue WithSetAt(Nullable<DateTime> setAt)
Parameters
setAt Nullable<DateTime>
The timestamp; converted to UTC
Returns
RtSecretValue
A protected value
Exceptions
InvalidOperationException
The value is not protected
LegacyPlaintext(String)
Creates a legacy value from a string found in a Secret slot (clear text or enc:v1).
public static RtSecretValue LegacyPlaintext(string value)
Parameters
value String
The stored string
Returns
RtSecretValue
A legacy value
ToString()
public string ToString()
Returns
Equals(RtSecretValue)
public bool Equals(RtSecretValue other)
Parameters
other RtSecretValue
Returns
Equals(Object)
public bool Equals(object obj)
Parameters
obj Object
Returns
GetHashCode()
public int GetHashCode()