Zum Hauptinhalt springen

SecretAttributeExtensions

Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets

Server-side access to the plaintext of a Secret attribute (concept §3.7). Every call is a counted decrypt; keep callers on the architecture-test allowlist.

public static class SecretAttributeExtensions

Inheritance Object → SecretAttributeExtensions

Methods​

GetSecretPlaintext(RtTypeWithAttributes, String, ISecretAttributeProtector, String)​

Returns the plaintext of the Secret attribute attributeName, or null when it is not set. A stored value that cannot be read (unknown key id, corrupt) is treated as not set and returns null as well; the protector logs an error without the value (ISecretAttributeProtector.RevealOrNull(RtSecretValue, SecretAccessContext), decisions 2026-10-06 item 2).

public static string GetSecretPlaintext(RtTypeWithAttributes entity, string attributeName, ISecretAttributeProtector protector, string tenantId)

Parameters​

entity RtTypeWithAttributes
Entity or record holding the attribute

attributeName String
Attribute name in PascalCase

protector ISecretAttributeProtector
The protector

tenantId String
Tenant id for the decrypt counter (optional)

Returns​

String
The plaintext or null

GetSecretReadState(RtTypeWithAttributes, String, ISecretAttributeProtector, String)​

Returns the read state of the Secret attribute attributeName without decrypting it (ISecretAttributeProtector.GetReadState(RtSecretValue, SecretAccessContext)).

public static SecretValueState GetSecretReadState(RtTypeWithAttributes entity, string attributeName, ISecretAttributeProtector protector, string tenantId)

Parameters​

entity RtTypeWithAttributes
Entity or record holding the attribute

attributeName String
Attribute name in PascalCase

protector ISecretAttributeProtector
The protector

tenantId String
Tenant id for log and counter tags (optional)

Returns​

SecretValueState
The read state

DescribeSecret(RtTypeWithAttributes, String, ISecretAttributeProtector, String)​

Describes the Secret attribute attributeName - read state, storage form, key id, "set at" - without decrypting it (ISecretAttributeProtector.DescribeSecret(RtSecretValue, SecretAccessContext)).

public static SecretReadInfo DescribeSecret(RtTypeWithAttributes entity, string attributeName, ISecretAttributeProtector protector, string tenantId)

Parameters​

entity RtTypeWithAttributes
Entity or record holding the attribute

attributeName String
Attribute name in PascalCase

protector ISecretAttributeProtector
The protector

tenantId String
Tenant id for log and counter tags (optional)

Returns​

SecretReadInfo
The description