Zum Hauptinhalt springen

SecretEnvelope

Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets

Strict structural parsing of secret envelopes (AB#5528, concept §3.4). No key material is needed; a successful parse does not mean the value decrypts.

public static class SecretEnvelope

Inheritance Object → SecretEnvelope

Remarks:

enc:v2:<kid>:<base64url(nonce[12] ‖ tag[16] ‖ ciphertext)> - the kid is 1-32 characters of [A-Za-z0-9_-], the payload is unpadded base64url and decodes to at least 28 bytes.

enc:v1:<base64(nonce[12] ‖ tag[16] ‖ ciphertext)> - the legacy InstanceSecretCrypto format of octo-sdk, standard base64 with padding.

Anything else is not an envelope - including a clear-text password that happens to start with enc:, which InstanceSecretCrypto.IsEncrypted would have misread.

Fields​

PrefixV2​

Prefix of the current envelope format.

public static string PrefixV2;

PrefixV1​

Prefix of the legacy envelope format (octo-sdk InstanceSecretCrypto).

public static string PrefixV1;

CurrentVersion​

The version written by ISecretAttributeProtector.Protect(String).

public static int CurrentVersion;

NonceLength​

AES-GCM nonce length in bytes.

public static int NonceLength;

TagLength​

AES-GCM tag length in bytes.

public static int TagLength;

MaxKeyIdLength​

Maximum length of a key id.

public static int MaxKeyIdLength;

Methods​

IsValidKeyId(String)​

True when keyId is a valid key id (1-32 characters of [A-Za-z0-9_-]; in particular no :).

public static bool IsValidKeyId(string keyId)

Parameters​

keyId String

Returns​

Boolean

BuildHeaderV2(String)​

Builds the header of a version 2 envelope, which is also the AES-GCM associated data.

public static string BuildHeaderV2(string keyId)

Parameters​

keyId String

Returns​

String

IsEnvelope(String)​

True when value is a structurally valid v1 or v2 envelope.

public static bool IsEnvelope(string value)

Parameters​

value String

Returns​

Boolean

TryParse(String, out SecretEnvelopeInfo)​

Parses an envelope strictly.

public static bool TryParse(string value, out SecretEnvelopeInfo info)

Parameters​

value String
The candidate value

info SecretEnvelopeInfo
Version and key id on success

Returns​

Boolean
True for a structurally valid envelope

TryParse(String, out SecretEnvelopeInfo, out String, out Byte[])​

Parses an envelope strictly and returns its decoded payload and header.

public static bool TryParse(string value, out SecretEnvelopeInfo info, out String header, out Byte[] payload)

Parameters​

value String
The candidate value

info SecretEnvelopeInfo
Version and key id on success

header String
The header (associated data for v2; the v1 prefix for v1)

payload Byte[]
The decoded nonce ‖ tag ‖ ciphertext bytes

Returns​

Boolean
True for a structurally valid envelope