PipelineSecretValues
Namespace: Meshmakers.Octo.Sdk.Common.EtlDataPipeline
How a Secret attribute value shows up in the data context, and the guard that type-switch nodes
(ConvertDataType@1, SetPrimitiveValue@1, If@1, Switch@1,
ExecuteCSharp@1, the adapter's DataMapping@1) use to refuse it explicitly (AB#5538).
public static class PipelineSecretValues
Inheritance Object → PipelineSecretValues
Remarks:
Entities enter the data context through the engine serialisers, which write a Secret value only as
the marker {"isSet": true|false} (RtSecretValueWireFormat) — never the plaintext and
never the envelope. A node therefore sees a Secret in one of two ways: as that marker object at the
path it reads, or as the configured value type . Before
AB#5538 the first surfaced as a generic "value is an object" / JSON conversion error and the second
fell into each node's default branch; both now raise
PipelineExecutionException.SecretNotSupported(NodePath, String).
With a registered read-state classifier (PipelineSecretValues.SetReadStateClassifier(Func<RtSecretValue, SecretReadInfo>), the mesh adapter
registers its key ring) a stored value whose key id is unknown reads as
{"isSet": false, "keyMissing": true}. Echoing any marker back into a write means "unchanged".
Reading the marker's isSet property ($.attributes.password.isSet as Boolean) stays
allowed — that is how a pipeline asks whether a secret is configured.
Properties
ReadStateClassifier
The process-wide classifier the pipeline serialiser uses to write a Secret marker that reflects
the read state (AB#5538); null when none is registered.
public static Func<RtSecretValue, SecretReadInfo> ReadStateClassifier { get; }
Property Value
Func<RtSecretValue, SecretReadInfo>
Methods
SetReadStateClassifier(Func<RtSecretValue, SecretReadInfo>)
Registers the classifier the pipeline serialiser (SystemTextJsonOptions) uses when it
writes a Secret value into the data context. A host with a key ring (the mesh adapter) passes
ISecretAttributeProtector.DescribeSecret, so a stored value whose key id is not in the ring is
written as {"isSet": false, "keyMissing": true} instead of the key-ring-less
{"isSet": true} of RtSecretValueWireFormat. Without a classifier the engine marker is
written unchanged.
public static void SetReadStateClassifier(Func<RtSecretValue, SecretReadInfo> classifier)
Parameters
classifier Func<RtSecretValue, SecretReadInfo>
The classifier, or null to remove it
Remarks:
The key ring is per process (the protector is a singleton), hence a process-wide registration: the serialiser options are static and shared by every data context.
ResetReadStateClassifier(Func<RtSecretValue, SecretReadInfo>)
Removes classifier if it is still the registered one (a later registration by
another host in the same process is kept).
public static void ResetReadStateClassifier(Func<RtSecretValue, SecretReadInfo> classifier)
Parameters
classifier Func<RtSecretValue, SecretReadInfo>
The classifier registered before
IsSecretMarker(JsonNode)
True when node is a Secret marker: an object with the boolean property
isSet and otherwise only the optional properties keyMissing (boolean) and
setAt (string or null). Property names are matched case-sensitively, as they are written.
public static bool IsSecretMarker(JsonNode node)
Parameters
node JsonNode
Returns
IsSecretMarker(IDataContext, String)
True when the value at path is a Secret marker (see
PipelineSecretValues.IsSecretMarker(JsonNode)). Cheap for anything that is not an object.
public static bool IsSecretMarker(IDataContext dataContext, string path)
Parameters
dataContext IDataContext
path String
Returns
ThrowIfSecretValueType(INodeContext, Nullable<AttributeValueTypesDto>, String)
Throws PipelineExecutionException.SecretNotSupported(NodePath, String) when
valueType is .
public static void ThrowIfSecretValueType(INodeContext nodeContext, Nullable<AttributeValueTypesDto> valueType, string settingName)
Parameters
nodeContext INodeContext
The node context, for the node path in the message
valueType Nullable<AttributeValueTypesDto>
The configured value type
settingName String
Name of the setting carrying the type, for the message
ThrowIfSecretMarker(INodeContext, IDataContext, String[])
Throws PipelineExecutionException.SecretNotSupported(NodePath, String) when one of
paths holds a Secret marker. Null or empty paths are skipped.
public static void ThrowIfSecretMarker(INodeContext nodeContext, IDataContext dataContext, String[] paths)
Parameters
nodeContext INodeContext
The node context, for the node path in the message
dataContext IDataContext
The data context
paths String[]
The data paths the node reads