SecretAttributeConventions
Namespace: Meshmakers.Octo.ConstructionKit.Contracts
Shared conventions of the AttributeValueTypesDto.Secret value type (AB#5528,
docs/concept-secret-attribute-type.md). One place for the rules that the compiler, the
blueprint seed lint and the runtime write path (AB#5532) must agree on.
public static class SecretAttributeConventions
Inheritance Object → SecretAttributeConventions
Fields
MinimumSystemVersion
The first System model version whose engine understands the Secret value type
(decision 12). A model that uses Secret must depend on System >= 2.5, so an
engine that does not know the value type fails with a dependency error instead of
misreading the attribute.
public static CkVersion MinimumSystemVersion;
AllowedRecordKeyValueTypes
Value types a record key (CkRecordDto.RecordKey) may have: scalar values that identify an element and compare by value.
public static IReadOnlyCollection<AttributeValueTypesDto> AllowedRecordKeyValueTypes;
SystemModelName
Name of the system construction kit model.
public static string SystemModelName;
TodoSetPlaceholderPrefix
Prefix of the TODO_SET_<UPPER_SNAKE> legacy placeholder form (see
SecretAttributeConventions.IsTodoSetPlaceholder(String)).
public static string TodoSetPlaceholderPrefix;
Methods
IsLegacyPlaceholder(String)
MIGRATION ONLY (decisions 2026-10-06, item 1): true when a LEGACY value - a string found in a Secret slot in storage, written before the slot became a Secret - is exactly a placeholder in one of the two forms that blueprints and apps used before the Secret value type:
a non-empty text enclosed in exactly one pair of angle brackets such as
<set-after-install> (SecretAttributeConventions.IsAngleBracketPlaceholder(String));
TODO_SET_<UPPER_SNAKE> such as TODO_SET_CLIENT_SECRET
(SecretAttributeConventions.IsTodoSetPlaceholder(String)).
Leading and trailing whitespace is ignored. Such a legacy value is converted once to "not set" (the encrypt sweep, the CK migration hook, and the write step when it meets a stored legacy string, e.g. on carry-over) and counted as a normalised placeholder.
Placeholders have NO meaning anywhere else: a <...> or TODO_SET_... string
sent through any API is an ordinary value and is encrypted like any other, and blueprint seeds
may not carry one in a Secret slot (SecretAttributeConventions.IsAllowedSeedValue(String)). Never call this for
input values.
public static bool IsLegacyPlaceholder(string value)
Parameters
value String
The legacy stored text
Returns
Boolean
True for a legacy placeholder
IsAngleBracketPlaceholder(String)
True when value is a non-empty text enclosed in exactly one pair of angle
brackets, e.g. <set-after-install>. <>, <a><b> and
<<x>> are not placeholders.
public static bool IsAngleBracketPlaceholder(string value)
Parameters
value String
The value to check
Returns
Boolean
True for an angle-bracket placeholder
Remarks:
Migration only, see SecretAttributeConventions.IsLegacyPlaceholder(String).
IsTodoSetPlaceholder(String)
True when value is TODO_SET_ followed by one or more
upper-case snake-case words: [A-Z0-9]+(_[A-Z0-9]+)*, e.g. TODO_SET_PASSWORD
or TODO_SET_AZURE_TENANT_ID. The bare prefix, lower-case letters, a trailing or
doubled underscore and any other character make it a regular value.
public static bool IsTodoSetPlaceholder(string value)
Parameters
value String
The value to check
Returns
Boolean
True for a TODO_SET_ placeholder
Remarks:
Migration only, see SecretAttributeConventions.IsLegacyPlaceholder(String).
IsAllowedSeedValue(String)
True when a blueprint seed may carry value for a Secret attribute: only
null or an empty or whitespace-only string (decisions 2026-10-06, item 1). A placeholder
(<...>, TODO_SET_...) is a value and therefore not allowed.
public static bool IsAllowedSeedValue(string value)
Parameters
value String
The seed value
Returns
Boolean
True when the value is allowed in a seed