SecretAttributeExtensions
Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets
Server-side access to the plaintext of a Secret attribute (concept §3.7). Every call is a counted decrypt; keep callers on the architecture-test allowlist.
public static class SecretAttributeExtensions
Inheritance Object → SecretAttributeExtensions
Methods
GetSecretPlaintext(RtTypeWithAttributes, String, ISecretAttributeProtector, String)
Returns the plaintext of the Secret attribute attributeName, or
null when it is not set. A stored value that cannot be read (unknown key id, corrupt) is
treated as not set and returns null as well; the protector logs an error without the value
(ISecretAttributeProtector.RevealOrNull(RtSecretValue, SecretAccessContext), decisions 2026-10-06 item 2).
public static string GetSecretPlaintext(RtTypeWithAttributes entity, string attributeName, ISecretAttributeProtector protector, string tenantId)
Parameters
entity RtTypeWithAttributes
Entity or record holding the attribute
attributeName String
Attribute name in PascalCase
protector ISecretAttributeProtector
The protector
tenantId String
Tenant id for the decrypt counter (optional)
Returns
String
The plaintext or null
GetSecretReadState(RtTypeWithAttributes, String, ISecretAttributeProtector, String)
Returns the read state of the Secret attribute attributeName without decrypting
it (ISecretAttributeProtector.GetReadState(RtSecretValue, SecretAccessContext)).
public static SecretValueState GetSecretReadState(RtTypeWithAttributes entity, string attributeName, ISecretAttributeProtector protector, string tenantId)
Parameters
entity RtTypeWithAttributes
Entity or record holding the attribute
attributeName String
Attribute name in PascalCase
protector ISecretAttributeProtector
The protector
tenantId String
Tenant id for log and counter tags (optional)
Returns
SecretValueState
The read state
DescribeSecret(RtTypeWithAttributes, String, ISecretAttributeProtector, String)
Describes the Secret attribute attributeName - read state, storage form, key id,
"set at" - without decrypting it (ISecretAttributeProtector.DescribeSecret(RtSecretValue, SecretAccessContext)).
public static SecretReadInfo DescribeSecret(RtTypeWithAttributes entity, string attributeName, ISecretAttributeProtector protector, string tenantId)
Parameters
entity RtTypeWithAttributes
Entity or record holding the attribute
attributeName String
Attribute name in PascalCase
protector ISecretAttributeProtector
The protector
tenantId String
Tenant id for log and counter tags (optional)
Returns
SecretReadInfo
The description