SecretEnvelope
Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets
Strict structural parsing of secret envelopes (AB#5528, concept §3.4). No key material is needed; a successful parse does not mean the value decrypts.
public static class SecretEnvelope
Inheritance Object → SecretEnvelope
Remarks:
enc:v2:<kid>:<base64url(nonce[12] ‖ tag[16] ‖ ciphertext)> - the kid is
1-32 characters of [A-Za-z0-9_-], the payload is unpadded base64url and decodes to
at least 28 bytes.
enc:v1:<base64(nonce[12] ‖ tag[16] ‖ ciphertext)> - the legacy
InstanceSecretCrypto format of octo-sdk, standard base64 with padding.
Anything else is not an envelope - including a clear-text password that happens to start
with enc:, which InstanceSecretCrypto.IsEncrypted would have misread.
Fields
PrefixV2
Prefix of the current envelope format.
public static string PrefixV2;
PrefixV1
Prefix of the legacy envelope format (octo-sdk InstanceSecretCrypto).
public static string PrefixV1;
CurrentVersion
The version written by ISecretAttributeProtector.Protect(String).
public static int CurrentVersion;
NonceLength
AES-GCM nonce length in bytes.
public static int NonceLength;
TagLength
AES-GCM tag length in bytes.
public static int TagLength;
MaxKeyIdLength
Maximum length of a key id.
public static int MaxKeyIdLength;
Methods
IsValidKeyId(String)
True when keyId is a valid key id (1-32 characters of
[A-Za-z0-9_-]; in particular no :).
public static bool IsValidKeyId(string keyId)
Parameters
keyId String
Returns
BuildHeaderV2(String)
Builds the header of a version 2 envelope, which is also the AES-GCM associated data.
public static string BuildHeaderV2(string keyId)
Parameters
keyId String
Returns
IsEnvelope(String)
True when value is a structurally valid v1 or v2 envelope.
public static bool IsEnvelope(string value)
Parameters
value String
Returns
TryParse(String, out SecretEnvelopeInfo)
Parses an envelope strictly.
public static bool TryParse(string value, out SecretEnvelopeInfo info)
Parameters
value String
The candidate value
info SecretEnvelopeInfo
Version and key id on success
Returns
Boolean
True for a structurally valid envelope
TryParse(String, out SecretEnvelopeInfo, out String, out Byte[])
Parses an envelope strictly and returns its decoded payload and header.
public static bool TryParse(string value, out SecretEnvelopeInfo info, out String header, out Byte[] payload)
Parameters
value String
The candidate value
info SecretEnvelopeInfo
Version and key id on success
header String
The header (associated data for v2; the v1 prefix for v1)
payload Byte[]
The decoded nonce ‖ tag ‖ ciphertext bytes
Returns
Boolean
True for a structurally valid envelope