SecretValueForm
Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets
Stored form of a Secret value as the sweep classifies it.
public enum SecretValueForm
Inheritance Object → ValueType → Enum → SecretValueForm
Implements IComparable, ISpanFormattable, IFormattable, IConvertible
Fields
| Name | Value | Description |
|---|---|---|
| NotSet | 0 | No value (null or missing). |
| Placeholder | 1 | A legacy string slot holding exactly a legacy placeholder () or "" - "not set", normalised to null once by SecretSweepMode.Encrypt and the CK migration hook. Protected values are never classified as placeholders, whatever they decrypt to. |
| Plaintext | 2 | A legacy string slot holding clear text. |
| EncV1 | 3 | A legacy string slot holding an enc:v1: envelope (octo-sdk InstanceSecretCrypto). |
| EncV2 | 4 | An enc:v2:<kid>: envelope whose key id is in the key ring. |
| UnknownKeyId | 5 | An enc:v2:<kid>: envelope whose key id is NOT in the key ring - kept, reads as "key missing" and is listed in SecretSweepResult.Unreadable. A legacy enc:v1 string on a host without the legacy key (SecretEncryption:LegacyV1Key) is classified the same way, with key id SecretValueStates.LegacyV1KeyId (AB#5532). SecretSweepMode.Verify classifies without any key material, so on a host without key ring every protected value and every enc:v1 string lands here. |