SecretValueStates
Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets
Pure classification of Secret values into SecretValueState (decisions 2026-10-06, item 2). ISecretAttributeProtector.GetReadState(RtSecretValue, SecretAccessContext) uses it with the key ring of the process; callers without a protector pass the set of known key ids (or no key ring at all, see SecretValueStates.GetReadState(RtSecretValue, Func<String, Boolean>, Boolean)).
public static class SecretValueStates
Inheritance Object → SecretValueStates
Fields
LegacyV1KeyId
Key id reported for a legacy enc:v1 string when the legacy key
(SecretEncryption:LegacyV1Key) is not configured: such a value is classified as
SecretValueState.KeyMissing / SecretStorageForm.KeyMissing with this key id
(inventory, sweep Unreadable entries and per-key-id counts). It is not a valid key-ring key id
(it contains a colon), so it never collides with a real one.
public static string LegacyV1KeyId;
Methods
GetReadState(RtSecretValue, Func<String, Boolean>)
Classifies a stored or pending Secret value. Never decrypts.
public static SecretValueState GetReadState(RtSecretValue value, Func<string, bool> isKnownKeyId)
Parameters
value RtSecretValue
The value; null = not set
isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring. null = the caller has no key ring (e.g. the octo-sdk
DTO mapper without a protector): every protected value then counts as SecretValueState.Set
and SecretValueState.KeyMissing is never returned - such a caller must report
"key missing" as unknown (null), not as false.
Returns
SecretValueState
The state
Remarks:
ValueState
null
protected, key id in the ring
protected, key id NOT in the ring
pending (input)
SecretValueState.Set when non-empty - a placeholder-looking input is an ordinary value
legacy string: empty or legacy placeholder
SecretValueState.NotSet (normalised once by the migration)
legacy string: enc:v2 envelope
SecretValueState.NotSet - corrupt (SecretValueStates.IsCorrupt(RtSecretValue)), never decrypted
legacy string: other (clear text, enc:v1)
SecretValueState.Set (an enc:v1 string is SecretValueState.KeyMissing through the overload with legacyV1KeyConfigured = false)
GetReadState(RtSecretValue, Func<String, Boolean>, Boolean)
Like SecretValueStates.GetReadState(RtSecretValue, Func<String, Boolean>, Boolean), plus whether the legacy
enc:v1 key is configured: when legacyV1KeyConfigured is false, a legacy
enc:v1 string is SecretValueState.KeyMissing (stored, cannot be read on this host,
key id SecretValueStates.LegacyV1KeyId) instead of SecretValueState.Set (AB#5532).
public static SecretValueState GetReadState(RtSecretValue value, Func<string, bool> isKnownKeyId, bool legacyV1KeyConfigured)
Parameters
value RtSecretValue
The value; null = not set
isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring
legacyV1KeyConfigured Boolean
True when the legacy enc:v1 key is configured
Returns
SecretValueState
The state
Describe(RtSecretValue, Func<String, Boolean>)
Describes a value - read state, storage form, key id and "set at" - without decrypting it. Same
rules and the same isKnownKeyId contract as
SecretValueStates.GetReadState(RtSecretValue, Func<String, Boolean>, Boolean); without a key ring a protected value
is SecretStorageForm.EncV2.
public static SecretReadInfo Describe(RtSecretValue value, Func<string, bool> isKnownKeyId)
Parameters
value RtSecretValue
The value; null = not set
isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring
Returns
SecretReadInfo
The description
Describe(RtSecretValue, Func<String, Boolean>, Boolean)
Like SecretValueStates.Describe(RtSecretValue, Func<String, Boolean>, Boolean), plus whether the legacy enc:v1
key is configured: without it a legacy enc:v1 string is described as
SecretValueState.KeyMissing / SecretStorageForm.KeyMissing with key id
SecretValueStates.LegacyV1KeyId (AB#5532).
public static SecretReadInfo Describe(RtSecretValue value, Func<string, bool> isKnownKeyId, bool legacyV1KeyConfigured)
Parameters
value RtSecretValue
The value; null = not set
isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring
legacyV1KeyConfigured Boolean
True when the legacy enc:v1 key is configured
Returns
SecretReadInfo
The description
GetReadState(RtSecretValue, IEnumerable<String>)
Classifies with an explicit set of known key ids (compared case-insensitively like the key ring).
public static SecretValueState GetReadState(RtSecretValue value, IEnumerable<string> knownKeyIds)
Parameters
value RtSecretValue
The value
knownKeyIds IEnumerable<String>
Key ids of the key ring
Returns
SecretValueState
The state
IsCorrupt(RtSecretValue)
True for a value that is stored but can never be read: an enc:v2 envelope found as a legacy
string (AB#5532 - nothing legitimate writes one; it was copied there). Readers treat it as not set.
public static bool IsCorrupt(RtSecretValue value)
Parameters
value RtSecretValue
The value
Returns
Boolean
True when corrupt