Skip to main content

SecretValueStates

Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets

Pure classification of Secret values into SecretValueState (decisions 2026-10-06, item 2). ISecretAttributeProtector.GetReadState(RtSecretValue, SecretAccessContext) uses it with the key ring of the process; callers without a protector pass the set of known key ids (or no key ring at all, see SecretValueStates.GetReadState(RtSecretValue, Func<String, Boolean>, Boolean)).

public static class SecretValueStates

Inheritance Object → SecretValueStates

Fields​

LegacyV1KeyId​

Key id reported for a legacy enc:v1 string when the legacy key (SecretEncryption:LegacyV1Key) is not configured: such a value is classified as SecretValueState.KeyMissing / SecretStorageForm.KeyMissing with this key id (inventory, sweep Unreadable entries and per-key-id counts). It is not a valid key-ring key id (it contains a colon), so it never collides with a real one.

public static string LegacyV1KeyId;

Methods​

GetReadState(RtSecretValue, Func<String, Boolean>)​

Classifies a stored or pending Secret value. Never decrypts.

public static SecretValueState GetReadState(RtSecretValue value, Func<string, bool> isKnownKeyId)

Parameters​

value RtSecretValue
The value; null = not set

isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring. null = the caller has no key ring (e.g. the octo-sdk DTO mapper without a protector): every protected value then counts as SecretValueState.Set and SecretValueState.KeyMissing is never returned - such a caller must report "key missing" as unknown (null), not as false.

Returns​

SecretValueState
The state

Remarks:

ValueState

null

SecretValueState.NotSet

protected, key id in the ring

SecretValueState.Set

protected, key id NOT in the ring

SecretValueState.KeyMissing

pending (input)

SecretValueState.Set when non-empty - a placeholder-looking input is an ordinary value

legacy string: empty or legacy placeholder

SecretValueState.NotSet (normalised once by the migration)

legacy string: enc:v2 envelope

SecretValueState.NotSet - corrupt (SecretValueStates.IsCorrupt(RtSecretValue)), never decrypted

legacy string: other (clear text, enc:v1)

SecretValueState.Set (an enc:v1 string is SecretValueState.KeyMissing through the overload with legacyV1KeyConfigured = false)

GetReadState(RtSecretValue, Func<String, Boolean>, Boolean)​

Like SecretValueStates.GetReadState(RtSecretValue, Func<String, Boolean>, Boolean), plus whether the legacy enc:v1 key is configured: when legacyV1KeyConfigured is false, a legacy enc:v1 string is SecretValueState.KeyMissing (stored, cannot be read on this host, key id SecretValueStates.LegacyV1KeyId) instead of SecretValueState.Set (AB#5532).

public static SecretValueState GetReadState(RtSecretValue value, Func<string, bool> isKnownKeyId, bool legacyV1KeyConfigured)

Parameters​

value RtSecretValue
The value; null = not set

isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring

legacyV1KeyConfigured Boolean
True when the legacy enc:v1 key is configured

Returns​

SecretValueState
The state

Describe(RtSecretValue, Func<String, Boolean>)​

Describes a value - read state, storage form, key id and "set at" - without decrypting it. Same rules and the same isKnownKeyId contract as SecretValueStates.GetReadState(RtSecretValue, Func<String, Boolean>, Boolean); without a key ring a protected value is SecretStorageForm.EncV2.

public static SecretReadInfo Describe(RtSecretValue value, Func<string, bool> isKnownKeyId)

Parameters​

value RtSecretValue
The value; null = not set

isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring

Returns​

SecretReadInfo
The description

Describe(RtSecretValue, Func<String, Boolean>, Boolean)​

Like SecretValueStates.Describe(RtSecretValue, Func<String, Boolean>, Boolean), plus whether the legacy enc:v1 key is configured: without it a legacy enc:v1 string is described as SecretValueState.KeyMissing / SecretStorageForm.KeyMissing with key id SecretValueStates.LegacyV1KeyId (AB#5532).

public static SecretReadInfo Describe(RtSecretValue value, Func<string, bool> isKnownKeyId, bool legacyV1KeyConfigured)

Parameters​

value RtSecretValue
The value; null = not set

isKnownKeyId Func<String, Boolean>
True when a key id is in the key ring; null = no key ring

legacyV1KeyConfigured Boolean
True when the legacy enc:v1 key is configured

Returns​

SecretReadInfo
The description

GetReadState(RtSecretValue, IEnumerable<String>)​

Classifies with an explicit set of known key ids (compared case-insensitively like the key ring).

public static SecretValueState GetReadState(RtSecretValue value, IEnumerable<string> knownKeyIds)

Parameters​

value RtSecretValue
The value

knownKeyIds IEnumerable<String>
Key ids of the key ring

Returns​

SecretValueState
The state

IsCorrupt(RtSecretValue)​

True for a value that is stored but can never be read: an enc:v2 envelope found as a legacy string (AB#5532 - nothing legitimate writes one; it was copied there). Readers treat it as not set.

public static bool IsCorrupt(RtSecretValue value)

Parameters​

value RtSecretValue
The value

Returns​

Boolean
True when corrupt