| | | 1 | | namespace Elsa.Secrets.Stores; |
| | | 2 | | |
| | 31 | 3 | | public class EncryptedSecretStore(ISecretValueProtector protector) : ISecretStore |
| | | 4 | | { |
| | | 5 | | private const string ProtectedValueKey = "protectedValue"; |
| | | 6 | | |
| | 79 | 7 | | public string Name => SecretStoreNames.Encrypted; |
| | | 8 | | |
| | 60 | 9 | | public SecretStoreDescriptor Descriptor { get; } = new( |
| | 31 | 10 | | SecretStoreNames.Encrypted, |
| | 31 | 11 | | "Elsa Encrypted Store", |
| | 31 | 12 | | "Stores values in Elsa-managed encrypted payloads.", |
| | 31 | 13 | | SecretStoreCapabilities.Read | SecretStoreCapabilities.Write | SecretStoreCapabilities.Delete | SecretStoreCapab |
| | 31 | 14 | | false); |
| | | 15 | | |
| | | 16 | | public Task<SecretPayload> WriteAsync(Secret secret, SecretVersion version, SecretPayload payload, CancellationToken |
| | | 17 | | { |
| | 26 | 18 | | if (payload.Value == null) |
| | 0 | 19 | | throw new InvalidOperationException("A value is required for encrypted secrets."); |
| | | 20 | | |
| | 26 | 21 | | var protectedPayload = new SecretPayload(); |
| | 26 | 22 | | protectedPayload.Metadata[ProtectedValueKey] = protector.Protect(payload.Value); |
| | | 23 | | |
| | 55 | 24 | | foreach (var item in payload.Metadata.Where(x => !string.Equals(x.Key, ProtectedValueKey, StringComparison.Ordin |
| | 1 | 25 | | protectedPayload.Metadata[item.Key] = item.Value; |
| | | 26 | | |
| | 26 | 27 | | return Task.FromResult(protectedPayload); |
| | | 28 | | } |
| | | 29 | | |
| | | 30 | | public Task<SecretPayload?> ReadAsync(Secret secret, SecretVersion version, CancellationToken cancellationToken = de |
| | | 31 | | { |
| | 3 | 32 | | if (!version.Payload.Metadata.TryGetValue(ProtectedValueKey, out var protectedValue)) |
| | 0 | 33 | | return Task.FromResult<SecretPayload?>(null); |
| | | 34 | | |
| | 3 | 35 | | return Task.FromResult<SecretPayload?>(SecretPayload.FromValue(protector.Unprotect(protectedValue))); |
| | | 36 | | } |
| | | 37 | | |
| | | 38 | | public Task DeleteAsync(Secret secret, CancellationToken cancellationToken = default) |
| | | 39 | | { |
| | 12 | 40 | | foreach (var version in secret.Versions) |
| | 3 | 41 | | version.Payload.Metadata.Remove(ProtectedValueKey); |
| | | 42 | | |
| | 3 | 43 | | return Task.CompletedTask; |
| | | 44 | | } |
| | | 45 | | |
| | | 46 | | public async Task<bool> TestAsync(Secret secret, SecretVersion version, CancellationToken cancellationToken = defaul |
| | | 47 | | { |
| | 1 | 48 | | var payload = await ReadAsync(secret, version, cancellationToken); |
| | 0 | 49 | | return payload?.Value != null; |
| | 0 | 50 | | } |
| | | 51 | | } |