Skip to content

(WIP) Add a "description" field to each stored secret - #164

Closed
creachadair wants to merge 17 commits into
mainfrom
mjf/description
Closed

creachadair wants to merge 17 commits into
mainfrom
mjf/description

Conversation

@creachadair

Copy link
Copy Markdown
Member

This builds on #163 and requires it to be merged first.

There are multiple commits here that can be reviewed separately, and the branch
is currently based on the #163 branch, but I intend to rebase it on main before
requesting a real review.

NOT READY -- DO NOT MERGE

Comment thread types/api/api.go

// MaxDescriptionBytes is the maximum permitted length of a secret description.
// Descriptions in excess of this length will be rejected.
const MaxDescriptionBytes = 1000

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rationale: About 12 lines or 200 words of English text, should be enough for anybody.

This is preparation for adding a Reader type in the next commit.
Update usage throughout.
This allows a caller to read back through the contents of an audit log.
The Reader exposes a basic iterator interface.
This field can be used to report the last time the server recorded a use of
each secret, where "use" is defined as any authorized query that is not the
"info" operation.
This is in preparation for adding a new option for the access index.
Wire in an initial access index, and ensure it gets updated whenever we
successfully authorize an operation besides "info". Note that we will update
the index even if the operation reports an error, because we are using the
audit log as the source of truth, and we did in fact allow the operation even
if it did not wind up doing anything.
Surface the last accessed information in list and info responses.
Base automatically changed from mjf/audit-read to main September 30, 2026 20:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant