Repository navigation
(WIP) Add a "description" field to each stored secret - #164
Closed
creachadair wants to merge 17 commits into
Closed
creachadair wants to merge 17 commits into
creachadair wants to merge 17 commits into
Conversation
creachadair
force-pushed
the
mjf/description
branch
from
April 27, 2026 21:10
c0d457e to
8c0fd80
Compare
creachadair
commented
Apr 27, 2026
|
|
||
| // MaxDescriptionBytes is the maximum permitted length of a secret description. | ||
| // Descriptions in excess of this length will be rejected. | ||
| const MaxDescriptionBytes = 1000 |
Member
Author
There was a problem hiding this comment.
Rationale: About 12 lines or 200 words of English text, should be enough for anybody.
creachadair
force-pushed
the
mjf/audit-read
branch
from
July 7, 2026 22:30
0cdea43 to
1fb7d21
Compare
creachadair
force-pushed
the
mjf/description
branch
from
July 7, 2026 22:31
8c0fd80 to
89c2e8a
Compare
creachadair
force-pushed
the
mjf/audit-read
branch
from
August 24, 2026 21:41
1fb7d21 to
e95135a
Compare
creachadair
force-pushed
the
mjf/description
branch
from
August 24, 2026 21:41
89c2e8a to
341cada
Compare
creachadair
force-pushed
the
mjf/audit-read
branch
2 times, most recently
from
August 24, 2026 22:39
816d184 to
7cd0238
Compare
creachadair
force-pushed
the
mjf/description
branch
from
August 24, 2026 22:39
341cada to
686b51b
Compare
This is preparation for adding a Reader type in the next commit. Update usage throughout.
This allows a caller to read back through the contents of an audit log. The Reader exposes a basic iterator interface.
This field can be used to report the last time the server recorded a use of each secret, where "use" is defined as any authorized query that is not the "info" operation.
This is in preparation for adding a new option for the access index.
Wire in an initial access index, and ensure it gets updated whenever we successfully authorize an operation besides "info". Note that we will update the index even if the operation reports an error, because we are using the audit log as the source of truth, and we did in fact allow the operation even if it did not wind up doing anything.
Surface the last accessed information in list and info responses.
creachadair
force-pushed
the
mjf/audit-read
branch
from
August 24, 2026 22:42
7cd0238 to
c267227
Compare
creachadair
force-pushed
the
mjf/description
branch
from
August 24, 2026 22:43
686b51b to
e7755cd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This builds on #163 and requires it to be merged first.
There are multiple commits here that can be reviewed separately, and the branch
is currently based on the #163 branch, but I intend to rebase it on main before
requesting a real review.
NOT READY -- DO NOT MERGE