secrets

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package secrets reads secret values that the runner holds for the app, such as a key to sign links with. The permission list declares their names, never their values:

secrets: [link_key]

Get fetches a secret when the app needs it; one the permission list does not declare is E-MAN-002. It returns a Value, which shows as [REDACTED] wherever it is printed, logged or encoded. Only Value.Reveal returns the secret: call it where the value is used, and never log, store or show what it returns. In aicoded dev the values come from the developer's dev.yaml, and the logs and traces it keeps show a value of 4 bytes or more as [secret <name>].

Read more in the guide docs/guides/settings-and-secrets.md, which aicoded explain and the MCP tool howto print as guides/settings-and-secrets.

Index

Examples

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Value

type Value struct {
	// contains filtered or unexported fields
}

Value is a secret. It holds a pointer to the text so that printing a struct with a Value in an unexported field shows an address.

Example

A Value shows as [REDACTED] wherever it is printed, logged or encoded, so a slip never shows the secret.

package main

import (
	"encoding/json"
	"fmt"
	"log"

	"aicoded.dev/framework/secrets"
)

func main() {
	var key secrets.Value // as secrets.Get returns it
	fmt.Println(key)
	data, err := json.Marshal(struct{ Key secrets.Value }{key})
	if err != nil {
		log.Fatal(err)
	}
	fmt.Println(string(data))
}
Output:
[REDACTED]
{"Key":"[REDACTED]"}

func Get

func Get(ctx context.Context, name string) (Value, error)

Get returns secret name.

Example

Reveal a secret only where it is used, here in a page's Data to sign a link so that the app can later tell that it made the link itself.

package main

import (
	"context"
	"crypto/hmac"
	"crypto/sha256"
	"encoding/hex"
	"fmt"

	"aicoded.dev/framework/secrets"
)

func main() {
	data := func(ctx context.Context) error {
		key, err := secrets.Get(ctx, "link_key") // secrets: [link_key] in the permission list
		if err != nil {
			return err
		}
		mac := hmac.New(sha256.New, []byte(key.Reveal()))
		mac.Write([]byte("/reports/2026-09"))
		fmt.Println("/reports/2026-09?sig=" + hex.EncodeToString(mac.Sum(nil)))
		return nil
	}
	_ = data
}

func (Value) Format

func (Value) Format(f fmt.State, _ rune)

func (Value) LogValue

func (Value) LogValue() slog.Value

func (Value) MarshalJSON

func (Value) MarshalJSON() ([]byte, error)

func (Value) MarshalText

func (Value) MarshalText() ([]byte, error)

func (Value) Reveal

func (v Value) Reveal() string

Reveal returns the secret. Pass the result straight to where it is needed; never log it.

func (Value) String

func (Value) String() string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL