secrets

package
v2.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: AGPL-3.0 Imports: 18 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CreateSecret

func CreateSecret(db *gorm.DB, settings *Secret) error

CreateSecret creates a new Secret record in the database.

func DecryptValue

func DecryptValue(value string) string

DecryptValue decrypts a value that was encrypted with EncryptValue. Returns the decrypted plaintext, or the original value if not encrypted.

func DeleteSecretByID

func DeleteSecretByID(db *gorm.DB, id uint) error

DeleteSecretByID deletes a Secret record from the database by ID.

func EncryptValue

func EncryptValue(plaintext string) string

EncryptValue encrypts a plaintext string using the application's AES key. Returns the encrypted value or the original if encryption fails or is not configured.

func EncryptionKeyConfigured

func EncryptionKeyConfigured() bool

EncryptionKeyConfigured reports whether a secrets encryption key is set, through SetEncryptionKey or the environment.

func FilterSensitiveFields

func FilterSensitiveFields(obj interface{}) interface{}

func FilterSesitiveFieldsArr

func FilterSesitiveFieldsArr(in interface{}) interface{}

func GetOrCreateDefaultSecrets

func GetOrCreateDefaultSecrets(db *gorm.DB) error

GetOrCreateDefaultSecrets ensures default secrets exist in the database. This function creates OPENAI_KEY and ANTHROPIC_KEY secrets with empty values if they don't already exist, allowing users to fill in their API keys later.

func GetSecretReference

func GetSecretReference(name string) string

GetSecretReference returns a secret reference string for a given name

func GetValue

func GetValue(reference string, preserveRef bool) string

func IsSecretReference

func IsSecretReference(value string) bool

IsSecretReference checks if a string is in the format $SECRET/NAME

func ReencryptLegacySecrets

func ReencryptLegacySecrets(db *gorm.DB) (int, error)

ReencryptLegacySecrets rewrites stored Secret rows that still use the legacy AES-CFB format to the current scrypt+AES-GCM scheme. Rows that are empty, already migrated, or fail to decrypt (e.g. written under a different key) are left untouched. Rows are processed in batches to bound memory usage, with each batch's updates applied in a single transaction. Returns the number of migrated rows.

func SetDBRef

func SetDBRef(db *gorm.DB)

func SetEncryptionKey

func SetEncryptionKey(key string)

SetEncryptionKey sets the key that encrypts secrets at rest, taking the place of the TYK_AI_SECRET_KEY environment variable. An embedding host calls it before any secret is read or written.

func UpdateSecret

func UpdateSecret(db *gorm.DB, settings *Secret, encryptValue bool) error

UpdateSecret updates an existing Secret record in the database. When encryptValue is true, the Value field is encrypted before saving. Pass false when the Value already contains the stored (encrypted) value and should not be re-encrypted.

func WarnIfEncryptionUnconfigured

func WarnIfEncryptionUnconfigured() bool

WarnIfEncryptionUnconfigured emits a prominent startup warning when the encryption key is not configured, so operators know stored secrets will be persisted as plaintext. Returns true when the key is configured.

Types

type Secret

type Secret struct {
	gorm.Model
	ID      uint   `gorm:"primaryKey" json:"id" access:"secrets"`
	VarName string `json:"name"`
	Value   string `json:"value"`
	// contains filtered or unexported fields
}

func GetSecretByID

func GetSecretByID(db *gorm.DB, id uint, preserveRef bool) (*Secret, error)

GetSecretByID retrieves a Secret record from the database by ID.

func GetSecretByVarName

func GetSecretByVarName(db *gorm.DB, name string, preserveRef bool) (*Secret, error)

GetSecretByVarName retrieves a Secret record from the database by it's name.

func ListSecrets

func ListSecrets(db *gorm.DB, pageSize int, pageNumber int, all bool, scopes ...func(*gorm.DB) *gorm.DB) ([]Secret, int64, int, error)

func (*Secret) GetValue

func (s *Secret) GetValue() string

GetValue returns either the decrypted value or the reference format

func (*Secret) HasValue

func (s *Secret) HasValue() bool

HasValue reports whether the secret holds a non-empty value, without exposing it. Works on a row as stored (encrypted) and on one that has already been decrypted: an encrypted empty string is a real ciphertext, so the stored form has to be decrypted to know it is empty, while a decrypted value is simply checked for emptiness.

func (*Secret) PreserveReference

func (s *Secret) PreserveReference()

PreserveReference sets the secret to return in reference format

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL