feat(secrets): default resolver with TTL cache + audit (never logs plaintext)

This commit is contained in:
Joseph Doherty
2026-07-15 16:55:24 -04:00
parent 10455ec53b
commit 79ebd14baa
7 changed files with 435 additions and 0 deletions
@@ -0,0 +1,24 @@
using System.Collections.Concurrent;
using ZB.MOM.WW.Audit;
namespace ZB.MOM.WW.Secrets.Tests.Fakes;
/// <summary>
/// An <see cref="IAuditWriter"/> test double that collects every <see cref="AuditEvent"/> written,
/// so a test can assert on the audit trail (outcome, target, and — critically — that no plaintext
/// ever appears in any field).
/// </summary>
public sealed class CapturingAuditWriter : IAuditWriter
{
private readonly ConcurrentQueue<AuditEvent> _events = new();
/// <summary>The events captured so far, in write order.</summary>
public IReadOnlyList<AuditEvent> Events => _events.ToArray();
/// <inheritdoc />
public Task WriteAsync(AuditEvent evt, CancellationToken ct = default)
{
_events.Enqueue(evt);
return Task.CompletedTask;
}
}
@@ -0,0 +1,51 @@
using System.Collections.Concurrent;
using ZB.MOM.WW.Secrets.Abstractions;
namespace ZB.MOM.WW.Secrets.Tests.Fakes;
/// <summary>
/// An in-memory <see cref="ISecretStore"/> test double that counts <see cref="GetAsync"/> calls so
/// a test can prove a resolver cache hit (or miss). Only the read path exercised by
/// <c>DefaultSecretResolver</c> is meaningfully implemented; the mutation / replication members
/// throw so an accidental dependency on them fails loudly rather than silently no-ops.
/// </summary>
public sealed class CountingSecretStore : ISecretStore
{
private readonly ConcurrentDictionary<string, StoredSecret> _rows = new(StringComparer.Ordinal);
private int _getCount;
/// <summary>The number of times <see cref="GetAsync"/> has been invoked.</summary>
public int GetCount => Volatile.Read(ref _getCount);
/// <summary>Seeds (or overwrites) a row keyed by its normalized name.</summary>
/// <param name="row">The encrypted row to seed.</param>
public void Seed(StoredSecret row) => _rows[row.Name.Value] = row;
/// <inheritdoc />
public Task<StoredSecret?> GetAsync(SecretName name, CancellationToken ct)
{
Interlocked.Increment(ref _getCount);
_rows.TryGetValue(name.Value, out StoredSecret? row);
return Task.FromResult(row);
}
/// <inheritdoc />
public Task UpsertAsync(StoredSecret row, CancellationToken ct) =>
throw new NotSupportedException();
/// <inheritdoc />
public Task<bool> DeleteAsync(SecretName name, string? actor, CancellationToken ct) =>
throw new NotSupportedException();
/// <inheritdoc />
public Task<IReadOnlyList<SecretMetadata>> ListAsync(bool includeDeleted, CancellationToken ct) =>
throw new NotSupportedException();
/// <inheritdoc />
public Task<IReadOnlyList<SecretManifestEntry>> GetManifestAsync(CancellationToken ct) =>
throw new NotSupportedException();
/// <inheritdoc />
public Task ApplyReplicatedAsync(StoredSecret row, CancellationToken ct) =>
throw new NotSupportedException();
}
@@ -0,0 +1,16 @@
using ZB.MOM.WW.Secrets.Abstractions;
namespace ZB.MOM.WW.Secrets.Tests.Fakes;
/// <summary>
/// An <see cref="ISecretActorAccessor"/> test double that reports a fixed (or <c>null</c>) actor.
/// </summary>
public sealed class FixedActorAccessor : ISecretActorAccessor
{
/// <summary>Creates an accessor that always reports <paramref name="actor"/>.</summary>
/// <param name="actor">The actor to report, or <c>null</c>.</param>
public FixedActorAccessor(string? actor) => CurrentActor = actor;
/// <inheritdoc />
public string? CurrentActor { get; }
}
@@ -0,0 +1,29 @@
namespace ZB.MOM.WW.Secrets.Tests.Fakes;
/// <summary>
/// A <see cref="TimeProvider"/> test double with a settable <see cref="GetUtcNow"/>, so a test can
/// advance the clock past a cache TTL deterministically without sleeping.
/// </summary>
public sealed class MutableTimeProvider : TimeProvider
{
private DateTimeOffset _utcNow;
/// <summary>Creates a provider starting at the given instant (defaults to the Unix epoch).</summary>
/// <param name="start">The initial <see cref="GetUtcNow"/> value.</param>
public MutableTimeProvider(DateTimeOffset? start = null) =>
_utcNow = start ?? DateTimeOffset.UnixEpoch;
/// <summary>Gets or sets the current UTC instant this provider reports.</summary>
public DateTimeOffset UtcNow
{
get => _utcNow;
set => _utcNow = value;
}
/// <summary>Moves the clock forward by <paramref name="delta"/>.</summary>
/// <param name="delta">The amount to advance.</param>
public void Advance(TimeSpan delta) => _utcNow += delta;
/// <inheritdoc />
public override DateTimeOffset GetUtcNow() => _utcNow;
}