Reworked encryption to use less heap allocated buffers for secrets.

Also some work on plugin system.
This commit is contained in:
eelke 2026-08-18 07:40:24 +02:00
parent 8782ef39c6
commit 054754f553
42 changed files with 1452 additions and 242 deletions

View file

@ -0,0 +1,15 @@
namespace IdentityShroud.SecretProviders;
/// <summary>
/// Required interface of a SecretProvider.
/// </summary>
public interface ISecretProvider
{
/// <summary>
/// Used as a key in the registry. This same value should be used for the type field
/// when configuring a secret.
/// </summary>
string Key { get; }
Task<PlainSecret> GetSecret(string configurationValue, CancellationToken ct = default);
}

View file

@ -0,0 +1,13 @@
<Project Sdk="Microsoft.NET.Sdk">
<PropertyGroup>
<TargetFramework>net10.0</TargetFramework>
<ImplicitUsings>enable</ImplicitUsings>
<Nullable>enable</Nullable>
</PropertyGroup>
<ItemGroup>
<ProjectReference Include="..\IdentityShroud.PluginSupport\IdentityShroud.PluginSupport.csproj" />
</ItemGroup>
</Project>

View file

@ -0,0 +1,18 @@
using System.Security.Cryptography;
namespace IdentityShroud.SecretProviders;
public sealed class PlainSecret(byte[] secret) : IDisposable
{
private bool _disposed;
public ReadOnlySpan<byte> Secret => secret;
public void Dispose()
{
if (_disposed)
return;
_disposed = true;
CryptographicOperations.ZeroMemory(secret);
}
}