Required input markers for imported secrets
Summary
- Implemented OpenSpec 6.2 on branch
codex/octopus-import-secret-input-6-2. - Added Octopus-import-only required input structures:
OctopusImportRequiredInputDto,OctopusImportRequiredInputKind, andOctopusImportRequiredInputBuilder. - Sensitive variables still map to
VariableType.Passwordwith empty values, and now emitrequired-secret-inputmarkers with source ID, type, scope, and value-presence metadata only. - Added
RequiredInputsto Octopus import preview/resource/validation DTOs because existing import responses had no structured required-input surface; the general Squid variable command contract was not changed. - Reused the 6.1 central redaction helpers and diagnostics; no duplicate redaction logic was added.
- Updated OpenSpec task 6.2 and
SESSION_MEMORY.md; did not implement 6.3, 6.4, 6.5, 6.6, confirmation, or API behavior.
Test plan
-
dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter "FullyQualifiedName~OctopusImport"passed: 222/222. -
openspec validate add-octopus-import --strictpassed. -
git diff --checkpassed. -
Checked sensitive value handling via tests and search: source secret values are not emitted through required-input DTOs, diagnostics, or production code; no OctopusImport structured logging path was added. -
Full repository test suite not run; validation was scoped to OctopusImport-related tests.