Skip to content

Required input markers for imported secrets

Summary

  • Implemented OpenSpec 6.2 on branch codex/octopus-import-secret-input-6-2.
  • Added Octopus-import-only required input structures: OctopusImportRequiredInputDto, OctopusImportRequiredInputKind, and OctopusImportRequiredInputBuilder.
  • Sensitive variables still map to VariableType.Password with empty values, and now emit required-secret-input markers with source ID, type, scope, and value-presence metadata only.
  • Added RequiredInputs to Octopus import preview/resource/validation DTOs because existing import responses had no structured required-input surface; the general Squid variable command contract was not changed.
  • Reused the 6.1 central redaction helpers and diagnostics; no duplicate redaction logic was added.
  • Updated OpenSpec task 6.2 and SESSION_MEMORY.md; did not implement 6.3, 6.4, 6.5, 6.6, confirmation, or API behavior.

Test plan

  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter "FullyQualifiedName~OctopusImport" passed: 222/222.
  • openspec validate add-octopus-import --strict passed.
  • git diff --check passed.
  • Checked sensitive value handling via tests and search: source secret values are not emitted through required-input DTOs, diagnostics, or production code; no OctopusImport structured logging path was added.
  • Full repository test suite not run; validation was scoped to OctopusImport-related tests.

Merge request reports

Loading