SecretsExecutionEnv class final

An ExecutionEnv that injects secret env vars into every exec.

Implemented types

Constructors

SecretsExecutionEnv(ExecutionEnv _delegate, Map<String, String> secrets)
Creates a decorator over delegate injecting secrets (name → value).

Properties

backgroundJobsSupported → bool
Whether startShellJob actually works here. Decorators forward their delegate's answer, so wrapping an env never fakes the capability.
no setteroverride
cwd → String
Current working directory for relative paths.
no setteroverride
delegate → ExecutionEnv
The wrapped environment.
no setter
hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
secretNames → List<String>
Every secret name this env announces in exec envs: the live values' names plus the host-registered roster, sorted.
no setter

Methods

absolutePath(String path) → Future<Result<String, FileError>>
Returns an absolute addressed path without requiring it to exist and without resolving symlinks.
override
addSecrets(Map<String, String> secrets) → void
Merges secrets into the injected map at runtime; later exec calls see them. Per-call ShellExecOptions.env entries still win over the injected secrets.
appendFile(String path, String content) → Future<Result<void, FileError>>
Creates or appends to a file, creating parent directories.
override
createDir(String path, {bool recursive = true}) → Future<Result<void, FileError>>
Creates a directory. When recursive is true (the default), missing parents are created too.
override
exec(String command, {ShellExecOptions? options}) → Future<Result<ShellExecResult, ExecutionError>>
Executes a shell command. Must never throw: all failures are encoded in the returned Result.
override
exists(String path) → Future<Result<bool, FileError>>
Returns false for missing paths; other errors surface as Err.
override
fileInfo(String path) → Future<Result<FileInfo, FileError>>
Returns metadata for the addressed path without following symlinks.
override
joinPath(List<String> parts) → Future<Result<String, FileError>>
Joins path segments in the filesystem namespace without requiring the result to exist.
override
listDir(String path) → Future<Result<List<FileInfo>, FileError>>
Lists the direct children of a directory.
override
mergedExecEnv(ShellExecOptions? options) → Map<String, String>?
The exec env with the secret values AND the presence roster (secretPresenceEnvVar — names only) merged in. Per-call env entries win over the injected secret VALUES; the roster is harness-owned and cannot be shadowed by a per-call entry. Null when there is nothing to merge (no secrets, no roster, no per-call env).
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
readBinaryFile(String path) → Future<Result<Uint8List, FileError>>
Reads the file as raw bytes.
override
readRange(String path, int start, int end) → Future<Result<Uint8List, FileError>>
Reads the bytes of path in the half-open range [start, end).
override
readTextFile(String path) → Future<Result<String, FileError>>
Reads a UTF-8 text file.
override
readTextLines(String path, {int? maxLines}) → Future<Result<List<String>, FileError>>
Reads UTF-8 text lines. Implementations should stop once maxLines lines have been read.
override
registerSecretNames(Iterable<String> names) → void
Extends the announced secret-name roster (names only). Hosts pass the system-prompt "Available secret env vars" list here so env can show NAME: ABSENT for a not-currently-granted name.
remove(String path, {bool recursive = false, bool force = false}) → Future<Result<void, FileError>>
Removes a file or directory. With force, a missing path is not an error.
override
renamePath(String from, String to) → Future<Result<void, FileError>>
Atomically renames/moves from to to (overwrites an existing to, POSIX semantics).
override
revokeSecret(String name) → void
Removes name's value from the injected map (gh-1444 E3): later execs stop seeing the value while the name STAYS in the roster, so the sandbox env listing renders NAME: ABSENT instead of the variable silently disappearing. An exec already dispatched with the merged env keeps it (documented lifetime).
secretsSnapshot() → Map<String, String>
A snapshot copy of the live secret map currently injected into exec (name → value). Hosts read it for their own secret bridges (e.g. an app-facing keys API); mutating the returned map does not affect the env.
startShellJob(String command, {required String id, required String logPath, ShellExecOptions? options}) → Future<Result<ShellJob, ExecutionError>>
Starts command detached: stdout/stderr append to logPath and the returned ShellJob keeps running until it exits or is stopped. ShellExecOptions.timeout and ShellExecOptions.cancelToken still apply (both stop the job).
override
toString() → String
A string representation of this object.
inherited
writeBinaryFile(String path, Uint8List content) → Future<Result<void, FileError>>
Writes raw bytes to a file, creating parent directories.
override
writeFile(String path, String content) → Future<Result<void, FileError>>
Creates or overwrites a file, creating parent directories.
override

Operators

operator ==(Object other) → bool
The equality operator.
inherited