Skip to content

Commit 8757466

Browse files
sisunkarCopilot
andcommitted
[SiteRecovery] Mark SAS token and KEK PFX properties secret from 2026-11-01
Addresses SEC-SECRET-DETECT review findings SR-1 and SR-2. Adds a secret SecretString scalar and changes ExportJobDetails.sasToken and the ten primary/secondary KEK certificate PFX properties to it from 2026-11-01 via @typeChangedFrom, removing the sasToken secret-prop suppression. Earlier published versions are unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 08d8c9c commit 8757466

2 files changed

Lines changed: 45 additions & 23 deletions

File tree

  • specification/recoveryservicessiterecovery/resource-manager/Microsoft.RecoveryServices/SiteRecovery

‎specification/recoveryservicessiterecovery/resource-manager/Microsoft.RecoveryServices/SiteRecovery/models.tsp‎

Lines changed: 28 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,12 @@ using Azure.ResourceManager.Foundations;
1212

1313
namespace Microsoft.RecoveryServices;
1414

15+
/**
16+
* A string value that contains secret material.
17+
*/
18+
@secret
19+
scalar SecretString extends string;
20+
1521
/**
1622
* Value indicating whether the health error is customer resolvable.
1723
*/
@@ -10165,8 +10171,8 @@ model ExportJobDetails extends JobDetails {
1016510171
/**
1016610172
* The sas token to access blob.
1016710173
*/
10168-
#suppress "@azure-tools/typespec-azure-resource-manager/secret-prop" "FIXME: Update justification, follow aka.ms/tsp/conversion-fix for details"
10169-
sasToken?: string;
10174+
@typeChangedFrom(Versions.v2026_11_01, string)
10175+
sasToken?: SecretString;
1017010176

1017110177
/**
1017210178
* Gets the type of job details (see JobDetailsTypes enum for possible values).
@@ -10457,12 +10463,14 @@ model HyperVReplicaAzureApplyRecoveryPointInput
1045710463
/**
1045810464
* The primary kek certificate pfx.
1045910465
*/
10460-
primaryKekCertificatePfx?: string;
10466+
@typeChangedFrom(Versions.v2026_11_01, string)
10467+
primaryKekCertificatePfx?: SecretString;
1046110468

1046210469
/**
1046310470
* The secondary kek certificate pfx.
1046410471
*/
10465-
secondaryKekCertificatePfx?: string;
10472+
@typeChangedFrom(Versions.v2026_11_01, string)
10473+
secondaryKekCertificatePfx?: SecretString;
1046610474

1046710475
/**
1046810476
* The class type.
@@ -10839,12 +10847,14 @@ model HyperVReplicaAzurePlannedFailoverProviderInput
1083910847
/**
1084010848
* Primary kek certificate pfx.
1084110849
*/
10842-
primaryKekCertificatePfx?: string;
10850+
@typeChangedFrom(Versions.v2026_11_01, string)
10851+
primaryKekCertificatePfx?: SecretString;
1084310852

1084410853
/**
1084510854
* Secondary kek certificate pfx.
1084610855
*/
10847-
secondaryKekCertificatePfx?: string;
10856+
@typeChangedFrom(Versions.v2026_11_01, string)
10857+
secondaryKekCertificatePfx?: SecretString;
1084810858

1084910859
/**
1085010860
* The recovery point id to be passed to failover to a particular recovery point. In case of latest recovery point, null should be passed.
@@ -11285,12 +11295,14 @@ model HyperVReplicaAzureTestFailoverInput
1128511295
/**
1128611296
* Primary kek certificate pfx.
1128711297
*/
11288-
primaryKekCertificatePfx?: string;
11298+
@typeChangedFrom(Versions.v2026_11_01, string)
11299+
primaryKekCertificatePfx?: SecretString;
1128911300

1129011301
/**
1129111302
* Secondary kek certificate pfx.
1129211303
*/
11293-
secondaryKekCertificatePfx?: string;
11304+
@typeChangedFrom(Versions.v2026_11_01, string)
11305+
secondaryKekCertificatePfx?: SecretString;
1129411306

1129511307
/**
1129611308
* The recovery point id to be passed to test failover to a particular recovery point. In case of latest recovery point, null should be passed.
@@ -11317,12 +11329,14 @@ model HyperVReplicaAzureUnplannedFailoverInput
1131711329
/**
1131811330
* Primary kek certificate pfx.
1131911331
*/
11320-
primaryKekCertificatePfx?: string;
11332+
@typeChangedFrom(Versions.v2026_11_01, string)
11333+
primaryKekCertificatePfx?: SecretString;
1132111334

1132211335
/**
1132311336
* Secondary kek certificate pfx.
1132411337
*/
11325-
secondaryKekCertificatePfx?: string;
11338+
@typeChangedFrom(Versions.v2026_11_01, string)
11339+
secondaryKekCertificatePfx?: SecretString;
1132611340

1132711341
/**
1132811342
* The recovery point id to be passed to failover to a particular recovery point. In case of latest recovery point, null should be passed.
@@ -17765,12 +17779,14 @@ model RecoveryPlanHyperVReplicaAzureFailoverInput
1776517779
/**
1776617780
* The primary KEK certificate PFX.
1776717781
*/
17768-
primaryKekCertificatePfx?: string;
17782+
@typeChangedFrom(Versions.v2026_11_01, string)
17783+
primaryKekCertificatePfx?: SecretString;
1776917784

1777017785
/**
1777117786
* The secondary KEK certificate PFX.
1777217787
*/
17773-
secondaryKekCertificatePfx?: string;
17788+
@typeChangedFrom(Versions.v2026_11_01, string)
17789+
secondaryKekCertificatePfx?: SecretString;
1777417790

1777517791
/**
1777617792
* The recovery point type.

‎specification/recoveryservicessiterecovery/resource-manager/Microsoft.RecoveryServices/SiteRecovery/stable/2026-11-01/service.json‎

Lines changed: 17 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -15881,7 +15881,7 @@
1588115881
"description": "BlobUri of the exported jobs."
1588215882
},
1588315883
"sasToken": {
15884-
"type": "string",
15884+
"$ref": "#/definitions/SecretString",
1588515885
"description": "The sas token to access blob."
1588615886
}
1588715887
},
@@ -16656,11 +16656,11 @@
1665616656
"description": "ApplyRecoveryPoint input specific to HyperVReplicaAzure provider.",
1665716657
"properties": {
1665816658
"primaryKekCertificatePfx": {
16659-
"type": "string",
16659+
"$ref": "#/definitions/SecretString",
1666016660
"description": "The primary kek certificate pfx."
1666116661
},
1666216662
"secondaryKekCertificatePfx": {
16663-
"type": "string",
16663+
"$ref": "#/definitions/SecretString",
1666416664
"description": "The secondary kek certificate pfx."
1666516665
}
1666616666
},
@@ -16970,11 +16970,11 @@
1697016970
"description": "HyperVReplicaAzure specific planned failover input.",
1697116971
"properties": {
1697216972
"primaryKekCertificatePfx": {
16973-
"type": "string",
16973+
"$ref": "#/definitions/SecretString",
1697416974
"description": "Primary kek certificate pfx."
1697516975
},
1697616976
"secondaryKekCertificatePfx": {
16977-
"type": "string",
16977+
"$ref": "#/definitions/SecretString",
1697816978
"description": "Secondary kek certificate pfx."
1697916979
},
1698016980
"recoveryPointId": {
@@ -17338,11 +17338,11 @@
1733817338
"description": "HvrA provider specific input for test failover.",
1733917339
"properties": {
1734017340
"primaryKekCertificatePfx": {
17341-
"type": "string",
17341+
"$ref": "#/definitions/SecretString",
1734217342
"description": "Primary kek certificate pfx."
1734317343
},
1734417344
"secondaryKekCertificatePfx": {
17345-
"type": "string",
17345+
"$ref": "#/definitions/SecretString",
1734617346
"description": "Secondary kek certificate pfx."
1734717347
},
1734817348
"recoveryPointId": {
@@ -17366,11 +17366,11 @@
1736617366
"description": "HvrA provider specific input for unplanned failover.",
1736717367
"properties": {
1736817368
"primaryKekCertificatePfx": {
17369-
"type": "string",
17369+
"$ref": "#/definitions/SecretString",
1737017370
"description": "Primary kek certificate pfx."
1737117371
},
1737217372
"secondaryKekCertificatePfx": {
17373-
"type": "string",
17373+
"$ref": "#/definitions/SecretString",
1737417374
"description": "Secondary kek certificate pfx."
1737517375
},
1737617376
"recoveryPointId": {
@@ -25585,11 +25585,11 @@
2558525585
"description": "Recovery plan HVR Azure failover input.",
2558625586
"properties": {
2558725587
"primaryKekCertificatePfx": {
25588-
"type": "string",
25588+
"$ref": "#/definitions/SecretString",
2558925589
"description": "The primary KEK certificate PFX."
2559025590
},
2559125591
"secondaryKekCertificatePfx": {
25592-
"type": "string",
25592+
"$ref": "#/definitions/SecretString",
2559325593
"description": "The secondary KEK certificate PFX."
2559425594
},
2559525595
"recoveryPointType": {
@@ -27686,6 +27686,12 @@
2768627686
],
2768727687
"x-ms-discriminator-value": "ScriptActionTaskDetails"
2768827688
},
27689+
"SecretString": {
27690+
"type": "string",
27691+
"format": "password",
27692+
"description": "A string value that contains secret material.",
27693+
"x-ms-secret": true
27694+
},
2768927695
"SecurityConfiguration": {
2769027696
"type": "string",
2769127697
"description": "Security configuration state.",

0 commit comments

Comments
 (0)