using VaultSharp;
namespace SwBLL.Vault;
///
/// Reads secrets from HashiCorp Vault KV v2 at the "secret" mount point. Matches the
/// write shape used by ClientDatabaseProvisioner.WriteSecretAsync — a single "value" key.
///
public class SwVaultService : ISwVaultService
{
private readonly IVaultClient _vaultClient;
public SwVaultService(IVaultClient vaultClient) => _vaultClient = vaultClient;
public async Task GetSecretAsync(string vaultPath, CancellationToken ct)
{
var secret = await _vaultClient.V1.Secrets.KeyValue.V2
.ReadSecretAsync(path: vaultPath, mountPoint: "secret")
.ConfigureAwait(false);
return secret?.Data?.Data?["value"]?.ToString()
?? throw new InvalidOperationException($"Vault secret at path '{vaultPath}' returned empty or null data.");
}
}