Files
Resolve-DSCConfigurationData/Private/Resolve-ConfigurationDataSecretReference.ps1
T

55 lines
2.0 KiB
PowerShell

function Resolve-ConfigurationDataSecretReference {
[CmdletBinding()]
Param(
[Parameter(Mandatory=$true)]
[System.Collections.IDictionary]
$Reference,
[Parameter(Mandatory=$true)]
[ValidateSet("credential", "securestring", "string")]
[string]
$ExpectedType,
[Parameter(Mandatory=$false)]
[hashtable]
$ProviderSettings = @{},
[Parameter(Mandatory=$false)]
[AllowNull()]
$Context = $null
)
$Provider = [string](Get-ConfigurationDataMapValue -Map $Reference -Key "Provider")
$ProviderDefinition = Get-ConfigurationDataSecretProvider -Name $Provider
if($null -eq $ProviderDefinition){
throw "Unsupported secret provider [$Provider]."
}
if($ProviderDefinition.SupportedTypes -notcontains $ExpectedType.ToLowerInvariant()){
throw "Secret provider [$($ProviderDefinition.Name)] does not support type [$ExpectedType]."
}
$CurrentProviderSettings = @{}
if($ProviderSettings.ContainsKey($ProviderDefinition.Name)){
$CurrentProviderSettings = $ProviderSettings[$ProviderDefinition.Name]
}
$SecretValue = & $ProviderDefinition.Resolver -Reference $Reference -ExpectedType $ExpectedType -ProviderSettings $CurrentProviderSettings
if($ExpectedType.ToLowerInvariant() -eq "credential" -and (Test-ConfigurationDataMapContainsKey -Map $Reference -Key "Domain")){
if(-not ($SecretValue -is [System.Management.Automation.PSCredential])){
throw "Secret reference [$($Reference.Name)] defines [Domain], but the resolved value is not a PSCredential."
}
$Domain = Get-ConfigurationDataMapValue -Map $Reference -Key "Domain"
if($null -ne $Context){
$Domain = Resolve-ConfigurationDataValue -Value $Domain -Context $Context
}
$SecretValue = ConvertTo-ConfigurationDataDomainCredential -Credential $SecretValue -Domain ([string]$Domain)
}
return $SecretValue
}