Goldpath.DataProtection
0.1.0-preview.8
dotnet add package Goldpath.DataProtection --version 0.1.0-preview.8
NuGet\Install-Package Goldpath.DataProtection -Version 0.1.0-preview.8
<PackageReference Include="Goldpath.DataProtection" Version="0.1.0-preview.8" />
<PackageVersion Include="Goldpath.DataProtection" Version="0.1.0-preview.8" />
<PackageReference Include="Goldpath.DataProtection" />
paket add Goldpath.DataProtection --version 0.1.0-preview.8
#r "nuget: Goldpath.DataProtection, 0.1.0-preview.8"
#:package Goldpath.DataProtection@0.1.0-preview.8
#addin nuget:?package=Goldpath.DataProtection&version=0.1.0-preview.8&prerelease
#tool nuget:?package=Goldpath.DataProtection&version=0.1.0-preview.8&prerelease
Goldpath.DataProtection
Ring B data protection: classify a property as personal/sensitive ONCE and every sink masks it consistently — audit change rows, redacted logging, Mediant audit patterns. Masking, not encryption: nothing here changes what is stored in YOUR columns, only what leaks into observability and audit surfaces.
Getting started
builder.AddGoldpathDataProtection();
public class Customer
{
[GoldpathPersonalData] // GDPR-relevant identity data
public string? NationalId { get; set; }
[GoldpathSensitiveData] // financial / health / confidential
public string? Salary { get; set; }
}
With Goldpath.AuditTrail enabled, change rows for classified properties arrive masked (***)
while every other property keeps full old→new values — no configuration, the modules find
each other through the IGoldpathDataProtector seam.
Configuration
builder.AddGoldpathDataProtection(o =>
{
// Legacy/scaffolded entities whose source must not be touched:
o.Catalog(c => c.Classify<LegacyCustomer>(x => x.TaxNumber, GoldpathDataClass.Personal));
// Pseudonymization instead of erasure — correlation survives, the value doesn't:
o.UseHmacRedaction(builder.Configuration["Goldpath:DataProtection:HmacKey"]!);
});
Manifest: features.dataProtection: { mode: annotate|catalog|both, redactor: erase|hmac, auditMasking: true }. Catalog entries win over annotations on the same member.
Advanced
- Redaction is composed from
Microsoft.Extensions.Compliance.Redaction(ADR-0003): the defaultGoldpathErasingRedactoryields a fixed***token (visible in audit rows, reveals nothing — not even length); HMAC mode uses the built-inHmacRedactor. - Log redaction: the Goldpath attributes ARE Microsoft
DataClassificationAttributes, so the MEL enrichment path (builder.Logging.EnableRedaction()+[LogProperties]) redacts them natively — one annotation, both sinks. - Mediant alignment: properties carrying Mediant's
[SensitiveData]are recognized by name (no hard dependency); catalog-declared names are fed into Mediant'sSensitivePatternsso command-level audit masks the same members. - AuditTrail
NamesOnlyremains the blunt global fallback; per-property masking is the recommended posture (values stay useful, PII stays out). - Key rotation (HMAC): bump
HmacKeyIdwith the new key; old hashes stop correlating with new ones — by design. Runbook inops/.
Providers
Not applicable — sinks consume the IGoldpathDataProtector seam; absent module, absent service,
unmasked values (compile-time composition).
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Goldpath.Abstractions (>= 0.1.0-preview.8)
- Microsoft.Extensions.Compliance.Redaction (>= 10.9.0)
- Microsoft.Extensions.Configuration.Binder (>= 10.0.11)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.11)
-
net8.0
- Goldpath.Abstractions (>= 0.1.0-preview.8)
- Microsoft.Extensions.Compliance.Redaction (>= 10.9.0)
- Microsoft.Extensions.Configuration.Binder (>= 10.0.11)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.11)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.0-preview.8 | 83 | 9/7/2026 |
| 0.1.0-preview.7 | 99 | 9/1/2026 |
| 0.1.0-preview.6 | 349 | 8/4/2026 |
| 0.1.0-preview.5 | 90 | 7/28/2026 |
| 0.1.0-preview.4 | 82 | 7/27/2026 |
| 0.1.0-preview.3 | 67 | 7/25/2026 |
| 0.1.0-preview.2 | 69 | 7/13/2026 |
| 0.1.0-preview.1 | 105 | 7/13/2026 |