Sensitive

annotation class Sensitive(val level: SensitivityLevel, val mask: Mask = Mask())

Declares a sensitive field of a query model: its level and how query results mask it.

Sensitivity is declared only on the domain field, never in a declaration file or by a string path, so renaming the field cannot silently drop the protection. The field must be a JVM String that serializes as a JSON string.

data class AccountState(
@field:Sensitive(SensitivityLevel.CONFIDENTIAL)
val password: String,
@field:Sensitive(SensitivityLevel.DISPLAY, mask = Mask(keepPrefix = 3, keepSuffix = 4))
val phone: String?,
)

It can also annotate an annotation class, which then declares the same sensitivity wherever it is used.

On a value type — a Kotlin value class or a type with a @JsonValue member, serialized as a string — it protects every property declared with that type (or a collection of it), in states and event payloads alike, so one value keeps one level everywhere. A property may repeat or tighten the type's level, never loosen it:

@JvmInline
@Sensitive(SensitivityLevel.DISPLAY, mask = Mask(keepPrefix = 3, keepSuffix = 4))
value class PhoneNumber(val value: String)

Any other class carrying @Sensitive fails the schema build.

Properties

Link copied to clipboard
Link copied to clipboard
val mask: Mask