001/* 002 * SPDX-License-Identifier: Apache-2.0 003 * 004 * Copyright 2025-2026 The Enola <https://enola.dev> Authors 005 * 006 * Licensed under the Apache License, Version 2.0 (the "License"); 007 * you may not use this file except in compliance with the License. 008 * You may obtain a copy of the License at 009 * 010 * https://www.apache.org/licenses/LICENSE-2.0 011 * 012 * Unless required by applicable law or agreed to in writing, software 013 * distributed under the License is distributed on an "AS IS" BASIS, 014 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 015 * See the License for the specific language governing permissions and 016 * limitations under the License. 017 */ 018package dev.enola.common.secret; 019 020import java.io.IOException; 021import java.util.Optional; 022 023/** 024 * SecretManager that reads secrets from the JVM properties (AKA <code>java -D...</code>). 025 * 026 * <p>This is not very secure, and really only marginally better than the {@link 027 * EnvironmentSecretManager} (because JVM process launch parameters are often still too broadly 028 * visible). Other implementations are preferred - but sometimes this may be useful. 029 */ 030public class JavaPropertySecretManager extends ReadOnlySecretManager { 031 032 @Override 033 @SuppressWarnings("deprecation") 034 public Optional<Secret> getOptional(String key) throws IOException { 035 String value = System.getProperty(key); 036 return Optional.ofNullable(value).map(Secret::new); 037 } 038}