Commit b151823
feat(azure): replace file-system CSV export with browser streaming + ZIP
In the Azure topology, NO component was actually writing CSVs to App Service
disk: CsvExportService is wired only in the on-prem Worker. The Web.Azure
Settings page and HybridAgent appsettings.json still exposed CsvOutputPath /
KeyValueExportPath fields that confused operators — they pointed at a feature
that simply does not exist on Azure.
This commit removes the dead surface and replaces it with browser-streaming
exports so no file artifact ever lands on App Service storage.
Changes
-------
* Components/App.razor — add the missing `downloadTextFile` JS helper (the
existing /audit CSV export was referencing it but it had never been
ported from the on-prem Web/App.razor — broken at runtime today). Also
add `downloadBinaryFile` for the new ZIP download.
* Components/Pages/Settings.razor — remove CsvOutputPath, KeyValueExportPath,
LogPath input fields (no consumer in the Azure flow). Update the "Sensitive
feature" card copy to reflect the Azure-native model (no file system,
browser streaming, audited).
* HybridAgent/appsettings.json — remove the inherited-but-unused
CsvOutputPath/KeyValueExportPath entries (replaced with a comment that
explains the data flow).
* Components/Pages/Devices/DeviceList.razor — add an "Export CSV (metadata)"
button. Streams the current filtered slice of devices to the browser
(metadata only — no recovery key values). Capped at 50k rows. Records the
authenticated portal user in the audit log.
* Components/Pages/Export.razor — NEW page at /export (AdminOnly). Streams a
ZIP containing recovery-key-values_<ts>.csv + optional .salt sidecar to
the browser. Each recovery key value is AES-256-GCM encrypted with the
configured passphrase, bound to (KeyId, Source, DeviceId) via AAD — same
row layout and snapshot semantics as the on-prem CsvExportService.
Preflight count caps the batch at 100k rows. Cancels on circuit dispose.
Handles mid-export DataKey lock by emitting Reason="encrypted-locked"
rather than tearing down the whole export.
* Components/Layout/MainLayout.razor — add NavLink to /export inside the
AdminOnly AuthorizeView.
Rationale (not a Storage Account)
---------------------------------
User asked: "esportare su uno Storage Account oppure qualcosa diverso più
sicuro". I chose streaming-to-browser over Blob Storage because:
1. It eliminates the "file artifact" concept entirely — no SAS rotation,
no lifecycle policy, no ciphertext sitting around waiting to be
exfiltrated.
2. Zero new infrastructure (no Bicep changes, no new Storage Account,
no CMK, no private endpoint).
3. Mirrors the existing in-memory Audit CSV export pattern.
A Blob backend can be added later behind an IExportSink abstraction if
long-term archival becomes a requirement.
Verification
------------
* dotnet build BitLockerKeyMonitor.Azure.slnx — 0 warn / 0 err
* dotnet build BitLockerKeyMonitor.slnx — 0 warn / 0 err
(on-prem solution untouched, Core unchanged)
* dotnet test BitLockerKeyMonitor.Azure.slnx — 135/135 pass
(112 Core + 15 Functions + 8 HybridAgent)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>1 parent c061fa4 commit b151823
6 files changed
Lines changed: 651 additions & 20 deletions
File tree
- src
- BitLockerKeyMonitor.HybridAgent
- BitLockerKeyMonitor.Web.Azure/Components
- Layout
- Pages
- Devices
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
47 | | - | |
48 | | - | |
| 47 | + | |
49 | 48 | | |
50 | 49 | | |
51 | 50 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
21 | 54 | | |
22 | 55 | | |
23 | 56 | | |
Lines changed: 1 addition & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| 18 | + | |
18 | 19 | | |
19 | 20 | | |
20 | 21 | | |
| |||
Lines changed: 215 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
| 5 | + | |
4 | 6 | | |
| 7 | + | |
| 8 | + | |
5 | 9 | | |
6 | 10 | | |
7 | 11 | | |
| |||
39 | 43 | | |
40 | 44 | | |
41 | 45 | | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
42 | 52 | | |
43 | 53 | | |
44 | 54 | | |
| |||
113 | 123 | | |
114 | 124 | | |
115 | 125 | | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
116 | 129 | | |
| 130 | + | |
117 | 131 | | |
118 | 132 | | |
119 | 133 | | |
120 | 134 | | |
121 | 135 | | |
122 | 136 | | |
123 | 137 | | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
124 | 141 | | |
125 | 142 | | |
126 | 143 | | |
| |||
335 | 352 | | |
336 | 353 | | |
337 | 354 | | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
338 | 534 | | |
339 | 535 | | |
340 | 536 | | |
| |||
413 | 609 | | |
414 | 610 | | |
415 | 611 | | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
416 | 631 | | |
0 commit comments