renderEnvListingWithSecretPresence function
Renders the full env listing over the merged exec env: plain vars
as NAME=value, rostered secret names as PRESENT/ABSENT lines (a
rostered name with no value in the env renders ABSENT — the revoked
secret must stay visible), and the roster var itself hidden. Sorted by
name, newline-terminated when non-empty.
Implementation
String renderEnvListingWithSecretPresence(Map<String, String> env) {
final names = secretNamesFromEnv(env);
final lines = <String, String>{
for (final entry in env.entries)
if (entry.key != '?' && entry.key != secretPresenceEnvVar)
entry.key: names.contains(entry.key)
? secretPresenceLine(entry.key, env)
: '${entry.key}=${entry.value}',
for (final name in names)
if (!env.containsKey(name)) name: secretPresenceLine(name, env),
};
final sorted = lines.keys.toList()..sort();
if (sorted.isEmpty) return '';
return '${sorted.map((name) => lines[name]!).join('\n')}\n';
}