CodeSampleX

Sample

pydantic 2.13.4: Preserve SecretStr and SecretBytes plain values during Python model_dump while preventing secret value corruption across JSON serialization and deserialization cycles in Pydantic 2.13.4

Verified sample for pypi pydantic 2.13.4: Preserve SecretStr and SecretBytes plain values during Python model_dump while preventing secret value corruption…

sha256:e5a1e6b5f189f5c49af04e8a71b357635addc81edb18abeb301d700e63678557

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment python linux x64 python python pip

Verification-run environments

Environment Contract Stages Run
python 3.12 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · python@1
2026-08-17
python 3.12 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · python@1
2026-08-18

Case

HOW
Goal
Preserve SecretStr and SecretBytes plain values during Python model_dump while preventing secret value corruption across JSON serialization and deserialization cycles in Pydantic 2.13.4
Packages
Symbols
  • pydantic.types.SecretStr
  • pydantic.types.SecretBytes
  • pydantic.BaseModel.model_dump
  • pydantic.BaseModel.model_dump_json
  • pydantic.BaseModel.model_validate
  • pydantic.BaseModel.model_validate_json
Environment
python
Created
2026-08-17T06:49:32Z

Contract

  1. model_dump_json masks SecretStr and SecretBytes to asterisks, and subsequent model_validate_json silently parses the mask string as the new secret value instead of preserving the secret or raising an error.
  2. model_dump() in default python mode preserves SecretStr and SecretBytes objects, enabling lossless model_validate() roundtripping and explicit get_secret_value() extraction.
  3. model_dump(mode='json') outputs masked strings identical to model_dump_json, shedding SecretStr and SecretBytes types.
  4. SecretStr and SecretBytes mask their payload in str() and repr(), but len() reflects the underlying secret length rather than mask length.
  5. SecretStr never compares equal to a plain str or permits concatenation, preventing accidental plaintext leak via equality or string operations.

Files

  • NOTES.md
  • csx.json
  • requirements.lock
  • requirements.txt
  • src/__init__.py
  • src/models.py
  • test/contract.py

Download the source artifact (tar.gz)

Origin Seeder

csx-seed