redact

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 27, 2026 License: MIT Imports: 9 Imported by: 0

Documentation

Index

Constants

View Source
const MaxWalkDepth = 64

MaxWalkDepth bounds JSON-tree recursion against pathological MCP payloads. On exceedance: scanners under-detect, RedactTree leaves the subtree untouched — fail-safe in both directions, harnesses layer fail-open.

Variables

This section is empty.

Functions

func AllHits

func AllHits(v any) (ruleIDs []string, fields []string)

AllHits walks the tree and returns dedup'd rule IDs + dotted paths. HONORS allow/fixture markers — for AUTHORED trees (e.g. tool-call input args).

func AllHitsToolOutput

func AllHitsToolOutput(v any) (ruleIDs []string, fields []string)

AllHitsToolOutput is AllHits for UNTRUSTED tool-output trees: it does NOT honor allow/fixture markers (issue #56).

func FirstHit

func FirstHit(v any) (bool, string, []string)

FirstHit walks v and returns (true, dotted-path, ruleIDs) on first match. Path shape: k1.k2[3].k4 (matches audit-log format). HONORS allow/fixture markers — for AUTHORED trees (e.g. an MCP tool's input args).

func FirstHitToolOutput

func FirstHitToolOutput(v any) (bool, string, []string)

FirstHitToolOutput is FirstHit for UNTRUSTED tool-output trees (WebFetch/MCP responses): it does NOT honor allow/fixture markers (issue #56).

func Placeholder

func Placeholder(f report.Finding) string

Placeholder builds "<REDACTED:<rule-id>:<last-4-of-secret>>", omitting the fingerprint below minFingerprintLen.

func Redact

func Redact(content string) (string, error)

Redact scans AUTHORED content and returns it with each credential-shape finding replaced by a placeholder. ANSI escapes are stripped from the scan target so colored output like "\x1b[31mAKIA…\x1b[0m" still matches. Fail-open on detector init: returns original content + error.

This is an authored-content entry point: inline allow/fixture markers (ctxcop:allow, ctxcop:fixture, gitleaks:allow) are honored. For untrusted tool output use RedactToolOutput.

func RedactToolOutput

func RedactToolOutput(content string) (string, []string, error)

RedactToolOutput redacts UNTRUSTED tool output / transcripts. It behaves like RedactWithMatches but does NOT honor inline allow/fixture markers: a secret in a Bash output stream, a WebFetch/MCP response, a Read'd file, or a compaction transcript is redacted even when it sits next to `gitleaks:allow` or `# ctxcop:allow` — whether that marker was planted by an attacker or emitted by something like `sed 's/$/ # ctxcop:allow/'` (issue #56). Marker honoring is reserved for content the developer authored.

func RedactTree

func RedactTree(v any) (any, []string)

RedactTree returns a deep copy of v with every string redacted, plus the dedup'd rule IDs that fired. Non-string scalars and unsupported types pass through unchanged. HONORS allow/fixture markers — for AUTHORED or outbound trees.

func RedactTreeToolOutput

func RedactTreeToolOutput(v any) (any, []string)

RedactTreeToolOutput is RedactTree for UNTRUSTED tool-output trees (WebFetch/MCP responses): it does NOT honor allow/fixture markers so a planted marker can't suppress redaction of the response (issue #56).

func RedactWithMatches

func RedactWithMatches(content string) (string, []string, error)

RedactWithMatches is Redact + the rule IDs that fired (for audit). It HONORS inline allow/fixture markers and is for AUTHORED content only (Write/Edit/ NotebookEdit scanning, `ctxcop scan`, prompt/command/tool-input checks).

func Splice

func Splice(content string, findings []report.Finding) string

Splice replaces every finding's matched substring with a placeholder and guarantees, per finding, that the secret cannot survive in the output.

Detection runs on the ANSI-stripped buffer, so decoded findings' byte offsets are relative to stripANSI(content). We reproduce that buffer here (stripANSI is deterministic) and resolve offsets against it — never against the original content, whose length and byte positions differ once ANSI is present or an earlier surface replacement has run.

Surface findings (rule matched raw content) use strings.ReplaceAll on f.Match — UTF-8 safe and position-independent.

Decoded findings (`decoded:*` tag — rule matched base64/hex/percent/unicode content) have f.Match as the DECODED secret, which doesn't appear in the raw text. The encoded segment is spliced out via StartColumn/EndColumn offsets into the stripped buffer (see spliceByOffset).

After each finding's splice we VERIFY the secret is actually gone. If it survived — interleaved ANSI, a no-op replace, or a segment that couldn't be isolated — we fall back to over-redaction: replace the whole line, then the whole payload. Over-redaction is the only acceptable failure direction; a false "redacted" attestation is the one a secret scanner must never emit.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL