Documentation
¶
Index ¶
- Constants
- func AllHits(v any) (ruleIDs []string, fields []string)
- func AllHitsToolOutput(v any) (ruleIDs []string, fields []string)
- func FirstHit(v any) (bool, string, []string)
- func FirstHitToolOutput(v any) (bool, string, []string)
- func Placeholder(f report.Finding) string
- func Redact(content string) (string, error)
- func RedactToolOutput(content string) (string, []string, error)
- func RedactTree(v any) (any, []string)
- func RedactTreeToolOutput(v any) (any, []string)
- func RedactWithMatches(content string) (string, []string, error)
- func Splice(content string, findings []report.Finding) string
Constants ¶
const MaxWalkDepth = 64
MaxWalkDepth bounds JSON-tree recursion against pathological MCP payloads. On exceedance: scanners under-detect, RedactTree leaves the subtree untouched — fail-safe in both directions, harnesses layer fail-open.
Variables ¶
This section is empty.
Functions ¶
func AllHits ¶
AllHits walks the tree and returns dedup'd rule IDs + dotted paths. HONORS allow/fixture markers — for AUTHORED trees (e.g. tool-call input args).
func AllHitsToolOutput ¶
AllHitsToolOutput is AllHits for UNTRUSTED tool-output trees: it does NOT honor allow/fixture markers (issue #56).
func FirstHit ¶
FirstHit walks v and returns (true, dotted-path, ruleIDs) on first match. Path shape: k1.k2[3].k4 (matches audit-log format). HONORS allow/fixture markers — for AUTHORED trees (e.g. an MCP tool's input args).
func FirstHitToolOutput ¶
FirstHitToolOutput is FirstHit for UNTRUSTED tool-output trees (WebFetch/MCP responses): it does NOT honor allow/fixture markers (issue #56).
func Placeholder ¶
Placeholder builds "<REDACTED:<rule-id>:<last-4-of-secret>>", omitting the fingerprint below minFingerprintLen.
func Redact ¶
Redact scans AUTHORED content and returns it with each credential-shape finding replaced by a placeholder. ANSI escapes are stripped from the scan target so colored output like "\x1b[31mAKIA…\x1b[0m" still matches. Fail-open on detector init: returns original content + error.
This is an authored-content entry point: inline allow/fixture markers (ctxcop:allow, ctxcop:fixture, gitleaks:allow) are honored. For untrusted tool output use RedactToolOutput.
func RedactToolOutput ¶
RedactToolOutput redacts UNTRUSTED tool output / transcripts. It behaves like RedactWithMatches but does NOT honor inline allow/fixture markers: a secret in a Bash output stream, a WebFetch/MCP response, a Read'd file, or a compaction transcript is redacted even when it sits next to `gitleaks:allow` or `# ctxcop:allow` — whether that marker was planted by an attacker or emitted by something like `sed 's/$/ # ctxcop:allow/'` (issue #56). Marker honoring is reserved for content the developer authored.
func RedactTree ¶
RedactTree returns a deep copy of v with every string redacted, plus the dedup'd rule IDs that fired. Non-string scalars and unsupported types pass through unchanged. HONORS allow/fixture markers — for AUTHORED or outbound trees.
func RedactTreeToolOutput ¶
RedactTreeToolOutput is RedactTree for UNTRUSTED tool-output trees (WebFetch/MCP responses): it does NOT honor allow/fixture markers so a planted marker can't suppress redaction of the response (issue #56).
func RedactWithMatches ¶
RedactWithMatches is Redact + the rule IDs that fired (for audit). It HONORS inline allow/fixture markers and is for AUTHORED content only (Write/Edit/ NotebookEdit scanning, `ctxcop scan`, prompt/command/tool-input checks).
func Splice ¶
Splice replaces every finding's matched substring with a placeholder and guarantees, per finding, that the secret cannot survive in the output.
Detection runs on the ANSI-stripped buffer, so decoded findings' byte offsets are relative to stripANSI(content). We reproduce that buffer here (stripANSI is deterministic) and resolve offsets against it — never against the original content, whose length and byte positions differ once ANSI is present or an earlier surface replacement has run.
Surface findings (rule matched raw content) use strings.ReplaceAll on f.Match — UTF-8 safe and position-independent.
Decoded findings (`decoded:*` tag — rule matched base64/hex/percent/unicode content) have f.Match as the DECODED secret, which doesn't appear in the raw text. The encoded segment is spliced out via StartColumn/EndColumn offsets into the stripped buffer (see spliceByOffset).
After each finding's splice we VERIFY the secret is actually gone. If it survived — interleaved ANSI, a no-op replace, or a segment that couldn't be isolated — we fall back to over-redaction: replace the whole line, then the whole payload. Over-redaction is the only acceptable failure direction; a false "redacted" attestation is the one a secret scanner must never emit.
Types ¶
This section is empty.