redact

package
v0.6.1-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: Apache-2.0 Imports: 2 Imported by: 0

Documentation

Overview

Package redact takes the SHAPE of a secret out of text before anything keeps it, shows it, or sends it to a model.

── WHY THIS EXISTS ──

A worker ran `gh auth token`. The tool result came back as thirty-six characters of live OAuth credential, and those characters were then written verbatim into two task journals on the person's disk, drawn on their screen, and sent back to the model on every request for the rest of the run. None of the three ever needed them. A journal is a record of what happened, and "a token came back" is the whole of what happened. A screen is being read by the person whose token it already is. AND THE MODEL NEVER NEEDS A CREDENTIAL'S CHARACTERS: a shell command that has to USE one already has it in its own environment, which is exactly why `gh auth token` was run inside `TOKEN=$(…)` rather than for the model to read.

── THE TABLE IS SHAPES, NOT SERVICES ──

Every row of [shapes] is one SHAPE a secret takes, written as one pattern with one comment saying which secrets wear it. There is deliberately no branch on a service name, no list of hosts, and no per-provider function: a provider that starts minting `sk-` keys tomorrow is covered the day it launches, and a provider that invents a genuinely new shape is one more row here rather than a change anywhere else.

── NO RANDOM BYTE SURVIVES ──

A marker keeps a few leading characters so a person reading the record can tell WHICH kind of thing was taken out — `[redacted token · gho_…]` says a GitHub token was here where a bare `[redacted]` says only that something was. The characters it keeps are the token's OWN FIXED PREFIX and never one byte of its random part, which is why [shape.lead] is a per-row number rather than a constant four: `gho_` is four characters of prefix, `github_pat_` is eleven, and both are printed on every token of their kind anyway. A shape whose secret has no fixed prefix keeps nothing.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Secrets

func Secrets(text string) string

Secrets replaces every secret-shaped span in text with a marker naming what was taken out of it.

It is PURE and it is TOTAL: the same text in gives the same text out, it touches no disk and no clock, and text with nothing secret-shaped in it comes back as the identical string. That is what lets it sit on the one door every tool result passes through without anything downstream having to know it is there.

WHAT IT COSTS, because it runs on every result: roughly 10 MB/s on an M3 (BenchmarkSecretsOnALargeCleanResult), which is one pass per row of the table over text that has nothing in it. Every tool on the belt truncates its own output at 50KB (internal/exec/bare's truncation), so the largest result this can be handed costs well under a millisecond — beside a shell call that took seconds to produce it. There is no screening pass and no cache, because at that ratio either would be more machinery than it saved.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL