Documentation
¶
Overview ¶
Package secretscreen holds the secret-shaped-text detector Corvint's local writers share plus immutable stored-format compatibility matchers. Before this package existed, internal/trace and internal/contextindex each carried a byte-for-byte-identical copy of the same pattern with no parity test between them; see docs/agent-memory/fixes.md 2026-09-01 "observations ledger has no secret screen; secret regex duplicated in two packages".
Index ¶
Constants ¶
const Placeholder = "[REDACTED]"
Placeholder replaces every secret-shaped match Screen redacts.
Variables ¶
var Pattern = regexp.MustCompile(`(?i)` + writerQuotedAssignmentAlt + `|` + awsAccessKeyIDWithSecretAlt + `|` + authorizationSchemeAlt + `|` +
writerURLTokenUserinfoAlt + `|` +
secretPattern(writerAssignmentFields, writerCredentialedURLAlt) + `|"` + writerAssignmentFields + `"[` + pythonWhitespace + `]*:[` + pythonWhitespace + `]*(?:"(?:[^"\\]|\\[\s\S])*(?:"|\\?\z)|[^` + pythonWhitespace + `]+)|` +
writerOnlyVendorAlt + `|` + writerCredentialFlagAlt)
Pattern is the current secret-shaped-text detector: key=value/key: value, quoted credential values (bare assignment or double-quoted JSON property, whole lexical strings, including escaped quotes and whitespace, without JSON escape decoding; unterminated values extend through absolute EOF, including a dangling backslash), credential assignments, the credential after an authorization scheme word, private-key headers, credentialed URLs (including a raw `@` in the password and token-shaped userinfo), command-line credential flags, an AWS access-key ID paired with its adjacent secret, and known vendor token shapes (GitHub, GitLab, Slack, AWS, Azure account keys, Google, npm, Stripe, PyPI, SendGrid, Shopify, Svix/Stripe webhook secrets, Hugging Face, DigitalOcean, bearer tokens, and JWT-shaped strings).
var StoredV1Pattern = regexp.MustCompile(secretPattern(`[a-z0-9_.-]*(?:`+storedV1AssignmentNames+`)[a-z0-9_.-]*`, storedV1CredentialedURLAlt))
StoredV1Pattern preserves the detector used when schema-version 1 trace rows were written. It is intentionally narrower than the current writer screen so a detector expansion cannot invalidate immutable stored rows.
Functions ¶
func MatchStoredV1String ¶
MatchStoredV1String reports whether text matches the immutable schema-v1 trace detector. New writes must use MatchString instead.
func MatchString ¶
MatchString reports whether text contains secret-shaped content for new writes and Git-history candidate filtering. Stored traces use the v1 matcher.
Types ¶
This section is empty.