Documentation
¶
Index ¶
Constants ¶
const ( DefaultReviewMax = 20 DefaultReviewTTL = 24 * time.Hour )
Review store defaults and limits.
const (
// Version is the only supported `version:` value.
Version = 1
)
Variables ¶
This section is empty.
Functions ¶
func BuiltinNeverSend ¶
func BuiltinNeverSend() []string
BuiltinNeverSend returns the embedded never_send globs.
func LoadSalt ¶
LoadSalt returns the per-install salt for stable placeholders. The file holds hex and must be 0600; it is created with fresh random bytes the first time. A missing path, a permissive mode or a malformed file fails closed.
func SchemaJSON ¶
func SchemaJSON() []byte
SchemaJSON returns the embedded JSON Schema for version 1.
Types ¶
type Config ¶
type Config struct {
// Options configures redact.New.
Options redact.Options
// NeverSend matches commands and paths whose output is never sent.
NeverSend *NeverSend
// Sources lists the config files that were loaded, lowest precedence first.
Sources []string
// RuleSource maps each custom rule id to the file that defines it.
RuleSource map[string]string
// Tests are the embedded `tests:` cases from every loaded file.
Tests []TestCase
// Review turns on storing the exact redacted payload of recent sends
// (redact.review or JEVKIT_REDACT_REVIEW). Off by default: stored
// payloads are themselves sensitive.
Review bool
// ReviewMax and ReviewTTL bound the review store.
ReviewMax int
ReviewTTL time.Duration
// Confirm asks for an interactive yes before an interactive send.
Confirm bool
}
Config is the resolved result of layering built-ins, user and project.
func Load ¶
func Load(o LoadOptions) (*Config, error)
Load resolves the layers, lowest to highest precedence: embedded built-ins, the USER file, the PROJECT file. A missing file is skipped. Any problem returns a *jev.Error with jev.CodeRejected wrapping a *Error that names the file and key; the caller must then send nothing.
func (*Config) Gate ¶
func (c *Config) Gate(ctx context.Context, subject, text string, send Send) (out, pattern string, sent bool, err error)
Gate runs never_send matching, then redaction, then send. subject is the command line or path that produced text. When subject matches a never_send pattern Gate returns sent=false and the matching pattern without redacting text or calling send: the output never leaves the machine. Any redaction failure returns its error and send is not called.
type Error ¶
type Error struct {
File string
// Key is the offending key path such as "rules[1].pattern"; empty when the
// whole file is at fault.
Key string
Msg string
}
Error describes one problem in one config file. Every Load failure wraps an *Error in a *jev.Error with jev.CodeRejected, so callers send nothing and hooks pass output through unchanged.
type LoadOptions ¶
type LoadOptions struct {
// UserPath is <config_dir>/redact.yaml (trusted; must be 0600).
UserPath string
// ProjectPath is <workspace>/.jevkit/redact.yaml (untrusted, additive only).
ProjectPath string
// SaltPath holds the per-install random salt for stable placeholders,
// created 0600 on first use.
SaltPath string
// Environ is the process environment (os.Environ()).
Environ []string
}
LoadOptions says where the layers live.
type NeverSend ¶
type NeverSend struct {
// contains filtered or unexported fields
}
NeverSend matches command lines and paths whose output must never reach Jev. It is consulted before any network use.
func NewNeverSend ¶
NewNeverSend compiles glob patterns.
type TestCase ¶
type TestCase struct {
// File is the config file that defined the case; set by Load.
File string `json:"-"`
Name string `json:"name"`
Input string `json:"input"`
MustNotContain []string `json:"must_not_contain"`
MustContain []string `json:"must_contain"`
}
TestCase is an embedded regression case from a `tests:` list: the engine is run on Input, and the output must contain every MustContain string and none of the MustNotContain strings.