Documentation
¶
Overview ¶
Package redact removes caller-declared sensitive values from text destined for logs or operator diagnostics.
A Redactor matches exact, non-empty values and their URL-userinfo-escaped spellings. Callers own the policy decision about which values are sensitive; this package does not inspect configuration, errors, or process state.
Index ¶
Constants ¶
const Replacement = "[REDACTED]"
Replacement is the stable marker substituted for sensitive text.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Redactor ¶
type Redactor struct {
// contains filtered or unexported fields
}
Redactor is an immutable exact-value replacement policy. The zero value leaves text unchanged. A configured Redactor is safe for concurrent use.
func NewRedactor ¶
NewRedactor constructs a policy from caller-owned sensitive values. Empty values are ignored. Longer and URL-userinfo-escaped forms are matched before shorter values so overlapping credentials cannot be partially exposed.