sanitize

package
v0.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 14, 2026 License: MIT Imports: 1 Imported by: 0

Documentation

Overview

Package sanitize holds the redaction policy seam shared by the client and server halves of this library.

It lives on its own, and imports nothing but net/http, for the same reason lifecycle does: both client and server need this type, and neither should have to import the other to get it. A service with one redaction policy can hand the same value to an outgoing client and to an inbound request logger.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type NoopSanitizer

type NoopSanitizer struct{}

NoopSanitizer returns everything it is given, unchanged.

It is the default everywhere this package is used, which means a caller that installs no policy logs URLs, headers and bodies verbatim — Authorization headers, cookies, session tokens and any credential carried in a URL path or query included. That is a deliberate choice to leave redaction entirely to the caller, but it makes installing a real Sanitizer the first thing to reach for in any service whose traffic carries credentials.

func NewNoopSanitizer

func NewNoopSanitizer() *NoopSanitizer

NewNoopSanitizer returns a Sanitizer that redacts nothing.

func (*NoopSanitizer) SanitizeBody

func (s *NoopSanitizer) SanitizeBody(b []byte) []byte

SanitizeBody returns b unchanged.

func (*NoopSanitizer) SanitizeHeaders

func (s *NoopSanitizer) SanitizeHeaders(h http.Header) http.Header

SanitizeHeaders returns h unchanged.

func (*NoopSanitizer) SanitizeURL

func (s *NoopSanitizer) SanitizeURL(u string) string

SanitizeURL returns u unchanged.

type Sanitizer

type Sanitizer interface {
	// SanitizeURL renders a URL for logging. The input is the full URL string,
	// credentials and query included.
	SanitizeURL(u string) string
	// SanitizeHeaders renders a header set for logging.
	SanitizeHeaders(h http.Header) http.Header
	// SanitizeBody renders a body for logging. It is only called where body
	// logging is enabled; the returned bytes are truncated afterwards, so an
	// implementation need not bound its own output.
	SanitizeBody(b []byte) []byte
}

Sanitizer decides what a request or response may look like in a log record.

Callers pass it every URL, header set and body they are about to log, and use whatever comes back. What counts as a secret is caller knowledge — one service treats X-Api-Key as a credential, another uses it as a routing hint — so the library provides the seam and the caller provides the policy.

Implementations MUST NOT mutate their argument. The header map and the body belong to a live request: http.Client re-enters RoundTrip with the same *http.Request on retries and redirects, so a mutating sanitizer corrupts the second attempt. Return a copy instead.

Implementations should also be cheap and total. They run on every logged exchange, and a panic inside one propagates out of the caller — logging is a side effect, and it should never be the reason a request fails.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL