secretref

package
v1.142.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

Documentation

Overview

Package secretref is the reference to a stored secret a caller writes into a request, `{{secret:<name>}}`, and the redaction of a secret's value from whatever comes back (#2051).

A placeholder is filled at the last moment, as the request is built for sending, so everything that records the call (the audit row, the call record, a script's recording, the arguments a cut response hands back) holds the placeholder and never the value. What the upstream sends back is then put through a Redactor holding the values the request carried, so an upstream that echoes one cannot hand it to the caller.

The package knows nothing about where secrets are stored or who may use them: a Lookup answers for one name, and refuses by name.

Index

Constants

View Source
const MinValueLength = 6

MinValueLength is the shortest value a secret may hold. Redaction replaces every occurrence of a value in a response, and a value of a character or two would rewrite ordinary text.

View Source
const NamePattern = `[a-z0-9][a-z0-9_.-]{0,62}`

NamePattern is the grammar of a secret's name: lower case, digits, and . _ - after the first character. It is narrow so a name reads the same in a placeholder, a URL and a log line.

View Source
const TOTPPrefix = "totp:"

TOTPPrefix qualifies the name a {{totp:<name>}} placeholder is looked up by: Lookup is asked for "totp:<name>", which no secret can be called, so one lookup answers both kinds and tells them apart.

Variables

View Source
var ErrMalformed = errors.New("malformed secret placeholder")

ErrMalformed is wrapped by the refusal of text that opens a placeholder and does not complete one.

Functions

func Fill

func Fill(s string, lookup Lookup, escape func(string) string) (string, error)

Fill replaces each placeholder in s with its secret's value as escape writes it. A placeholder whose lookup fails fails the fill, and so does text that opens a placeholder without completing one: neither is ever sent as written.

func FillConnection added in v1.142.0

func FillConnection(ctx context.Context, connection, s string, escape func(string) string) (string, error)

FillConnection fills the placeholders in one value of connection's configuration, escaping each value with escape.

func FillPath

func FillPath(path string, lookup Lookup) (string, error)

FillPath fills the placeholders of a request path, in either form a path carries one: as the caller wrote it, or with its braces escaped by path_params substitution. The value is path-escaped, so it cannot add a segment.

func FillStrings

func FillStrings(m map[string]string, lookup Lookup) (map[string]string, error)

FillStrings fills the values of a string map, returning a copy.

func FillValue

func FillValue(v any, lookup Lookup) (any, error)

FillValue fills every string in a JSON-shaped value (maps, lists and strings, nested), returning a copy: the value the caller passed is the one recorded, and keeps its placeholders. Map keys are filled too.

func HasPlaceholder added in v1.142.0

func HasPlaceholder(s string) bool

HasPlaceholder reports whether s names a stored secret, or opens a placeholder that Fill would refuse as malformed.

func IsPlaceholder added in v1.142.0

func IsPlaceholder(s string) bool

IsPlaceholder reports whether s is exactly one placeholder: a reference with nothing secret written beside it, which a connection's configuration can read back as written.

func IsTOTPName added in v1.142.0

func IsTOTPName(qualified string) (string, bool)

IsTOTPName reports whether a lookup was asked for a one-time code, and returns the secret's own name.

func JSONString

func JSONString(s string) string

JSONString writes a value as the inside of a JSON string, for a body sent as JSON text.

func Malformed added in v1.142.0

func Malformed(s string) bool

Malformed reports whether s opens a placeholder it does not complete, which Fill refuses rather than sending as written.

func Names added in v1.142.0

func Names(s string) []string

Names returns the names s's placeholders are looked up by, in order, each once: a secret's name, or TOTPName of one for {{totp:<name>}}.

func Raw

func Raw(s string) string

Raw writes a value as it is: for a body object, query values and header values, which are encoded on their way out.

func Redaction

func Redaction(name string) string

Redaction is what a value is replaced with in a response.

func TOTPName added in v1.142.0

func TOTPName(name string) string

TOTPName is the name a lookup is asked for to fill {{totp:<name>}}.

func Transport

func Transport(base http.RoundTripper) http.RoundTripper

Transport wraps base so that a response to a request whose context carries a Redactor with values in it comes back with them redacted: from every header value, and from the body as it is read, however it is read. A request that filled no placeholder passes through untouched.

The redacted body is a different length from the one the upstream sent, so its declared length is dropped.

func ValidName

func ValidName(name string) bool

ValidName reports whether name is one a secret can be stored under.

func WithoutPlaceholders added in v1.142.0

func WithoutPlaceholders(s string) string

WithoutPlaceholders is s with every placeholder removed, for a check on the text an operator wrote around one: a placeholder's own ':' is not a colon in a Basic auth userid.

Types

type ConnectionSource added in v1.142.0

type ConnectionSource func(ctx context.Context, name, connection string) (string, error)

ConnectionSource reads a stored secret on behalf of the connection whose own configuration names it (secretstore.Store.ConnectionValue): the value, or a refusal naming the secret and the connection.

func SetConnectionSource added in v1.142.0

func SetConnectionSource(src ConnectionSource) ConnectionSource

SetConnectionSource installs the source a connection's configuration is filled from (#2066), and returns the one it replaces so a test can put it back. The platform installs its store once at startup; a nil src removes it, after which a configuration naming a secret is refused when it is used.

type Lookup

type Lookup func(name string) (string, error)

Lookup returns a secret's value, or an error that names the secret and says why it may not be used here. A {{totp:<name>}} placeholder is looked up as TOTPName(name), and answered with the current code.

func ConnectionLookup added in v1.142.0

func ConnectionLookup(ctx context.Context, connection string) Lookup

ConnectionLookup is the lookup a connection's own configuration is filled through as a request is sent: a credential, a header the operator fixed, a sign-in body. Each value is read from the installed source as of this moment, so a rotated secret is used from the next request on, and is recorded on ctx's Redactor so a response that echoes it is redacted.

type Redactor

type Redactor struct {
	// contains filtered or unexported fields
}

Redactor replaces the values of the secrets one call used with their redaction. A call adds each value as it fills it; the response side then passes everything it returns through the Redactor.

Each value is matched as written and in the forms an upstream echoes one in: escaped inside a JSON string (once, or twice for a JSON body echoed inside JSON), and query- and path-escaped.

func FromContext

func FromContext(ctx context.Context) *Redactor

FromContext is the call's Redactor, or nil when the call made none, which every method treats as empty.

func WithRedactor

func WithRedactor(ctx context.Context) (context.Context, *Redactor)

WithRedactor returns ctx carrying a fresh Redactor, and the Redactor, for one call: the request side adds to it, the response side reads it.

func (*Redactor) Add

func (r *Redactor) Add(name, value string)

Add records a value a call sent under name.

func (*Redactor) Bytes

func (r *Redactor) Bytes(b []byte) []byte

Bytes returns b with every recorded value replaced.

func (*Redactor) Empty

func (r *Redactor) Empty() bool

Empty reports whether no value was recorded, so a caller can skip the pass over a response that cannot need it.

func (*Redactor) Error

func (r *Redactor) Error(err error) string

Error is err's message with every recorded value replaced.

func (*Redactor) Reader

func (r *Redactor) Reader(src io.ReadCloser) io.ReadCloser

Reader redacts a stream, for a response written somewhere without being held whole. It holds back the bytes that could be the start of a value until the next read shows whether they are.

func (*Redactor) Recording

func (r *Redactor) Recording(lookup Lookup) Lookup

Recording returns lookup with every value it answers recorded on r, so the response to the request it fills is redacted of them. A one-time code is not recorded (#2065): six to eight digits would rewrite ordinary numbers in a response, and the code is useless once its period passes. The seed it was computed from is recorded by the lookup that read it.

func (*Redactor) String

func (r *Redactor) String(s string) string

String returns s with every recorded value replaced.

func (*Redactor) Strings

func (r *Redactor) Strings(h map[string][]string)

Strings redacts each value of a header-shaped map in place.

type Request

type Request struct {
	Path        string
	Headers     map[string]string
	Query       map[string]any
	Body        any
	ContentType string
}

Request is the parts of an outbound request a placeholder may sit in. ContentType is the type the body will be sent as, which says how a value written into a string body is escaped.

func FillRequest

func FillRequest(req Request, lookup Lookup) (Request, error)

FillRequest returns req with every placeholder in its path, headers, query and body filled through lookup. req itself is not changed, so what a caller recorded keeps its placeholders.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL