mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-08 03:10:26 +00:00
fabro(01KWF7MM3VPXZZA8BTHJXE9VT1): simplify_gpt (succeeded)
Fabro-Run: 01KWF7MM3VPXZZA8BTHJXE9VT1
Fabro-Completed: 7
Fabro-Checkpoint: 94846118b8
⚒️ Generated with [Fabro](https://fabro.sh)
This commit is contained in:
parent
5f961f0723
commit
8a4e3c2d8d
1 changed files with 20 additions and 9 deletions
|
|
@ -9,7 +9,8 @@ use crate::Region;
|
|||
/// This complements the crate's content-based redaction by redacting registered
|
||||
/// values even when they do not look like credentials. Clones share the same
|
||||
/// registry so callers can hand a redactor to another subsystem and continue to
|
||||
/// register values through the original.
|
||||
/// register values through the original. Registered values are exact substring
|
||||
/// matches and may be low-entropy strings such as environment names.
|
||||
#[derive(Clone, Default)]
|
||||
pub struct SecretRedactor {
|
||||
values: Arc<RwLock<Vec<String>>>,
|
||||
|
|
@ -39,21 +40,19 @@ impl SecretRedactor {
|
|||
|
||||
/// Redact all registered secret values from `s`.
|
||||
pub fn redact_into(&self, s: &str) -> String {
|
||||
let values = self.read();
|
||||
if values.is_empty() {
|
||||
let Some(values) = self.values_snapshot() else {
|
||||
return s.to_string();
|
||||
}
|
||||
};
|
||||
redact_string_values(s, &values)
|
||||
}
|
||||
|
||||
/// Redact registered secret values from every JSON string leaf.
|
||||
/// Redact registered secret values from every JSON string value.
|
||||
///
|
||||
/// Object keys are left unchanged.
|
||||
/// Object keys and non-string values are left unchanged.
|
||||
pub fn redact_json(&self, mut value: Value) -> Value {
|
||||
let values = self.read();
|
||||
if values.is_empty() {
|
||||
let Some(values) = self.values_snapshot() else {
|
||||
return value;
|
||||
}
|
||||
};
|
||||
|
||||
redact_json_leaves(&mut value, &values);
|
||||
value
|
||||
|
|
@ -66,6 +65,14 @@ impl SecretRedactor {
|
|||
fn write(&self) -> RwLockWriteGuard<'_, Vec<String>> {
|
||||
self.values.write().unwrap_or_else(PoisonError::into_inner)
|
||||
}
|
||||
|
||||
fn values_snapshot(&self) -> Option<Vec<String>> {
|
||||
let values = self.read();
|
||||
if values.is_empty() {
|
||||
return None;
|
||||
}
|
||||
Some(values.clone())
|
||||
}
|
||||
}
|
||||
|
||||
fn redact_json_leaves(value: &mut Value, values: &[String]) {
|
||||
|
|
@ -107,6 +114,10 @@ fn redact_string_values(s: &str, values: &[String]) -> String {
|
|||
}
|
||||
}
|
||||
|
||||
if regions.is_empty() {
|
||||
return s.to_string();
|
||||
}
|
||||
|
||||
crate::redact_regions(s, regions)
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue