mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-08 03:10:26 +00:00
fabro(01KWF7MM3VPXZZA8BTHJXE9VT1): simplify_gpt (succeeded)
Fabro-Run: 01KWF7MM3VPXZZA8BTHJXE9VT1
Fabro-Completed: 7
Fabro-Checkpoint: 94846118b8
⚒️ Generated with [Fabro](https://fabro.sh)
This commit is contained in:
parent
5f961f0723
commit
8a4e3c2d8d
1 changed files with 20 additions and 9 deletions
|
|
@ -9,7 +9,8 @@ use crate::Region;
|
||||||
/// This complements the crate's content-based redaction by redacting registered
|
/// This complements the crate's content-based redaction by redacting registered
|
||||||
/// values even when they do not look like credentials. Clones share the same
|
/// values even when they do not look like credentials. Clones share the same
|
||||||
/// registry so callers can hand a redactor to another subsystem and continue to
|
/// registry so callers can hand a redactor to another subsystem and continue to
|
||||||
/// register values through the original.
|
/// register values through the original. Registered values are exact substring
|
||||||
|
/// matches and may be low-entropy strings such as environment names.
|
||||||
#[derive(Clone, Default)]
|
#[derive(Clone, Default)]
|
||||||
pub struct SecretRedactor {
|
pub struct SecretRedactor {
|
||||||
values: Arc<RwLock<Vec<String>>>,
|
values: Arc<RwLock<Vec<String>>>,
|
||||||
|
|
@ -39,21 +40,19 @@ impl SecretRedactor {
|
||||||
|
|
||||||
/// Redact all registered secret values from `s`.
|
/// Redact all registered secret values from `s`.
|
||||||
pub fn redact_into(&self, s: &str) -> String {
|
pub fn redact_into(&self, s: &str) -> String {
|
||||||
let values = self.read();
|
let Some(values) = self.values_snapshot() else {
|
||||||
if values.is_empty() {
|
|
||||||
return s.to_string();
|
return s.to_string();
|
||||||
}
|
};
|
||||||
redact_string_values(s, &values)
|
redact_string_values(s, &values)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Redact registered secret values from every JSON string leaf.
|
/// Redact registered secret values from every JSON string value.
|
||||||
///
|
///
|
||||||
/// Object keys are left unchanged.
|
/// Object keys and non-string values are left unchanged.
|
||||||
pub fn redact_json(&self, mut value: Value) -> Value {
|
pub fn redact_json(&self, mut value: Value) -> Value {
|
||||||
let values = self.read();
|
let Some(values) = self.values_snapshot() else {
|
||||||
if values.is_empty() {
|
|
||||||
return value;
|
return value;
|
||||||
}
|
};
|
||||||
|
|
||||||
redact_json_leaves(&mut value, &values);
|
redact_json_leaves(&mut value, &values);
|
||||||
value
|
value
|
||||||
|
|
@ -66,6 +65,14 @@ impl SecretRedactor {
|
||||||
fn write(&self) -> RwLockWriteGuard<'_, Vec<String>> {
|
fn write(&self) -> RwLockWriteGuard<'_, Vec<String>> {
|
||||||
self.values.write().unwrap_or_else(PoisonError::into_inner)
|
self.values.write().unwrap_or_else(PoisonError::into_inner)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn values_snapshot(&self) -> Option<Vec<String>> {
|
||||||
|
let values = self.read();
|
||||||
|
if values.is_empty() {
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
Some(values.clone())
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
fn redact_json_leaves(value: &mut Value, values: &[String]) {
|
fn redact_json_leaves(value: &mut Value, values: &[String]) {
|
||||||
|
|
@ -107,6 +114,10 @@ fn redact_string_values(s: &str, values: &[String]) -> String {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if regions.is_empty() {
|
||||||
|
return s.to_string();
|
||||||
|
}
|
||||||
|
|
||||||
crate::redact_regions(s, regions)
|
crate::redact_regions(s, regions)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue