Skip to content

Redact credentials without mangling surrounding text - #17

Merged
openai0229 merged 1 commit into
mainfrom
fix/redaction-boundaries
Sep 20, 2026
Merged

openai0229 merged 1 commit into
mainfrom
fix/redaction-boundaries

Conversation

@openai0229

Copy link
Copy Markdown
Contributor

What

redact() replaced the password and username anywhere they appeared as plain substrings. Testing the Oracle failure path showed the consequence: with the password oracle, the driver's documentation URL came out as https://docs.[redacted].com/error-help/db/ora-17002/, and a short username such as app would rewrite every application in a message.

A secret is now replaced only when it stands alone: the character before and after it must be neither alphanumeric nor a dot. Credentials echoed in connection text (jdbc:mysql://app:s3cret@db:3306/app) are still redacted, hostnames and ordinary words are left intact.

Verification

cargo test -p sqlx-protocol adds two unit tests:

redact("https://docs.oracle.com/error-help/db/ora-17002/", user=app, password=oracle)
  → unchanged
redact("the application could not start", …)                     → unchanged
redact("password authentication failed for user \"app\" with s3cret", …)
  → password authentication failed for user \"[redacted]\" with [redacted]
redact("jdbc:mysql://app:s3cret@db:3306/app", …)
  → jdbc:mysql://[redacted]:[redacted]@db:3306/[redacted]

cargo fmt --all -- --check and cargo clippy --workspace --all-targets --locked -- -D warnings passed.

Risks and limits

  • A secret glued to a word or a longer hostname (for example a password that is a substring of the database name) is no longer redacted there; the credential itself is still hidden wherever it appears on its own.
  • Redaction is best-effort output hygiene, not a security boundary.

@openai0229
openai0229 merged commit 3baa5e8 into main Sep 20, 2026
9 checks passed
@openai0229
openai0229 deleted the fix/redaction-boundaries branch September 20, 2026 11:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant