Files
trufflehog/pkg/log/redaction_core.go
Cody Rose f42f63271b Create global log redaction capability (#3522)
Some source use client libraries that can emit errors that contain sensitive information - in particular, git-facing libraries that embed tokens into repository URLs. This PR introduces a way of redacting them - starting with GitLab (where we've seen this most recently), but in theory extensible to other sources as needed.

This implementation uses a custom zap core; this might also be possible with a custom zap encoder, but I didn't test it out.

(The deleted core.go file was entirely unused.)
2024-10-29 09:44:07 -04:00

43 lines
1.4 KiB
Go

package log
import (
"go.uber.org/zap/zapcore"
)
// redactionCore wraps a zapcore.Core to perform redaction of log messages in
// the message and field values.
type redactionCore struct {
zapcore.Core
redactor *dynamicRedactor
}
// NewRedactionCore creates a zapcore.Core that performs redaction of logs in
// the message and field values.
func NewRedactionCore(core zapcore.Core, redactor *dynamicRedactor) zapcore.Core {
return &redactionCore{core, redactor}
}
// Check overrides the embedded zapcore.Core Check() method to add the
// redactionCore to the zapcore.CheckedEntry.
func (c *redactionCore) Check(ent zapcore.Entry, ce *zapcore.CheckedEntry) *zapcore.CheckedEntry {
if c.Enabled(ent.Level) {
return ce.AddCore(ent, c)
}
return ce
}
func (c *redactionCore) With(fields []zapcore.Field) zapcore.Core {
return NewRedactionCore(c.Core.With(fields), c.redactor)
}
// Write overrides the embedded zapcore.Core Write() method to redact the message and fields before passing them to be
// written. Only message and string values are redacted; keys and non-string values (e.g. those inside of arrays and
// structured objects) are not redacted.
func (c *redactionCore) Write(ent zapcore.Entry, fields []zapcore.Field) error {
ent.Message = c.redactor.redact(ent.Message)
for i := range fields {
fields[i].String = c.redactor.redact(fields[i].String)
}
return c.Core.Write(ent, fields)
}