Shared PII redaction utilities used by error reporting adapters.
Shared PII redaction utilities used by error reporting adapters.
(apply-redaction context config)Apply PII redaction to a context map that may contain :tags and :extra.
Always applies default PII redaction, even when :redact is omitted.
Apply PII redaction to a context map that may contain :tags and :extra. Always applies default PII redaction, even when :redact is omitted.
(build-redact-state config)Build effective redaction configuration from adapter config.
Config structure (all optional):
{:redact {:keys [:password :authorization ...] :additional-keys [:custom-field] :mask-email? true}}
Build effective redaction configuration from adapter config.
Config structure (all optional):
{:redact {:keys [:password :authorization ...]
:additional-keys [:custom-field]
:mask-email? true}}Default set of keys whose values should be redacted before sending to external systems.
Names are in the form normalize-key-name produces: lower-case kebab, so
:access_token, "accessToken" and :access-token all match one entry.
Default set of keys whose values should be redacted before sending to external systems. Names are in the form `normalize-key-name` produces: lower-case kebab, so `:access_token`, `"accessToken"` and `:access-token` all match one entry.
(email-string? s)Best-effort detection of email-like strings.
Args: s: String to check
Returns: Boolean indicating if string looks like an email
Best-effort detection of email-like strings. Args: s: String to check Returns: Boolean indicating if string looks like an email
(mask-email s)Mask an email address, preserving only the first character of the local part.
For non-email strings, returns [REDACTED].
Mask an email address, preserving only the first character of the local part. For non-email strings, returns [REDACTED].
Names the suffix rules below would catch but that carry no secret.
Names the suffix rules below would catch but that carry no secret.
(normalize-key-name k)Normalize a map key to a lower-case kebab string for matching:
:Password, "password_hash" and "passwordHash" become
"password", "password-hash" and "password-hash".
Normalize a map key to a lower-case kebab string for matching: `:Password`, `"password_hash"` and `"passwordHash"` become "password", "password-hash" and "password-hash".
(redact-for-log data)Redact secrets in data before it is logged. Emails are left alone: logs
already carry them, and this is about credentials.
Redact secrets in `data` before it is logged. Emails are left alone: logs already carry them, and this is about credentials.
(redact-pii data state)Recursively redact PII from arbitrarily nested data structures.
Redacts based on key names using the provided redaction state.
Recursively redact PII from arbitrarily nested data structures. Redacts based on key names using the provided redaction state.
(redact-pii-value k v {:keys [keys mask-email?] :as _state})Redact a single value based on its key and redaction state.
Email is treated specially:
Redact a single value based on its key and redaction state. Email is treated specially: - when :mask-email? is true and the value looks like an email, the local part is masked - when :mask-email? is false, email values are left as-is, even if :email is in the default key set
(sensitive-key-name? keys kname)True when a normalized key name is in keys, or ends in -secret, -token,
-hash, -password or a credential-bearing -key (stripe-secret-key,
x-api-key). A bare -key suffix would also catch idempotency-key and
cache-key, so only the key kinds that are secrets are listed.
True when a normalized key name is in `keys`, or ends in -secret, -token, -hash, -password or a credential-bearing -key (`stripe-secret-key`, `x-api-key`). A bare -key suffix would also catch `idempotency-key` and `cache-key`, so only the key kinds that are secrets are listed.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |