Expand description
Keeping secrets out of the store.
Everything the runtime persists can leak: the input (kept for identity, audit and handler recovery), the output (replayed to later callers), audit payloads, and error messages, which often echo tokens back. Two tools keep secrets out:
Secret<T>, the default. It serializes as"[REDACTED]", so a secret field in an input or output never reaches the store. ItsDebugandDisplayprint[REDACTED]too. The action sees the real value (it holds it in memory); what is read back from the store is a redactedSecret(Secret::exposereturnsNone).- A
Redactoron the runtime (RuntimeBuilder::redactor). It rewrites every input, output, audit payload and error message before it is written.RedactKeysmasks fields by name at any depth.
Redaction happens before the input is fingerprinted, so secrets are not part of an effect’s identity and are never stored, not even hashed.
What is redacted cannot be replayed or resumed:
- a later caller gets the redacted output;
- a handler resumed by recovery gets the redacted input.
Keep credentials in the action’s captured state or in the handler, not in inputs.
Structs§
- Redact
Keys - Replaces the value of every object field with one of these names
(case-insensitively, at any depth) with
"[REDACTED]". - Secret
- A value that must never be stored or logged.
Enums§
Constants§
- REDACTED
- What redacted values are replaced with.
Traits§
- Redactor
- Rewrites values before the runtime stores them. Applies to every effect the runtime runs, every transition it records and every operator decision.