Skip to main content

Module redaction

Module redaction 

Source
Expand description

Keeping secrets out of the store.

Everything the runtime persists can leak: the input (kept for identity, audit and handler recovery), the output (replayed to later callers), audit payloads, and error messages, which often echo tokens back. Two tools keep secrets out:

  • Secret<T>, the default. It serializes as "[REDACTED]", so a secret field in an input or output never reaches the store. Its Debug and Display print [REDACTED] too. The action sees the real value (it holds it in memory); what is read back from the store is a redacted Secret (Secret::expose returns None).
  • A Redactor on the runtime (RuntimeBuilder::redactor). It rewrites every input, output, audit payload and error message before it is written. RedactKeys masks fields by name at any depth.

Redaction happens before the input is fingerprinted, so secrets are not part of an effect’s identity and are never stored, not even hashed.

What is redacted cannot be replayed or resumed:

  • a later caller gets the redacted output;
  • a handler resumed by recovery gets the redacted input.

Keep credentials in the action’s captured state or in the handler, not in inputs.

Structs§

RedactKeys
Replaces the value of every object field with one of these names (case-insensitively, at any depth) with "[REDACTED]".
Secret
A value that must never be stored or logged.

Enums§

Field
Which persisted value a Redactor is looking at.

Constants§

REDACTED
What redacted values are replaced with.

Traits§

Redactor
Rewrites values before the runtime stores them. Applies to every effect the runtime runs, every transition it records and every operator decision.