pub fn redact_data(
data: &Value,
fields: &[String],
amendment_id: &GovernanceLogId,
blind: Blind,
) -> Result<Value, RedactError>Expand description
data with the value at each RFC 6901 pointer in fields replaced by
redaction_marker.
Whole-value replacement only: a redaction tool that can write arbitrary
replacement prose is a rewrite tool. The server and every verifier share
this one definition, because what it returns is what the target’s
resulting_data_hash covers.
The entry’s Blind is replaced by blind — a fresh one, not a
marker. Destroying the old value is what stops a removed value being
confirmed against the entry’s original data_hash (see blind_data);
leaving a new one is what protects the next redaction of the same
entry, whose removed values could otherwise be tested against this
one’s public resulting_data_hash. An entry that predates blinding
gains one here. blind must be random outside tests.