1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
// =============================================================================
// Copyright (c) 2025 - 2026 Haixing Hu.
//
// SPDX-License-Identifier: Apache-2.0
//
// Licensed under the Apache License, Version 2.0.
// =============================================================================
//! Derive macros for `qubit-redact` domain objects.
use TokenStream;
/// Derives immutable redacted formatting for a struct or enum.
///
/// Named, tuple, and unit structs are accepted, as are enums with named,
/// tuple, and unit variants. Unmarked fields use ordinary `Debug` by default;
/// masking, recursion, map processing, and omission require explicit field
/// attributes. This derive macro deliberately does not infer which fields are
/// sensitive: type owners must classify newly added fields and choose the
/// appropriate attributes. Add `#[redact(require_explicit)]` as an opt-in
/// review aid to require every field to select a mode, and use
/// `#[redact(plain)]` for fields that should remain visible. It is not an
/// automatic privacy guarantee.
///
/// # Parameters
///
/// * `input` - Rust item annotated with `#[derive(Redact)]`.
///
/// # Returns
///
/// An implementation of `qubit_redact::Redact`, or a targeted compile error
/// when the input is a union, an attribute is unsafe or malformed, or the
/// runtime crate cannot be resolved.
/// Derives explicit logical in-place redaction for owned fields of a struct or
/// enum.
///
/// # Parameters
///
/// * `input` - Rust item annotated with `#[derive(RedactMut)]`.
///
/// # Returns
///
/// An implementation of `qubit_redact::RedactMut`, or a targeted compile
/// error for unsupported input or field capabilities.