Expand description
Secret redaction for every report sink. Secret redaction for every report sink.
All run output flows through crate::reporting::Reporter. The
[Redactor] held by the reporter replaces known secret values with
[REDACTED] before any sink (console, NDJSON, JUnit, GitHub, Perfetto)
sees the text, so a leaked API key or token can never make it into a log
or CI report.
Secrets come from three places, all funneled into one redactor:
- Config-derived —
collect_secrets_from_scenario_configgathersllm_api_key, per-endpoint API keys, Entra client secrets, AWS static credentials, and the values of sensitive-named headers, and the runner registers them on everycrate::runner::ScenarioRunnerit builds. - Runtime-obtained — tokens fetched by
crate::auth(token commands, header commands, Entra client-credentials and managed identity) are pushed into a process-global observed-secret registry via [observe_secret], which every [Redactor::redact] consults. They are registered before theLlmCallFinishedevent that describes the call is emitted, so the very event that echoes a token is redacted. - Explicit extras — callers add literal values via
Reporter::add_redaction_secret(the CLI’s--redact/HARNESS_REDACT), for secrets not present in the config (URL query tokens, scenario-embedded test data).
Redaction is exact-match, case-sensitive substring replacement. Values
shorter than [MIN_SECRET_LEN] are skipped when derived from config or
runtime sources so short, common strings (e.g. "dev") do not destroy
log readability — explicit extras always apply.
Raw eprintln! sites that bypass the reporter (the #[browser_test]
run-report strings, MCP/A2A server startup banners, the cost report)
are intentionally out of scope: they carry no secret-bearing text today.
Structs§
- Redactor
- Replaces known secret values in a string with
[REDACTED].
Functions§
- collect_
secrets_ from_ scenario_ config - Gathers the startup-known secrets of a (merged) scenario config: LLM API keys, endpoint credentials, and sensitive header values.
- observe_
secret - Registers a runtime-obtained secret so every subsequent
Redactor::redactcall replaces it: token-command output, header-command output, and Entra/IMDS access tokens.