Skip to main content

Module redact

Module redact 

Source
Expand description

Secret redaction for every report sink. Secret redaction for every report sink.

All run output flows through crate::reporting::Reporter. The Redactor held by the reporter replaces known secret values with [REDACTED] before any sink (console, NDJSON, JUnit, GitHub, Perfetto) sees the text, so a leaked API key or token can never make it into a log or CI report.

Secrets come from three places, all funneled into one redactor:

  • Config-derived — collect_secrets_from_scenario_config gathers llm_api_key, per-endpoint API keys, Entra client secrets, AWS static credentials, and the values of sensitive-named headers, and the runner registers them on every crate::runner::ScenarioRunner it builds.
  • Runtime-obtained — tokens fetched by crate::auth (token commands, header commands, Entra client-credentials and managed identity) are pushed into a process-global observed-secret registry via observe_secret, which every Redactor::redact consults. They are registered before the LlmCallFinished event that describes the call is emitted, so the very event that echoes a token is redacted.
  • Explicit extras — callers add literal values via Reporter::add_redaction_secret (the CLI’s --redact / HARNESS_REDACT), for secrets not present in the config (URL query tokens, scenario-embedded test data).

Redaction is exact-match, case-sensitive substring replacement. Values shorter than [MIN_SECRET_LEN] are skipped when derived from config or runtime sources so short, common strings (e.g. "dev") do not destroy log readability — explicit extras always apply.

Raw eprintln! sites that bypass the reporter (the #[browser_test] run-report strings, MCP/A2A server startup banners, the cost report) are intentionally out of scope: they carry no secret-bearing text today.

Structs§

Redactor
Replaces known secret values in a string with [REDACTED].

Functions§

collect_secrets_from_scenario_config
Gathers the startup-known secrets of a (merged) scenario config: LLM API keys, endpoint credentials, and sensitive header values.
observe_secret
Registers a runtime-obtained secret so every subsequent Redactor::redact call replaces it: token-command output, header-command output, and Entra/IMDS access tokens.