pub struct Redactor { /* private fields */ }Expand description
Scrubs known secret values in addition to key-shaped ones.
Built once at startup from whatever credentials were configured, then shared. The literal pass matters for the OAuth client secret, which is the one credential we hold that need not look like a Tailscale key.
Redactor::for_credentials is how a session gets one, and
the_session_scrubs_its_own_credential is what keeps that call in place:
this said it was built from the configured credentials for four releases
during which nothing registered one, so the literal pass ran over an empty
list and only the shape rules did any work.
Implementations§
Source§impl Redactor
impl Redactor
pub fn new() -> Self
Sourcepub fn add_secret(&mut self, secret: impl Into<String>)
pub fn add_secret(&mut self, secret: impl Into<String>)
Register a value to remove wherever it appears. Very short values are ignored: scrubbing a two-character “secret” would mangle every message.
pub fn with_secret(self, secret: impl Into<String>) -> Self
Sourcepub fn for_credentials(credentials: Option<&Credentials>) -> Self
pub fn for_credentials(credentials: Option<&Credentials>) -> Self
The redactor a session runs with: shape rules, plus whatever secret values this session was actually configured with.
A federated credential contributes nothing, and that is not an omission: the JWT is read from disk at exchange time and never held, so at startup there is no value to register. What it is exchanged for is a bearer token, which the shape rules cover.