20 lines
845 B
TypeScript
20 lines
845 B
TypeScript
export const REDACTED = "[REDACTED]";
|
|
|
|
// scheme://user:password@host — only redacts when a password is present, so
|
|
// ordinary URLs (with or without a userinfo) are left untouched.
|
|
const URL_CREDENTIALS = /\b([a-z][a-z0-9+.-]*:\/\/)[^/\s@]+:[^/\s@]*@/gi;
|
|
|
|
// AWS access key ID (AKIA prefix + 16 uppercase alphanumeric chars).
|
|
const AWS_ACCESS_KEY_ID = /\bAKIA[0-9A-Z]{16}\b/g;
|
|
|
|
// OpenSSH and other PEM private key headers embedded anywhere in a string.
|
|
const PRIVATE_KEY_HEADER = /-----BEGIN [A-Z ]*PRIVATE KEY-----/g;
|
|
|
|
/** Redact common credential-bearing substrings while leaving everything else intact. */
|
|
export function redactString(value: string): string {
|
|
return value
|
|
.replace(AWS_ACCESS_KEY_ID, REDACTED)
|
|
.replace(PRIVATE_KEY_HEADER, REDACTED)
|
|
.replace(URL_CREDENTIALS, (_match, scheme) => `${scheme}${REDACTED}@`);
|
|
}
|