Skip to content

fix: redact credentials in database connection URLs - #8

Open
varshith84 wants to merge 1 commit into
kittimzhe:mainfrom
varshith84:fix/database-url-redaction
Open

varshith84 wants to merge 1 commit into
kittimzhe:mainfrom
varshith84:fix/database-url-redaction

Conversation

@varshith84

Copy link
Copy Markdown

Closes #6.

Redact the username/password portion of PostgreSQL, Redis, and MySQL URLs in both mask and hash modes, retaining their scheme, host, port, and database path. Passwordless URLs remain intact, including user@host forms that would otherwise match the email rule. Update both README languages and regenerate the tracked bundle.

Validation:

  • npm run doctor: all checks passed
  • npm test: 219 passed
  • npm run typecheck, npm run bundle, and git diff --check: passed
  • New fixtures cover each scheme, empty usernames, encoded credentials, IPv6 hosts, punctuation, multiple occurrences, and passwordless URLs. The credential fixtures failed before the rule was added.

This is pattern-based best-effort redaction, consistent with the existing API. Prepared with Codex assistance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Redaction: add connection-string pattern (postgres/redis/mysql URLs with credentials)

1 participant