kra-new/internal/server/middleware/redact.go

42 lines
1.7 KiB
Go

package middleware
import "strings"
// redactedValue replaces a sensitive value in every log line and audit record.
const redactedValue = "***"
// sensitiveHeaders lists the headers whose value never reaches a log, compared
// after lowercasing.
var sensitiveHeaders = map[string]struct{}{
"authorization": {}, "proxy-authorization": {}, "cookie": {}, "set-cookie": {}, "x-token": {},
}
// sensitivePayloadKeys holds the normalized query and JSON body keys whose
// values never reach a log or an operation record. Keys are compared after
// lowercasing and stripping separators, so "new_password" and "newPassword"
// both match "newpassword".
var sensitivePayloadKeys = map[string]struct{}{
"password": {}, "newpassword": {}, "oldpassword": {}, "confirmpassword": {},
"passwd": {}, "pwd": {}, "token": {}, "accesstoken": {}, "refreshtoken": {},
"secret": {}, "clientsecret": {}, "apikey": {}, "privatekey": {}, "idcard": {},
"appkey": {}, "mchkey": {}, "apiv3key": {}, "clientcert": {}, "clientkey": {},
"platformcert": {}, "platformserialno": {}, "credentialcode": {}, "certfile": {},
"keyfile": {}, "publickey": {}, "rootcert": {}, "appcert": {}, "webhookid": {},
"authorization": {},
}
func isSensitiveHeader(key string) bool {
_, sensitive := sensitiveHeaders[strings.ToLower(key)]
return sensitive
}
// isSensitivePayloadKey also matches every key ending in "token" so provider
// specific token names stay masked without being enumerated.
func isSensitivePayloadKey(key string) bool {
normalized := strings.ToLower(strings.ReplaceAll(strings.ReplaceAll(key, "_", ""), "-", ""))
if _, sensitive := sensitivePayloadKeys[normalized]; sensitive {
return true
}
return strings.HasSuffix(normalized, "token")
}