feat: secrets redact from logs via config redaction layer and server redacting logger (E00-S04-T03)

This commit is contained in:
implementer
2026-08-30 03:52:52 +00:00
parent ebb9d4f421
commit 6458013306
7 changed files with 222 additions and 11 deletions
+10 -2
View File
@@ -11,8 +11,15 @@
* and `ConfigStartupError` — names each violating field), so the application
* fails fast at startup when a required setting is missing.
*
* The environment adapter (E00-S04-T04) and secret redaction (E00-S04-T03)
* build on this boundary in later tasks.
* [E00-S04-T03] Secret redaction: the boundary also exposes the redaction
* layer (`redactConfig` — a config value with every secret replaced by
* `[REDACTED]`, for logging the resolved configuration — and `redactText` —
* scrubbing free-form log text of the config's secret values), which the
* server's redacting logger applies to every log line, so secrets
* automatically redact from logs.
*
* The environment adapter (E00-S04-T04) builds on this boundary in a later
* task.
*/
export { configSchema } from './schema.js';
@@ -20,3 +27,4 @@ export type { Config } from './schema.js';
export { validateConfig } from './validate.js';
export type { ConfigValidationResult } from './validate.js';
export { assertValidConfig, ConfigStartupError, MissingRequiredSettingError } from './startup.js';
export { REDACTED, SECRET_FIELD_NAMES, redactConfig, redactText } from './redact.js';