mirror of
https://github.com/jcreek/CosmicClash.git
synced 2026-09-11 00:14:00 +00:00
fix(multiplayer): harden observability redaction
This commit is contained in:
@@ -45,19 +45,57 @@ func redact(key string, value any) any {
|
||||
}
|
||||
}
|
||||
switch typed := value.(type) {
|
||||
case string:
|
||||
if looksLikeCredential(typed) {
|
||||
return "[REDACTED]"
|
||||
}
|
||||
return typed
|
||||
case map[string]any:
|
||||
copy := make(map[string]any, len(typed))
|
||||
for key, value := range typed {
|
||||
copy[key] = redact(key, value)
|
||||
}
|
||||
return copy
|
||||
case map[string]string:
|
||||
copy := make(map[string]string, len(typed))
|
||||
for key, value := range typed {
|
||||
redacted := redact(key, value)
|
||||
copy[key] = redacted.(string)
|
||||
}
|
||||
return copy
|
||||
case []any:
|
||||
copy := make([]any, len(typed))
|
||||
for i, value := range typed {
|
||||
copy[i] = redact("item", value)
|
||||
}
|
||||
return copy
|
||||
case []string:
|
||||
copy := make([]string, len(typed))
|
||||
for i, value := range typed {
|
||||
copy[i] = redact("item", value).(string)
|
||||
}
|
||||
return copy
|
||||
default:
|
||||
return value
|
||||
}
|
||||
}
|
||||
|
||||
func looksLikeCredential(value string) bool {
|
||||
trimmed := strings.TrimSpace(value)
|
||||
if strings.HasPrefix(strings.ToLower(trimmed), "bearer ") || strings.Contains(trimmed, "-----BEGIN ") {
|
||||
return true
|
||||
}
|
||||
parts := strings.Split(trimmed, ".")
|
||||
if len(parts) == 3 && len(parts[0]) >= 8 && len(parts[1]) >= 8 && len(parts[2]) >= 8 {
|
||||
return true // compact JWT-like credential
|
||||
}
|
||||
if len(trimmed) < 40 || strings.ContainsAny(trimmed, " \t\r\n") {
|
||||
return false
|
||||
}
|
||||
hasLetter, hasDigit := false, false
|
||||
for _, ch := range trimmed {
|
||||
hasLetter = hasLetter || (ch >= 'A' && ch <= 'Z') || (ch >= 'a' && ch <= 'z')
|
||||
hasDigit = hasDigit || (ch >= '0' && ch <= '9')
|
||||
}
|
||||
return hasLetter && hasDigit
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user