dvRedactSecrets function

String dvRedactSecrets(
  1. String text
)

Replaces every resolved secret value in text with a redaction marker.

The declaration makes the secrets an enumerable set and DVSecrets is the only thing that hands their values out, so a log line, a trace attribute or an exception message can be checked against the values themselves rather than against a list of key names that look suspicious. Matching on the key misses the cases that actually leak: a connection string filed under url, an upstream error quoting the credential back, a sentence somebody typed during an incident.

Only values that were resolved at least once can be matched, which is no real limit -- code cannot print a secret it never read -- and better said out loud than implied.

Implementation

String dvRedactSecrets(String text) => DVSecrets.redact(text);