dvRedactSecrets function
Replaces every resolved secret value in text with a redaction marker.
The declaration makes the secrets an enumerable set and DVSecrets is the
only thing that hands their values out, so a log line, a trace attribute or
an exception message can be checked against the values themselves rather
than against a list of key names that look suspicious. Matching on the key
misses the cases that actually leak: a connection string filed under url,
an upstream error quoting the credential back, a sentence somebody typed
during an incident.
Only values that were resolved at least once can be matched, which is no real limit -- code cannot print a secret it never read -- and better said out loud than implied.
Implementation
String dvRedactSecrets(String text) => DVSecrets.redact(text);