Class UrlRedaction
java.lang.Object
io.github.intisy.gradle.github.utils.UrlRedaction
Strips the parts of a URL that can carry a credential (userinfo, the query string) before it
is used in a log line or an exception message.
- Implementation Note:
- A presigned or
?token=-style URL is the ordinary shape for a private Nexus, S3, or Artifactory download, andhttps://oauth2:TOKEN@host/repo.gitis the ordinary shape for a private git clone URL; both carry a credential in a place this method removes. Locating that credential is done textually, not viaURI: a credential that contains a/or+(the standard base64 alphabet an Azure DevOps PAT or similar token is drawn from), or a characterURIrejects outright (a raw newline, a space, a brace, the ordinary shape of a token read via Groovy'sfile("token.txt").text), makesURIeither throw or silently mis-parse the authority. Soredact(java.lang.String)checks first, on the raw text, whether the shape between"://"and the last'@'looks likeuserinfo:secret@, and if so removes that whole span outright before ever askingURIto parse anything.That check is scoped to end at the first
?or#after"://"(never at a/, since a leaked credential's own/must still be searched past). Without that bound, a credential-free URL whose query or fragment happens to contain a colon and a later@(an ordinary shape: amailto:link, anotify=admin@example.comparameter) would have its host and path destroyed by a match that was never really userinfo at all; RFC 3986 never allows a raw, unencoded?or#inside userinfo, so bounding the search there loses no real coverage. Only a URL with nouserinfo:secret@span falls through to structuredURIparsing (needed to preserve a port cleanly), and only a URL thatURIstill cannot parse falls through further to a best-effort manual strip.
-
Method Summary
-
Method Details
-
redact
- Parameters:
url- the URL to redact; may benull.- Returns:
urlwith any userinfo and query string removed, ornullifurlwasnull. A value this method cannot parse as a URI (for example, thegit@host:owner/repo.gitscp-like syntax, or a URI-illegal character inside userinfo) has its userinfo and query string stripped on a best-effort textual basis instead.
-