mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Part of #1743, follow up of #1803 which added the `debug_redact` labels but nothing was reading them yet. The unary interceptors log every request and response body. Until now the only redaction was to clear any field named `env`, so for example `MintActorJWTResponse.actor_jwt` (a bearer token) was going to the ateapi log on every mint call. Now the interceptor follows the label instead of the field name. Before logging it clones the message and masks every field with `[debug_redact = true]` in the copy: singular strings become `[REDACTED]`, other kinds (bytes, repeated, map, message) are cleared, and it recurses into nested messages, repeated messages and map values (the old walker skipped maps). The message returned to the client is never touched. The hardcoded `env` check is gone since both `EnvVar.value` and `EnvEntry.value` carry the label now. One visible change: env var names now show up in the log next to `[REDACTED]`, before the whole env list was dropped. I think this is better for debugging and the values are still gone. This is an incremental step and only fixes the known leak in the interceptor. It keeps today's structure, clone + walk on every request and response at this one call site. Two things are left for follow up PRs on purpose: moving the redaction into the shared slog handler (`internal/contextlogging`) so any slog call with a proto is covered, and the performance work (per message type cache so clean messages are not cloned at all, scan-then-rebuild handler). I benchmarked that already, numbers are in the doc linked from #1743. Without the cache this PR costs about the same as today on clean messages and a bit more on messages with secrets, about 100ns per masked value, which is fine for now. The postgres connection string in ateapi's startup flag log is still open from the P0 list, that will be a separate small PR.