Files
Da Huang 232d0f2227 ateinterceptors: redact debug_redact fields from RPC logs (#1822)
Part of #1743, follow up of #1803 which added the `debug_redact` labels
but nothing was reading them yet.

The unary interceptors log every request and response body. Until now
the only redaction was to clear any field named `env`, so for example
`MintActorJWTResponse.actor_jwt` (a bearer token) was going to the
ateapi log on every mint call.

Now the interceptor follows the label instead of the field name. Before
logging it clones the message and masks every field with `[debug_redact
= true]` in the copy: singular strings become `[REDACTED]`, other kinds
(bytes, repeated, map, message) are cleared, and it recurses into nested
messages, repeated messages and map values (the old walker skipped
maps). The message returned to the client is never touched. The
hardcoded `env` check is gone since both `EnvVar.value` and
`EnvEntry.value` carry the label now.

One visible change: env var names now show up in the log next to
`[REDACTED]`, before the whole env list was dropped. I think this is
better for debugging and the values are still gone.

This is an incremental step and only fixes the known leak in the
interceptor. It keeps today's structure, clone + walk on every request
and response at this one call site. Two things are left for follow up
PRs on purpose: moving the redaction into the shared slog handler
(`internal/contextlogging`) so any slog call with a proto is covered,
and the performance work (per message type cache so clean messages are
not cloned at all, scan-then-rebuild handler). I benchmarked that
already, numbers are in the doc linked from #1743. Without the cache
this PR costs about the same as today on clean messages and a bit more
on messages with secrets, about 100ns per masked value, which is fine
for now.

The postgres connection string in ateapi's startup flag log is still
open from the P0 list, that will be a separate small PR.
2026-09-23 17:05:55 +00:00
..