* refactor: remove stale sdk/src generated-file banners from bin/lib/*.cjs (#506) Drop the GENERATED FILE / Source: sdk/src / Regenerate: cd sdk banners from 13 hand-maintained CJS modules and delete the orphaned generator-freshness-contract script + test. Post-ADR-0174 cleanup; the referenced sdk/ generator pipeline (dir, gen:* scripts, *.generated.cjs) no longer exists. No runtime behavior change. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs: add changeset for #510 (sdk/src banner cleanup) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
33 lines
772 B
JavaScript
33 lines
772 B
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Secrets handling — masking convention for API keys and other
|
|
* credentials managed via /gsd-settings-integrations.
|
|
* This module does not read the filesystem.
|
|
*/
|
|
|
|
const SECRET_CONFIG_KEYS = new Set([
|
|
'brave_search',
|
|
'firecrawl',
|
|
'exa_search',
|
|
]);
|
|
|
|
function isSecretKey(keyPath) {
|
|
return SECRET_CONFIG_KEYS.has(keyPath);
|
|
}
|
|
|
|
function maskSecret(value) {
|
|
if (value === null || value === undefined || value === '')
|
|
return '(unset)';
|
|
const s = String(value);
|
|
if (s.length < 8)
|
|
return '****';
|
|
return '****' + s.slice(-4);
|
|
}
|
|
|
|
function maskIfSecret(keyPath, value) {
|
|
return isSecretKey(keyPath) ? maskSecret(value) : value;
|
|
}
|
|
|
|
module.exports = { SECRET_CONFIG_KEYS, isSecretKey, maskSecret, maskIfSecret };
|