feat(14-01): sunscreen redacting slog handler installed by every generated main
- Wrap redacts sensitive keys at any depth and scrubs Bearer, sk- and x-api-key shapes - InstallDefault is the first statement of the generated run; hello main regenerated - surf test pins that recovered panics echo no credential - sunscreen README, root modules row and the logging docs page
This commit is contained in:
30
modules/sunscreen/example_test.go
Normal file
30
modules/sunscreen/example_test.go
Normal file
@@ -0,0 +1,30 @@
|
||||
package sunscreen_test
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"log/slog"
|
||||
"os"
|
||||
|
||||
"git.golem15.com/golem15/summercms/modules/sunscreen"
|
||||
)
|
||||
|
||||
func ExampleWrap() {
|
||||
// Drop the time so the output is stable; a real application keeps it.
|
||||
plain := slog.NewTextHandler(os.Stdout, &slog.HandlerOptions{
|
||||
ReplaceAttr: func(groups []string, a slog.Attr) slog.Attr {
|
||||
if len(groups) == 0 && a.Key == slog.TimeKey {
|
||||
return slog.Attr{}
|
||||
}
|
||||
return a
|
||||
},
|
||||
})
|
||||
logger := slog.New(sunscreen.Wrap(plain))
|
||||
|
||||
logger.Info("vendor call failed",
|
||||
"api_key", "live-key-123",
|
||||
slog.Group("request", slog.String("Authorization", "Bearer abc.def")),
|
||||
"err", errors.New("401 for key sk-abcdefghijklmnopqrstuvwx"),
|
||||
)
|
||||
// Output:
|
||||
// level=INFO msg="vendor call failed" api_key=[REDACTED] request.Authorization=[REDACTED] err="401 for key sk-[REDACTED]"
|
||||
}
|
||||
Reference in New Issue
Block a user