sensitiveinputs

package
v0.86.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: MIT Imports: 11 Imported by: 0

Documentation

Overview

Package sensitiveinputs validates provider-declared sensitive Config leaves.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func DiagnosticRedactor

func DiagnosticRedactor(config map[string]any, paths []string) (func(string) string, error)

DiagnosticRedactor masks only declared resolved inputs in control-plane diagnostics. It must not be applied to provider outputs or consumer payloads.

func Expand

func Expand(config map[string]any, paths []string) ([]string, error)

Expand returns deterministic unique concrete leaf pointers. Missing optional fields have no match; present containers or scalar traversal are errors.

func ValidatePaths

func ValidatePaths(paths []string) error

ValidatePaths requires non-root canonical RFC 6901 pointers. Escapes are validated by re-encoding the parser's decoded tokens; malformed '~' escapes must not alias an otherwise valid key.

func ValidateReferences

func ValidateReferences(config map[string]any, paths []string) error

ValidateReferences rejects literal sensitive values without including them in diagnostics. It validates declarative inputs, never consumer artifacts.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL