Repository navigation
Fix three masking leaks (read rules, value cap, regex case) - #8
Merged
Merged
Conversation
- read rules write in clear under AllowList; read and mask on one match - MaxValueBytes cuts the value before a mask function and cuts mask output - PropMatches.Regex and function matchers ignore the case option - API surface the tests need: chainable read rules, comparison-aware function matcher (no behaviour change yet)
A read rule no longer writes its value in clear: it hands the value to the context and the next rule on the same match, or the default policy, writes it. Chain Unmasked() for clear text or a mask method to read and mask one match; read rules run wherever they stand among the rules.
A masking function now receives the whole value, so a Last4-style function sees the real last digits, and mask output - a hash, a function's result, the allow-list stars - is never cut by the cap.
PropMatches.Regex matched exact case even under the default case-insensitive option, so DRiverLicensE escaped a driverLicense rule. It now also matches case variants when the call ignores case; a function matcher can take the comparison through a new constructor.
CHANGELOG lists the read-rule and value-cap changes as 2.0 breaking changes and the regex case fix; README and the masking skill describe the new read semantics and where MaxValueBytes applies.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the three masking leaks found in the 2.0 review, failing tests first.
ReadX(f).Unmasked()keeps clear text,ReadX(f).MaskAny(...)reads and masks; a read rule runs wherever it stands among the rules.MaxValueBytesapplies to values written unmasked only: a masking function receives the whole value (***4444, not the digits at the cap), and mask output — hash, function result, allow-list stars — is never cut.PropMatches.RegexfollowsPropertyNameCaseInsensitive; a function matcher can take the comparison via a newPropMatchingStrategy(Func<string?, StringComparison, bool>)constructor.Breaking
Read rules under
AllowList/NullListnow write"***"/null; a masking function decodes a long value in full. Both listed under 2.0 "Changed — breaking".Verification
LeakTests: 29 cases (K1 under AllowList / BlockList / NullList / Relative / array, read+mask both orders, Explain; K2 three function kinds, segmented input, hash, long mask output; K3 truth table as a Theory). 20 red before the fix.