Files
DocsGPT/docsgpt/storage/db/redaction.py
T
Alex 574f96341e refactor: rename the application package to docsgpt
The backend import package is now docsgpt, the name it will carry on PyPI;
application was far too generic to install into anyone's site-packages.
git mv plus a mechanical rewrite of every import, dotted string and path
reference: 734 Python files, the compose files, Dockerfile, workflows, docs,
setup scripts, devcontainer, k8s manifests, vscode config, pytest and coverage
config, .gitignore. Behaviour is unchanged.

Kept for one release:
- A top-level application package whose meta-path finder resolves
  application.x.y to the already-imported docsgpt.x.y object, so old imports
  and entry points (celery -A application.app.celery,
  uvicorn application.asgi:asgi_app) keep working with a FutureWarning.
- Celery registers every application.* task name as an alias of its
  docsgpt.* task on start-up, so messages queued by the previous release still
  run. The redbeat key prefix moves to redbeat:docsgpt:v2: so schedule entries
  the previous release wrote are left unread instead of firing twice.

The backend image builds from the repository root (docker build -f
docsgpt/Dockerfile .) so it can ship the alias package; a root .dockerignore
allow-lists docsgpt/ and application/ and keeps caches, local data, .env
files, the sample index files and the Dockerfile out. Compose and the image
workflows point at the new context.
2026-09-07 10:20:43 +01:00

65 lines
1.8 KiB
Python

"""Secret redaction for reflected ``stack_logs`` data.
``stacks`` is built by reflecting every public attribute of runtime
objects (the ``llm`` component carries the deployment provider
``api_key`` and the caller's ``user_api_key``). The unified-logs endpoint
returns ``stacks`` to the client, so credentials must be scrubbed — at
write time for new rows, and at read time for rows written before
redaction existed.
"""
from __future__ import annotations
REDACTED = "[REDACTED]"
# Substrings marking a key as a credential. Compound token-count fields
# (``prompt_tokens`` / ``generated_tokens`` / ``token_budget`` / ...) are
# intentionally not matched: secret token forms are spelled out
# (``access_token`` etc.) and a bare ``token`` is handled separately.
_SECRET_SUBSTRINGS = (
"api_key",
"apikey",
"api_token",
"access_token",
"refresh_token",
"auth_token",
"id_token",
"session_token",
"secret",
"password",
"passwd",
"passphrase",
"private_key",
"credential",
"authorization",
"bearer",
)
def is_secret_key(key: str) -> bool:
"""True when ``key`` names a credential that must not be persisted/returned."""
k = key.lower()
if k == "token":
return True
return any(s in k for s in _SECRET_SUBSTRINGS)
def redact_secrets(obj):
"""Recursively replace secret-keyed values with ``[REDACTED]``.
Walks dicts and lists; leaf scalars pass through unchanged. ``None``
returns ``None`` so callers can redact an optional payload directly.
"""
if isinstance(obj, dict):
return {
k: (
REDACTED
if isinstance(k, str) and is_secret_key(k)
else redact_secrets(v)
)
for k, v in obj.items()
}
if isinstance(obj, list):
return [redact_secrets(v) for v in obj]
return obj