Skip to main content

Redacted

Struct Redacted 

Source
pub struct Redacted<T: Zeroize = String>(/* private fields */);
Expand description

A secret value whose Debug/Display output is always ***, and whose backing memory is zeroized when it is dropped.

Wrap any credential that must never reach a log line, a panic message, or a future #[derive(Debug)] added to a struct embedding it. T defaults to String, the shape every current call site needs; a caller that needs a different backing type must supply one that implements [Zeroize] (e.g. secret bytes as Vec<u8>).

§Examples

use deps_core::secret::Redacted;

let token = Redacted::new("super-secret-value".to_string());
assert_eq!(token.expose_secret(), "super-secret-value");
assert_eq!(format!("{token:?}"), "Redacted(***)");
assert_eq!(format!("{token}"), "***");

Implementations§

Source§

impl<T: Zeroize> Redacted<T>

Source

pub fn new(value: T) -> Self

Wraps value. The only way to recover it is Self::expose_secret (for T: AsRef<str>).

Source§

impl<T: Zeroize + AsRef<str>> Redacted<T>

Source

pub fn expose_secret(&self) -> &str

The raw secret value. Never pass this to anything but the one call site that needs it (e.g. attaching a header value to a request) — never to a log, error message, or anything Debug/Display-formatted downstream.

Named expose_secret() rather than as_str() deliberately, mirroring the secrecy crate’s ExposeSecret::expose_secret() convention: a name shared with hundreds of ordinary string-conversion methods across the workspace cannot be grepped for in isolation, while a distinctive name lets a reviewer or a future automated lint find every place a secret’s plaintext crosses its wrapper boundary with a single search.

Trait Implementations§

Source§

impl<T: Clone + Zeroize> Clone for Redacted<T>

Source§

fn clone(&self) -> Redacted<T>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<T: Zeroize> Debug for Redacted<T>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<T: Zeroize> Display for Redacted<T>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<T: Zeroize + Eq> Eq for Redacted<T>

Source§

impl<T: Zeroize + Hash> Hash for Redacted<T>

Hashes the wrapped value, not the redaction wrapper — so Redacted<T> can be used as (or inside) a hash-map/set key exactly when T itself could be. Opt-in via T: Hash, same shape as the PartialEq/Eq impls above: a caller that needs this must ask for it by bounding on Hash, so embedding a secret in a hash key stays a deliberate choice at each call site rather than something a blanket impl would make automatic.

Source§

fn hash<H: Hasher>(&self, state: &mut H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl<T: Zeroize + PartialEq> PartialEq for Redacted<T>

Source§

fn eq(&self, other: &Self) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl<T: Zeroize> ZeroizeOnDrop for Redacted<T>

Marker confirming Redacted<T> zeroizes its backing memory on drop — the actual zeroing is performed by the wrapped [Zeroizing<T>] field’s own Drop impl.

Auto Trait Implementations§

§

impl<T> Freeze for Redacted<T>
where T: Freeze,

§

impl<T> RefUnwindSafe for Redacted<T>
where T: RefUnwindSafe,

§

impl<T> Send for Redacted<T>
where T: Send,

§

impl<T> Sync for Redacted<T>
where T: Sync,

§

impl<T> Unpin for Redacted<T>
where T: Unpin,

§

impl<T> UnsafeUnpin for Redacted<T>
where T: UnsafeUnpin,

§

impl<T> UnwindSafe for Redacted<T>
where T: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more