feat(security): add secrets masking and validation (H-21/SEC5) #116

Merged
hamza.khyari merged 4 commits from feature/m4-security-secrets into develop-hamza-1 2026-02-19 13:45:29 +00:00

4 Commits

Author SHA1 Message Date
khyari hamza eccaeafa64 docs(plan): mark SEC5 secrets management items complete 2026-02-19 12:46:56 +00:00
khyari hamza 064939185b fix(security): whitelist structlog processor method_name for vulture 2026-02-19 12:45:59 +00:00
khyari hamza d815339c52 feat(security): add secrets masking and validation (H-21/SEC5)
Implement centralized redaction utility that masks API keys, tokens,
and credentials across CLI output, structlog logs, and error messages.

- Add shared/redaction.py with pattern-based secret detection (sk-*,
  sk-ant-*, tok_*, Bearer tokens), sensitive key name detection,
  database URL masking, custom pattern registration, and thread-safe
  global show_secrets flag
- Add config/logging.py with structlog configuration integrating the
  secrets_masking_processor into the processor chain
- Add --show-secrets global CLI option to reveal secrets when needed
- Redact error details in main.py, project.py, and auto_debug.py
  error handlers before printing
- Wrap format_output() in formatting.py with automatic dict redaction
- Add show_secrets field and safe __repr__ to Settings model
- Add 43-scenario Behave feature (features/security_secrets.feature)
- Add 10 Robot Framework smoke tests (robot/security_secrets.robot)
- Add ASV benchmarks (benchmarks/security_secrets_bench.py)
- Add reference docs (docs/reference/secrets_handling.md)
2026-02-19 11:15:18 +00:00
khyari hamza 359e3c4af2 chore: WIP branch for feat(security): add secrets masking and validation
Refs: H-21, SEC5.secrets
Planned: Day 13
2026-02-19 11:14:43 +00:00