Singleton implementation of an internal reference to the schema
Helper method to get an internal reference to the loaded profiles
Add a header to censor
The name of the header to censor
Add a censored option, including it's camelCase and kebabCase versions
The option to censor
Copy and censor any sensitive CLI arguments before logging/printing
The args list to censor
Copy and censor a raw command-line string before logging/printing.
This is resilient to the different ways a user may supply a sensitive option on the command line:
--password secret)--password=secret)-p secret / -p=secret)When the parsed command arguments are supplied, the literal value of
every secure option is additionally masked wherever it appears in the
string. This catches secure values that contain embedded whitespace
(e.g. a quoted --password "two words", which arrives here as
--password two words once the shell has stripped the quotes) that a
token-based regex cannot reliably match.
The raw command-line string to censor
The parsed command arguments, if available
Copy and censor environment variables before logging/printing.
Environment variables frequently hold credentials - Zowe explicitly supports supplying secure option values this way (e.g. ZOWE_OPT_PASSWORD, ZOWE_OPT_TOKEN_VALUE), and unrelated secrets (AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, etc.) commonly share the same environment. Because these values never pass through the CLI-argument censoring path, every variable whose name matches a credential pattern is redacted here. The serialized result is additionally routed through Censor.censorRawData so that any config-derived secure values are masked as well.
the environment to censor (defaults to process.env)
Copy and censor any sensitive CLI arguments before logging/printing
the data to censor
Copy and censor any sensitive CLI arguments before logging/printing
the data to censor
Censor sensitive data from an session object or a sub-object of a session. The intent is to create a copy of the object that is suitable for logging.
A Session object (or ISession, or availableCreds) to be censored.
Copy and censor a yargs argument object before logging
the args to censor
Escape every regular-expression metacharacter in a string so it can be safely embedded in a RegExp as a
literal. Secure values and option names are user-supplied and can frequently contain these characters.
The literal string to escape
new RegExpHelper function to handle profile schemas when setting the censored options
the profile type configuration to iterate over
Determine whether an environment-variable name indicates a sensitive value.
the environment-variable name to test
Identifies if a property is a secure property
The property to check
Specifies whether a given property path (e.g. "profiles.lpar1.properties.host") is a special value or not. Special value: Refers to any value defined as secure in the schema definition. These values should be already masked by the application (and/or plugin) developer.
Property path to determine if it is a special value
True - if the given property is to be treated as a special value; False - otherwise
Copy and censor over an object
the data to censor
Recursively replace sensitive data in an session-related object and any relevant sub-objects.
A Session object (or ISession, or the availableCreds) to be censored.
Generate and set the list of censored options. Attempt to source the censored options from the schema, config, and/or command being executed.
The objects to use to gather options that should be censored
Helper method to set an internal reference to loaded profiles
The schmas to pass in to set to the logger
Generated using TypeDoc
Basic censorship items - list definitions & initialiazations, etc. *