Skip to content
GitHubRSS

src/util/secret-mask.ts — masking secret-named values in what vx shows

A task that echoes $NPM_TOKEN, or a TS config that builds its command from process.env.API_KEY, put the value in the terminal, the stdout the cache keeps and every hit replays, the $ command line, telemetry records and vx show (L-11). The mask replaces a known value wherever it appears, the way GitHub Actions masks its secrets.

export const MASKED = '***'
export interface SecretMask {
mask(text: string): string
stream(): { push(chunk: string): string; end(): string }
}
export function secretMask(
sources: readonly (Record<string, string | undefined> | undefined)[],
named?: readonly string[], // the task's `exec.env.secret`: masked whatever the name
): SecretMask | null
export interface TaskEnvSecrets {
readonly define?: Record<string, string>
readonly secret?: readonly string[]
}
export function maskedCommand(command: string, env?: TaskEnvSecrets): string
export function maskedEmitter(
mask: SecretMask,
emit: (text: string) => void,
idleMs?: number,
): { push(chunk: string): void; end(): void }

A variable is masked when its name holds TOKEN, SECRET, KEY, PASSWORD, PASSWD or CREDENTIAL, it does not end _FILE, _PATH or _DIR and is not git’s GIT_CONFIG_KEY_<n>, or the task names it in exec.env.secret (L-14), and its value has six characters or more. No such variable: secretMask is null and nothing is paid per byte.

stream() holds back only a tail that could begin a value, so a value split across two chunks is caught and output that cannot be one (a readyWhen line, a start marker) is never delayed. maskedEmitter emits a held tail 25 ms after the last chunk when none follows, so a long task’s last characters do not wait for its exit; a value split by a longer pause between two writes is not caught.

Callers: orchestrator/execute-task.ts (live output, captured stdout), orchestrator/hit-restore.ts (a replayed hit’s stdout), orchestrator/framed-output.ts, orchestrator/events.ts and orchestrator/telemetry.ts (the command), cli/show.ts.