# How Credentials Are Redacted in Stored URLs and Error Messages in No-Mistakes

> Discover how the no-mistakes CLI protects your data by redacting credentials in stored URLs and error messages. Learn about its internal safeurl package and regex sanitization for secure logging.

- Repository: [Kun Chen/no-mistakes](https://github.com/kunchenguid/no-mistakes)
- Tags: internals
- Published: 2026-07-25

---

**The `no-mistakes` CLI uses the `internal/safeurl` package to strip user credentials from URLs before database storage and applies regex-based sanitization to error messages and logs to prevent authentication data leakage.**

The `no-mistakes` repository handles sensitive Git URLs that frequently embed authentication tokens or passwords in their user-info sections. To ensure these credentials never persist to disk or surface in error traces, the codebase implements a multi-layered redaction strategy that processes URLs at the storage boundary and sanitizes all runtime output.

## Redaction at the Storage Layer

When `no-mistakes` discovers a new repository, it immediately sanitizes the upstream URL before writing to the database. In [`internal/gate/gate.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/gate/gate.go), the `InitWithFork` function passes the raw URL through `safeurl.Redact`, which removes any embedded username or password components.

This guarantees that credentials redacted in stored URLs never survive application restarts or database dumps. The sanitized URL—now stripped of sensitive user-info like `https://[REDACTED]@github.com/org/repo.git`—is the only version persisted to storage.

```go
import "github.com/kunchenguid/no-mistakes/internal/safeurl"

func storeRepo(upstreamURL string) {
    // Remove any user-info like https://user:token@host/…
    redacted := safeurl.Redact(upstreamURL)
    // Persist `redacted` – the DB never sees the original credentials
    db.SaveRepoURL(redacted)
}

```

## Runtime Sanitization of Logs and Errors

Beyond persistence, the tool ensures credentials are redacted in error messages and log output generated during Git operations. The `internal/safeurl` package provides two primary functions for this purpose:

- **`safeurl.Redact`** – Parses and sanitizes URL strings specifically
- **`safeurl.RedactText`** – Applies regex-based credential detection to arbitrary text

In [`internal/pipeline/steps/push.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/push.go), the push step logs the target URL after wrapping it with `safeurl.Redact`:

```go
sctx.Log(fmt.Sprintf("pushing to %s (%s)...", safeurl.Redact(pushURL), ref))

```

Similarly, Git command errors in [`internal/git/git.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/git/git.go) sanitize both the command arguments and stderr output before returning wrapped errors:

```go
func runGit(args []string) error {
    out, err := exec.Command("git", args...).CombinedOutput()
    if err != nil {
        // Ensure any credentials embedded in the command line or Git’s stderr are hidden
        safeCmd := safeurl.RedactText(strings.Join(args, " "))
        safeStderr := safeurl.RedactText(string(out))
        return fmt.Errorf("git %s: %w: %s", safeCmd, err, safeStderr)
    }
    return nil
}

```

## Intent and User Input Sanitization

The redaction strategy extends to user-provided content through the `internal/intent` package. The `intent.RedactSecrets` function—defined in [`internal/intent/redact.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/intent/redact.go)—processes free-form text to identify and mask credential-like patterns before they are stored or processed as intent data.

```go
import "github.com/kunchenguid/no-mistakes/internal/intent"

func cleanIntent(raw string) string {
    // Strips adversarial content and redacts any credential-like patterns
    return intent.RedactSecrets(intent.StripAdversarial(raw))
}

```

This ensures that even adversarial user input containing embedded tokens is sanitized before entering the pipeline.

## Verification Through Unit Testing

The repository validates redaction behavior through targeted unit tests. The [`internal/safeurl/redact_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/safeurl/redact_test.go) file contains `TestRedactHidesHTTPSCredentials`, which verifies that various URL formats have their user-info sections properly obscured.

Additionally, [`internal/pipeline/steps/push_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/push_test.go) includes `TestPushStep_RedactsForkURLInGitErrors`, ensuring that when Git operations fail, any URLs appearing in error messages are automatically redacted before being returned to the caller or written to logs.

## Summary

- **Pre-storage redaction** – The `safeurl.Redact` function in [`internal/safeurl/redact.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/safeurl/redact.go) strips user credentials from URLs before database persistence in `gate.InitWithFork`.
- **Runtime log protection** – All URLs in log output are wrapped with `safeurl.Redact`, while free-form text uses `safeurl.RedactText` to catch credentials in command arguments or stderr.
- **User input handling** – The `intent.RedactSecrets` function sanitizes user-provided text to prevent credential leakage through intent processing.
- **Comprehensive testing** – Unit tests in [`redact_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/redact_test.go) and [`push_test.go`](https://github.com/kunchenguid/no-mistakes/blob/main/push_test.go) verify that credentials remain hidden across HTTPS URLs and Git error scenarios.

## Frequently Asked Questions

### What specific URL components does `safeurl.Redact` remove?

The function specifically targets the **user-info** section of URLs—the `username:password` or `token` portion that appears between the scheme (`https://`) and the host. This ensures that URLs like `https://ghp_token@github.com/user/repo.git` are stored and logged as `https://[REDACTED]@github.com/user/repo.git` without exposing the authentication credential.

### How does the tool handle credentials embedded in Git error messages?

When Git commands fail, the error handling code in [`internal/git/git.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/git/git.go) passes both the command-line arguments and stderr output through `safeurl.RedactText` before constructing the error return value. This regex-based scan identifies credential patterns that might appear in remote URL errors or authentication failure messages, replacing them with `[REDACTED]` markers.

### Are all database fields containing URLs automatically redacted?

Yes. According to the source code in [`internal/gate/gate.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/gate/gate.go), the `InitWithFork` function explicitly calls `safeurl.Redact` on the upstream URL before passing it to the database layer. This design ensures that no raw, credentialed URL ever enters persistent storage, protecting against credential exposure through database dumps or backups.

### Can the redaction logic be disabled or configured?

The current implementation in `no-mistakes` does not provide configuration options to disable redaction. The `internal/safeurl` package applies redaction universally as a security-critical defense mechanism, ensuring that credentials redacted in stored URLs and error messages remain the default and only behavior across all operations.