How Credentials Are Redacted in Stored URLs and Error Messages in No-Mistakes
The no-mistakes CLI uses the internal/safeurl package to strip user credentials from URLs before database storage and applies regex-based sanitization to error messages and logs to prevent authentication data leakage.
The no-mistakes repository handles sensitive Git URLs that frequently embed authentication tokens or passwords in their user-info sections. To ensure these credentials never persist to disk or surface in error traces, the codebase implements a multi-layered redaction strategy that processes URLs at the storage boundary and sanitizes all runtime output.
Redaction at the Storage Layer
When no-mistakes discovers a new repository, it immediately sanitizes the upstream URL before writing to the database. In internal/gate/gate.go, the InitWithFork function passes the raw URL through safeurl.Redact, which removes any embedded username or password components.
This guarantees that credentials redacted in stored URLs never survive application restarts or database dumps. The sanitized URL—now stripped of sensitive user-info like https://[REDACTED]@github.com/org/repo.git—is the only version persisted to storage.
import "github.com/kunchenguid/no-mistakes/internal/safeurl"
func storeRepo(upstreamURL string) {
// Remove any user-info like https://user:token@host/…
redacted := safeurl.Redact(upstreamURL)
// Persist `redacted` – the DB never sees the original credentials
db.SaveRepoURL(redacted)
}
Runtime Sanitization of Logs and Errors
Beyond persistence, the tool ensures credentials are redacted in error messages and log output generated during Git operations. The internal/safeurl package provides two primary functions for this purpose:
safeurl.Redact– Parses and sanitizes URL strings specificallysafeurl.RedactText– Applies regex-based credential detection to arbitrary text
In internal/pipeline/steps/push.go, the push step logs the target URL after wrapping it with safeurl.Redact:
sctx.Log(fmt.Sprintf("pushing to %s (%s)...", safeurl.Redact(pushURL), ref))
Similarly, Git command errors in internal/git/git.go sanitize both the command arguments and stderr output before returning wrapped errors:
func runGit(args []string) error {
out, err := exec.Command("git", args...).CombinedOutput()
if err != nil {
// Ensure any credentials embedded in the command line or Git’s stderr are hidden
safeCmd := safeurl.RedactText(strings.Join(args, " "))
safeStderr := safeurl.RedactText(string(out))
return fmt.Errorf("git %s: %w: %s", safeCmd, err, safeStderr)
}
return nil
}
Intent and User Input Sanitization
The redaction strategy extends to user-provided content through the internal/intent package. The intent.RedactSecrets function—defined in internal/intent/redact.go—processes free-form text to identify and mask credential-like patterns before they are stored or processed as intent data.
import "github.com/kunchenguid/no-mistakes/internal/intent"
func cleanIntent(raw string) string {
// Strips adversarial content and redacts any credential-like patterns
return intent.RedactSecrets(intent.StripAdversarial(raw))
}
This ensures that even adversarial user input containing embedded tokens is sanitized before entering the pipeline.
Verification Through Unit Testing
The repository validates redaction behavior through targeted unit tests. The internal/safeurl/redact_test.go file contains TestRedactHidesHTTPSCredentials, which verifies that various URL formats have their user-info sections properly obscured.
Additionally, internal/pipeline/steps/push_test.go includes TestPushStep_RedactsForkURLInGitErrors, ensuring that when Git operations fail, any URLs appearing in error messages are automatically redacted before being returned to the caller or written to logs.
Summary
- Pre-storage redaction – The
safeurl.Redactfunction ininternal/safeurl/redact.gostrips user credentials from URLs before database persistence ingate.InitWithFork. - Runtime log protection – All URLs in log output are wrapped with
safeurl.Redact, while free-form text usessafeurl.RedactTextto catch credentials in command arguments or stderr. - User input handling – The
intent.RedactSecretsfunction sanitizes user-provided text to prevent credential leakage through intent processing. - Comprehensive testing – Unit tests in
redact_test.goandpush_test.goverify that credentials remain hidden across HTTPS URLs and Git error scenarios.
Frequently Asked Questions
What specific URL components does safeurl.Redact remove?
The function specifically targets the user-info section of URLs—the username:password or token portion that appears between the scheme (https://) and the host. This ensures that URLs like https://ghp_token@github.com/user/repo.git are stored and logged as https://[REDACTED]@github.com/user/repo.git without exposing the authentication credential.
How does the tool handle credentials embedded in Git error messages?
When Git commands fail, the error handling code in internal/git/git.go passes both the command-line arguments and stderr output through safeurl.RedactText before constructing the error return value. This regex-based scan identifies credential patterns that might appear in remote URL errors or authentication failure messages, replacing them with [REDACTED] markers.
Are all database fields containing URLs automatically redacted?
Yes. According to the source code in internal/gate/gate.go, the InitWithFork function explicitly calls safeurl.Redact on the upstream URL before passing it to the database layer. This design ensures that no raw, credentialed URL ever enters persistent storage, protecting against credential exposure through database dumps or backups.
Can the redaction logic be disabled or configured?
The current implementation in no-mistakes does not provide configuration options to disable redaction. The internal/safeurl package applies redaction universally as a security-critical defense mechanism, ensuring that credentials redacted in stored URLs and error messages remain the default and only behavior across all operations.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →