How Credentials Are Redacted in Stored URLs and Error Messages in No-Mistakes

The no-mistakes CLI uses the internal/safeurl package to strip user credentials from URLs before database storage and applies regex-based sanitization to error messages and logs to prevent authentication data leakage.

The no-mistakes repository handles sensitive Git URLs that frequently embed authentication tokens or passwords in their user-info sections. To ensure these credentials never persist to disk or surface in error traces, the codebase implements a multi-layered redaction strategy that processes URLs at the storage boundary and sanitizes all runtime output.

Redaction at the Storage Layer

When no-mistakes discovers a new repository, it immediately sanitizes the upstream URL before writing to the database. In internal/gate/gate.go, the InitWithFork function passes the raw URL through safeurl.Redact, which removes any embedded username or password components.

This guarantees that credentials redacted in stored URLs never survive application restarts or database dumps. The sanitized URL—now stripped of sensitive user-info like https://[REDACTED]@github.com/org/repo.git—is the only version persisted to storage.

import "github.com/kunchenguid/no-mistakes/internal/safeurl"

func storeRepo(upstreamURL string) {
    // Remove any user-info like https://user:token@host/…
    redacted := safeurl.Redact(upstreamURL)
    // Persist `redacted` – the DB never sees the original credentials
    db.SaveRepoURL(redacted)
}

Runtime Sanitization of Logs and Errors

Beyond persistence, the tool ensures credentials are redacted in error messages and log output generated during Git operations. The internal/safeurl package provides two primary functions for this purpose:

  • safeurl.Redact – Parses and sanitizes URL strings specifically
  • safeurl.RedactText – Applies regex-based credential detection to arbitrary text

In internal/pipeline/steps/push.go, the push step logs the target URL after wrapping it with safeurl.Redact:

sctx.Log(fmt.Sprintf("pushing to %s (%s)...", safeurl.Redact(pushURL), ref))

Similarly, Git command errors in internal/git/git.go sanitize both the command arguments and stderr output before returning wrapped errors:

func runGit(args []string) error {
    out, err := exec.Command("git", args...).CombinedOutput()
    if err != nil {
        // Ensure any credentials embedded in the command line or Git’s stderr are hidden
        safeCmd := safeurl.RedactText(strings.Join(args, " "))
        safeStderr := safeurl.RedactText(string(out))
        return fmt.Errorf("git %s: %w: %s", safeCmd, err, safeStderr)
    }
    return nil
}

Intent and User Input Sanitization

The redaction strategy extends to user-provided content through the internal/intent package. The intent.RedactSecrets function—defined in internal/intent/redact.go—processes free-form text to identify and mask credential-like patterns before they are stored or processed as intent data.

import "github.com/kunchenguid/no-mistakes/internal/intent"

func cleanIntent(raw string) string {
    // Strips adversarial content and redacts any credential-like patterns
    return intent.RedactSecrets(intent.StripAdversarial(raw))
}

This ensures that even adversarial user input containing embedded tokens is sanitized before entering the pipeline.

Verification Through Unit Testing

The repository validates redaction behavior through targeted unit tests. The internal/safeurl/redact_test.go file contains TestRedactHidesHTTPSCredentials, which verifies that various URL formats have their user-info sections properly obscured.

Additionally, internal/pipeline/steps/push_test.go includes TestPushStep_RedactsForkURLInGitErrors, ensuring that when Git operations fail, any URLs appearing in error messages are automatically redacted before being returned to the caller or written to logs.

Summary

  • Pre-storage redaction – The safeurl.Redact function in internal/safeurl/redact.go strips user credentials from URLs before database persistence in gate.InitWithFork.
  • Runtime log protection – All URLs in log output are wrapped with safeurl.Redact, while free-form text uses safeurl.RedactText to catch credentials in command arguments or stderr.
  • User input handling – The intent.RedactSecrets function sanitizes user-provided text to prevent credential leakage through intent processing.
  • Comprehensive testing – Unit tests in redact_test.go and push_test.go verify that credentials remain hidden across HTTPS URLs and Git error scenarios.

Frequently Asked Questions

What specific URL components does safeurl.Redact remove?

The function specifically targets the user-info section of URLs—the username:password or token portion that appears between the scheme (https://) and the host. This ensures that URLs like https://ghp_token@github.com/user/repo.git are stored and logged as https://[REDACTED]@github.com/user/repo.git without exposing the authentication credential.

How does the tool handle credentials embedded in Git error messages?

When Git commands fail, the error handling code in internal/git/git.go passes both the command-line arguments and stderr output through safeurl.RedactText before constructing the error return value. This regex-based scan identifies credential patterns that might appear in remote URL errors or authentication failure messages, replacing them with [REDACTED] markers.

Are all database fields containing URLs automatically redacted?

Yes. According to the source code in internal/gate/gate.go, the InitWithFork function explicitly calls safeurl.Redact on the upstream URL before passing it to the database layer. This design ensures that no raw, credentialed URL ever enters persistent storage, protecting against credential exposure through database dumps or backups.

Can the redaction logic be disabled or configured?

The current implementation in no-mistakes does not provide configuration options to disable redaction. The internal/safeurl package applies redaction universally as a security-critical defense mechanism, ensuring that credentials redacted in stored URLs and error messages remain the default and only behavior across all operations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →