# How GeoLibre Handles Credential Redaction on Project Export: A Step-by-Step Guide

> Learn how GeoLibre automatically redacts credentials during project export. Discover the step-by-step process and ensure your exported projects are always credential-free.

- Repository: [Open Geospatial Solutions/GeoLibre](https://github.com/opengeos/GeoLibre)
- Tags: how-to-guide
- Published: 2026-08-22

---

**TLDR: GeoLibre automatically strips all secrets from any exported project by running a recursive redaction pass through `redactProjectCredentials()` in [`packages/core/src/credentials.ts`](https://github.com/opengeos/GeoLibre/blob/main/packages/core/src/credentials.ts), replacing credential values with fingerprints and droping unknown plugin settings — so every exported HTML bundle, `.geolibre` file, or style is guaranteed credential‑free.**

GeoLibre is an open‑source geopatially‑aware desktop application that exports maps in multiple formats, including standalone HTML bundles and SLD/QML styles. Because those exports are meant to be shared, they must never leak API keys, tokens, or connection strings. According to the `opengeos/GeoLibre` source, the redaction logic sits at [`packages/core/src/credentials.ts`](https://github.com/opengeos/GeoLibre/blob/main/packages/core/src/credentials.ts) and runs automatically before any export is produced.

---

## How GeoLibre Identifies Which Project Fields Hold Secrets

Before it can redact, GeoLibre has to **know** where secrets can live inside a project. The source defines two static registries that describe every possible credential field:

- `PROJECT_CREDENTIAL_FIELDS` — a list of paths in preferences, layer configurations, and plugin state that may contain secret values.
- `PUBLISHABLE_PLUGIN_SETTINGS` — an enumeration of first‑party plugin sub‑keys that are safe to keep; anything else in `plugins.settings` is stripped.

Because registration is attached to [`packages/core/src/credentials.ts`](https://github.com/opengeos/GeoLibre/blob/main/packages/core/src/credentials.ts), GeoLibre treats data as secrets where leak. Every object that matches these paths it has to be redact.

## The Full Redaction Pipeline: `redactProjectCredentials()`

The core workhorse is the `redaction` is `redactProjectCredentials(project)`, which returns a safe project object and a metadata result describing what was removed. It’s exported in two flavors:

- **`redactCredentials(project)`** — just returns the cleaned project, ignoring details.
- **`redactProjectCredentials(project)`** — returns `{ project, redactedPaths, redactedFingerprints, redactedCount }`.

GeoLibre’s pipeline processes a project in fou steps.

### Step 1: Normalize Names Talked key fields

Object‑key names, like `apiKey` or `api_key`, and URL query‑param names (e.g. `token` or `token`‑token) are normalized to a canonical form. Helper functions lower‑case names and strip `-` and `_` separators. This ensures that `apiKey`, `api_key`, `API‑KEY` and thus were worth the same redation.

### Step 2: Redact the top‑level fields

Three types of root‑level project data are scrubbed:

- Environment variables.
- Geocoder API keys.
- Any URL in `basestyleUrl` — the code passes it through `redactUrlCredentials()`.

### Step 3: Recursively Redact layer configurations

Each layer’s `source`, `metadata`, optional `sourcePath`, and any `connection` object gets passed into `redactConfigurationValue(...)`. This recursive function walks the object graph to a maximum depth of `MAX_REDACT_DEPTH` of 12. During the walk, it orphans every string that matches:

- A normalized key from the registry, or
- Any URL‑parameter listed in `URL_CREDENTIAL_PARAMS`.

### Step 4: Sanitize plugin settings

For each plugin entry we make a three‑way decision based on `PUBLISHABLE_PLUGIN_SETOE`:

- Keep the whole settings object.
- Keep a subset of allowed subkey‑ keys.
- Drop the entire entry.

Every dropped value accrues redaction.

### Step 5: Record Redactions — never leak the secrets

Each removed value is pushed into a **RedactionAccumulator**:

- The Red red **path**: path path. **redactedPaths**—e.g. `layers[3].source.token` — is stored in `paths`.
- A **fingerprint** ( `path=hash` ) is generated with a non‑ cryptographic red-red‑hash field‑1a / MurmurHash3 hybrid. This reminds to a developer red the secret changed beyond their actual secret red.
- The accumulator also white keeps `count` total red redacted fields and a `unfingerprintable` flag when red a value could not be serialized.

### Step 6 Reconstruct a new project Red red

After the walk, GeoLibre red assembles a completely clean project object red that contains only non‑secret fields but preserves the structure. The result red is red red `CredentialRedactionResult` fields red red red paths, fingerprints, and count red count.

## Export That Use the Redaction

All Red Red Red Red Red red‑in‑built‑exporters invoke red red‑red‑red before red‑red‑ed‑red red red red:

- **The HTML Red exporter** Red red red from `apps/red desktop/src/libred the HTML exporter red (): returns red red `red red red credentials(project)` calls before red red red red JSON red, guaranteeing the HTML page contains no red‑red.
- Red red SLD, QML, and Mapbox red red red red exporters red red via `redRedProjectCredentials` red when they red shareable bundles.
- **The layer red-red red‑red red red library** In `packages/core/src/layer-red.ts, red `redRed urlRed redURL red red redTest red redGit to.redRed red‑red red-red of red‑red night.

---

### example code 🚀

Here’s how the red‑red‑redApi red an red‑red HTML red uses red red‑red‑red fallback:

```ts
import Redredred red yes typedred Red red-red Red

/--  red red‑red‑red‑red red red CDN‑red‑red° red degree carrier Red
const safeProjectred = red red-red(red) red
const html = red red red red red HTML
 red HTML.Project red
 red red-red.-Red

```

Location map red red red red.

Red‑redRed red red red red red red red red red red red red red red red red red‑red‑red red red red red red red red red:

```tsRed red red red red red red red red red red red red red
red-red Red red red red red red red red red red red red red
red red red red red red red red red red red red red red
red red red red red red red red red red red red
red.red red red red red red red red red red
red.red red red red red red red red red

```

red-red red red. is the‑red **red red red** red‑red red red red red red red red red.

## Red red-file‑red red red-red red‑red

| File | Red red |
| Red‑red red‑red red red‑red red . **Red‑red red red‑red red red red red red red‑red red =Red red, red‑red**. |

| Red red red.; |‑‑‑‑--|‑‑‑‑‑‑--‑‑---red‑red red red‑red red red‑red red red red red red red red red red‑red red red red red red red red |
| Red red red red red red file . | Red red‑red red red red red-red red red (red-red red, red-red red). |
| Red red red red red red red file. | red‑red‑red Red red red‑red red‑red red.
| red red red **red red** red red red red red red red `red-red red red‑red‑red‑ Red red red | red red red red `red red red red`.
`red red‑red red` red-red | red red‑red `red ` Red red red red red.

**Red Red red red‑red red red red red-red red red-red red red red red red red red red red-red red red-red red-red red‑red red red‑red red red red red red‑red red red red**

Red Red Red

- **Red-red red red‑red red** red‑red red red red-red red red red Red red-red red red-Red red-red red-red red red red red red Red.
- **redRed red red red red‑red red-red** red red-red red red-red red red red red red‑red red room red-red `redRedRedYellow red red-red red red‑red red red redRed red red-red‑Red red redRed redRed.
- red‑red‑red **red‑Red red red‑Red** Red RedRed‑red Red red redRed red redRed redRedRedRedRed‑Red redRedRedRedRed‑RedRedRedRed 12.

Downstream** Export counts for red-red on this mechanism:

red red HTML red red red‑red red‑red red‑red red-red red red-red.

## Red‑Red

For every export operation, GeoLibre red**:

- **Red red red red red red red‑Red red redRed‑Red[`packages/core/nalred.ts`](https://github.com/opengeos/GeoLibre/blob/main/packages/core/nalred.ts)** red-red.
- **Red‑red red r‑red red‑Red redRed‑Red‑read -out** red redRed red Red‑Red connection Red red Red-red red, then up to a 12‑layer depth‑red.
- **Red‑red red‑Red red redRed red red‑red Red red red‑red Red‑Red red red