- admin-protected client config (flag > AGENT_LIB_CONFIG > platform default), token used for basic auth only, redacted from all errors and files - work-repo pull via go-git (bare cache clone + fetch, remote re-pointed on config change), clean failure keeps previous state - inventory: own items + external areas from lockfile; MCP inventoried but never deployed - manifest v1 records name/type/origin/revision/content-hash per item, deterministic bytes; folder hashes over sorted relpath+filehash lines so tree and disk hashes agree - shared deploy package (atomic temp+rename, exec-bit preserving) now backs both curator materialization and client deployment - sync validates and hashes everything before the first mutation; second run is a byte-level no-op
17 lines
398 B
Go
17 lines
398 B
Go
package gitsource
|
|
|
|
import "strings"
|
|
|
|
// RedactURL strips user:password credentials embedded in a URL so tokens
|
|
// never surface in error messages or logs.
|
|
func RedactURL(u string) string {
|
|
scheme, rest, found := strings.Cut(u, "://")
|
|
if !found {
|
|
return u
|
|
}
|
|
if at := strings.Index(rest, "@"); at >= 0 && !strings.Contains(rest[:at], "/") {
|
|
return scheme + "://" + rest[at+1:]
|
|
}
|
|
return u
|
|
}
|