Replaces credential-looking fields in a structure with a redaction marker.
The structure to scrub.
How deep the current walk is. Callers leave this at its default.
A copy with every sensitive field replaced by a marker.
The last line of defence, not the first. The rule that matters is at the call site — a log line carries the few fields that explain what happened, never a whole request or response body — and this exists because that rule is applied by people and a leaked key is not recoverable once it reaches a log stream.
Matching is by field name: a value that happens to look like a token is kept, and a field named like a secret is masked. Name-based matching is predictable, which is what makes the result reviewable; guessing at values would mask real data and still miss opaque secrets.
The one concession to type is booleans, which pass through. tokenPresented: false is not a credential — it is the reason an authentication failed, and
masking it left lines that recorded a failure while withholding its cause.
Names that routinely hold numeric secrets are exempt from that exemption.
Arrays and nested objects are walked to a bounded depth. Error values are
left alone for Logger to expand, and every other non-object value is
returned as it came.
Security