CommandRedactor
final class CommandRedactor (View source)
| internal |
CommandRedactor
The single home for "which command keys are sensitive, and how do we mask
them" — previously duplicated across {\CNIC\AbstractSocketConfig} (which
skips null values because they are dropped from the request, not logged)
and {\CNIC\AbstractResponse} (whose command values are never null, so the
skip is a no-op there, not a behaviour change). Both call sites keep their
own $sensitiveFields property — the two class hierarchies (SocketConfig
side, Response side) must each stay independently safe, since both
CNR\Response and IBS\Response are publicly constructible directly with
a raw, unmasked $cmd array — this class only removes the duplicated
matching/masking algorithm they each ran over their own list.
Not part of the SDK's public surface: it helps nobody talk to the API, it
only keeps this SDK's own two masking call sites in step. Consumers reach
redaction through the $sensitiveFields property they already override, so
nothing here needs to be callable from outside CNIC\.
Constants
| MASK |
The replacement value written over a sensitive command value. |
Methods
Mask the values of the sensitive keys in $command.
Details
static array
redact(array $command, array $sensitiveFields)
Mask the values of the sensitive keys in $command.
Matching is case-insensitive, so only the names in $sensitiveFields
matter, not their casing versus the command's actual keys. A null
value is left untouched even when its key matches — the SocketConfig
caller relies on this to leave a dropped-from-the-request parameter as
null rather than turning it into the literal string "***".
Builds and returns a new array rather than mutating $command in place, which is what lets the return type track the input's value type (string|null in, string|null out) instead of widening every caller to string|null regardless of whether it ever passes a null.