Before/After (linebreaks added for readability)
```log
# before
INFO [project::context_server_store::extension]
loaded command for context server mcp-server-github:
Command {
command: "/Users/peter/Library/Application Support/Zed/extensions/work/mcp-server-github/github-mcp-server-v0.5.0/github-mcp-server",
args: ["stdio"],
env: [("GITHUB_PERSONAL_ACCESS_TOKEN", "gho_WOOOOOOOOOOOOOOO")]
}
#after
INFO [project::context_server_store::extension]
loaded command for context server mcp-server-github:
Command {
command: "/Users/peter/Library/Application Support/Zed/extensions/work/mcp-server-github/github-mcp-server-v0.5.0/github-mcp-server",
args: ["stdio"],
env: [("GITHUB_PERSONAL_ACCESS_TOKEN", "[REDACTED]")]
}
```
Release Notes:
- Redact sensitive environment variables from MCP logs
9 lines
333 B
Rust
9 lines
333 B
Rust
/// Whether a given environment variable name should have its value redacted
|
|
pub fn should_redact(env_var_name: &str) -> bool {
|
|
const REDACTED_SUFFIXES: &[&str] =
|
|
&["KEY", "TOKEN", "PASSWORD", "SECRET", "PASS", "CREDENTIALS"];
|
|
REDACTED_SUFFIXES
|
|
.iter()
|
|
.any(|suffix| env_var_name.ends_with(suffix))
|
|
}
|