(gitUrl: string)
| 45 | } |
| 46 | |
| 47 | function sanitizeGitUrlForLogging(gitUrl: string): string { |
| 48 | try { |
| 49 | const url = new URL(gitUrl); |
| 50 | url.username = ''; |
| 51 | url.password = ''; |
| 52 | return url.toString(); |
| 53 | } catch { |
| 54 | // If URL parsing fails, return as-is (shouldn't happen with validated URLs) |
| 55 | return gitUrl; |
| 56 | } |
| 57 | } |
| 58 | |
| 59 | // Mask authentication tokens in git output to prevent leaking secrets in logs/errors. |
| 60 | // Handles patterns like `oauth2:TOKEN@`, `x-access-token:TOKEN@`, and `x-token-auth:TOKEN@`. |
| 61 | function sanitizeGitOutput(output: string): string { |
no test coverage detected