Terminal Streams Channel (stdout, stderr)
- Default Mode:
"warn" - Target:
process.stdoutandprocess.stderrpipes from the child process.
stdout and stderr channels inspect these streams and redact active secrets.
Real-Time SHA-256 Redaction
When a secret value appears in standard output or error:envtrapreplaces the secret value inline with its non-reversible truncated SHA-256 digest:- The redacted stream is forwarded to the parent terminal.
- Raw secret values are never printed to the screen or recorded in log files.
Enforcement Modes
- warn (Default)
- block
- off
Redacts secrets from the stream output, logs a leak incident, and allows the application process to continue running normally.
Child-Level Pre-Redaction & Fast-Path
If output originates from a test file or script matchingexclusions.paths, hooks.mjs pre-redacts the string inside the child process to [REDACTED: PATH_EXCLUDED]. Because the parent stream scanner receives an already-sanitized string, no alerts or warnings are raised.
Zero-Overhead Fast-Path (v3.1)
- Stack Inspection Bypass: In v3.1, stack frame parsing is completely skipped if no
exclusions.pathsare configured inenvtrap.json, or if the chunk does not contain any registered secret values. This ensures near-zero CPU and latency overhead on high-throughput console logging. - Double-Wrapping Guard:
process.stdout.writeandprocess.stderr.writehooks include an unwrap guard and recursion flag to prevent multiple wrapping layers or infinite loops when logger libraries wrap streams.
Configuration Example
envtrap.json
