Skip to main content

Terminal Streams Channel (stdout, stderr)

  • Default Mode: "warn"
  • Target: process.stdout and process.stderr pipes from the child process.
Logging frameworks, crash reporters, and debug statements frequently dump full request payloads or environment objects to terminal streams. The stdout and stderr channels inspect these streams and redact active secrets.

Real-Time SHA-256 Redaction

When a secret value appears in standard output or error:
  1. envtrap replaces the secret value inline with its non-reversible truncated SHA-256 digest:
  2. The redacted stream is forwarded to the parent terminal.
  3. Raw secret values are never printed to the screen or recorded in log files.

Enforcement Modes

Redacts secrets from the stream output, logs a leak incident, and allows the application process to continue running normally.

Child-Level Pre-Redaction & Fast-Path

If output originates from a test file or script matching exclusions.paths, hooks.mjs pre-redacts the string inside the child process to [REDACTED: PATH_EXCLUDED]. Because the parent stream scanner receives an already-sanitized string, no alerts or warnings are raised.

Zero-Overhead Fast-Path (v3.1)

  • Stack Inspection Bypass: In v3.1, stack frame parsing is completely skipped if no exclusions.paths are configured in envtrap.json, or if the chunk does not contain any registered secret values. This ensures near-zero CPU and latency overhead on high-throughput console logging.
  • Double-Wrapping Guard: process.stdout.write and process.stderr.write hooks include an unwrap guard and recursion flag to prevent multiple wrapping layers or infinite loops when logger libraries wrap streams.

Configuration Example

envtrap.json