package com.hubilon.util; import java.util.Set; /** Header-name based masking, mirroring run.ps1's Protect-HeaderValue. */ public final class SensitiveHeaders { private static final Set NAMES = Set.of( "authorization", "proxy-authorization", "cookie", "set-cookie", "x-api-key", "apikey", "api-key", "ocp-apim-subscription-key" ); private SensitiveHeaders() { } public static boolean isSensitive(String name) { return name != null && NAMES.contains(name.toLowerCase()); } public static String maskHeaderValue(String name, String value) { if (!isSensitive(name)) { return value; } int len = value == null ? 0 : value.length(); String tail = (value != null && value.length() >= 4) ? value.substring(value.length() - 4) : ""; return ""; } /** Masks any occurrence of a known secret value inside free-form log text. */ public static String maskSecrets(String text, Iterable secrets) { if (text == null || text.isEmpty() || secrets == null) { return text; } String out = text; for (String secret : secrets) { if (secret != null && secret.length() >= 4) { out = out.replace(secret, "****" + secret.substring(secret.length() - 4)); } } return out; } }