Description
Introduce centralized redaction for credentials, webhook URLs, authorization data, and other sensitive configuration values before they are written to logs.
Acceptance Criteria
Sensitive fields have a defined redaction policy.
Redaction is applied consistently.
Error logging does not bypass the policy.
Tests verify that representative secrets are not emitted.
Description
Introduce centralized redaction for credentials, webhook URLs, authorization data, and other sensitive configuration values before they are written to logs.
Acceptance Criteria
Sensitive fields have a defined redaction policy.
Redaction is applied consistently.
Error logging does not bypass the policy.
Tests verify that representative secrets are not emitted.