fix(redact): match Supabase secret prefixes without a leading word boundary

main

Commit

suhaanthayyil2mo ago

The provider-token layer anchored sb_secret_/sbp_ with a leading \b, which only matches after a non-word character. A secret glued to a preceding word character therefore slipped through: an underscore-joined name, or — in the JSONL fall-back / raw redact.Bytes path that redacts undecoded text — a JSON escape whose trailing letter abuts the prefix (e.g. "…line1\nsb_secret_…", where the byte before "sb" is the literal 'n'). These bodies are low-entropy, so no other layer backs the provider layer up and the raw key would reach the checkpoint blob.

Drop the \b anchor. The 10/4-char prefixes plus the {20,} length floor keep a legitimate mid-word collision vanishingly unlikely, and any high-entropy incidental match is already covered by the entropy layer. Add mutation-verified regression tests for the word-char-preceded and escape-glued cases (String path) and the malformed-line JSONL fall-back.