{"version":"2.1.285","anchor":"secret-redaction-adds-url-userinfo-patterns","canonical_anchor":"secret-redaction-adds-url-userinfo-patterns","heading":"Secret redaction catches more passwords written inside URLs","tier":"notice","area":"Redaction","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/secret-redaction-adds-url-userinfo-patterns","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Secret redaction catches more passwords written inside URLs\n\nSecret scrubbing now catches more forms of usernames and passwords written into URLs, including quoted and encoded ones\n\n**What**\n\nClaude Code scrubs secrets from text such as logs before they are stored or shown. A URL can carry a username and password before an `@` sign, like `https:\/\/user:pass@host`. This part is called userinfo.\n\n- The `url-userinfo` pattern now handles quoted userinfo and delimiter characters. Before, it was a simple match on everything between `:\/\/` and `@`.\n\n- New patterns are added: `url-userinfo-tail`, `url-userinfo-later-at`, `url-userinfo-encoded` and `masked-value-rest`.\n\n- Patterns for sensitive assignments, such as `password=...`, now accept other kinds of whitespace.\n\n**Why**\n\nCredentials written into URLs are removed in more of the forms they appear in, so fewer slip through into logs or output.\n\n- Area: Redaction\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}