user:pass@ credentials are replaced with the
literal REDACTED, with the parameter key preserved (sig=REDACTED).
Non-sensitive parameters and the path are left intact.
Built to pair with the redactUrl fetch option, e.g.
createInstrumentedFetch(undefined, { redactUrl: (u) => sanitizeUrl(u, { params: ["token"] }) }).
Unparseable input — and input with nothing to redact — is returned unchanged
(no query-string re-encoding when no secret matched).
Parameters
string
required
Returns
string