Conservative policy
Only reviewed operational fields with expected scalar types can pass through; every unknown field is redacted by default.
Day 029 / Frappe / Configuration Privacy
A dependency-free Python CLI that creates a conservative, allowlist-based copy of a Frappe site configuration while replacing every unrecognized value.
Only reviewed operational fields with expected scalar types can pass through; every unknown field is redacted by default.
Rejects non-object input, excessive key counts, invalid key names and incompatible values before producing a report.
Clearly states that generated output still needs inspection because key names and ordinary settings may reveal system details.
Allowlist-based redaction
Unknown values hidden by default
Nested values collapsed to one marker
Deterministic JSON report
Original file left untouched
Eleven passing standard-library tests
Argparse, pathlib, JSON and typed validation provide the complete dependency-free command-line workflow.
Uses data minimization and a fixed allowlist instead of relying on incomplete secret-name pattern matching.
Eleven tests cover safe fields, unknown and nested values, type boundaries, deterministic ordering, immutability and CLI output.