Day 029 / Frappe / Configuration Privacy

Site Config Redactor

View source ↗Scroll to explore ↓
Site Config Redactor project cover
/ Overview

A dependency-free Python CLI that creates a conservative, allowlist-based copy of a Frappe site configuration while replacing every unrecognized value.

NameSite Config Redactor

ClientIndependent daily build

IndustriesDeveloper and operations tooling

DateDay 029 · September 28, 2026

/ Challenge

A Frappe site configuration can mix ordinary runtime settings with database details, encryption keys and custom fields. Guessing which values are secrets from their names alone can leave sensitive information behind.

/ Provided services

Clear thinking.
Practical delivery.

01

Conservative policy

Only reviewed operational fields with expected scalar types can pass through; every unknown field is redacted by default.

02

Bounded validation

Rejects non-object input, excessive key counts, invalid key names and incompatible values before producing a report.

03

Human review boundary

Clearly states that generated output still needs inspection because key names and ordinary settings may reveal system details.

Site Config Redactor feature visual
/ Solution

Site Config Redactor validates a bounded top-level JSON object, retains only a small reviewed allowlist of scalar operational fields and replaces every other value with a fixed marker. It creates a new deterministic report locally without editing the source, connecting to a site or uploading data.

/ Impact

Allowlist-based redaction

Unknown values hidden by default

Nested values collapsed to one marker

Deterministic JSON report

Original file left untouched

Eleven passing standard-library tests

/ Tech stack

Python standard library

Argparse, pathlib, JSON and typed validation provide the complete dependency-free command-line workflow.

Configuration privacy

Uses data minimization and a fixed allowlist instead of relying on incomplete secret-name pattern matching.

Unittest

Eleven tests cover safe fields, unknown and nested values, type boundaries, deterministic ordering, immutability and CLI output.

Next project

Backup Freshness Checker

View case study ↗