redact or remove
elements from a supported structured collection with filter. The strategy,
path, predicate, and unavailable-data contracts are shared; the available data
targets differ by policy family.
Redaction strategies
For
partial, keepStart and keepEnd are integers from 0–256.
maskCharacter is exactly one character and defaults to *. Non-string
targets fail the transformation.
hash.saltRef is an identifier used for domain separation, not a literal
secret. Equal inputs within the same organization and salt reference produce
equal output.
fake.subtype accepts:
Structured paths
paths is optional unless the selected Resource target requires exact columns.
Without it, Forge transforms the whole value available at a supported Content
checkpoint or HTTP data target. With it, Forge transforms 1–64 selected values
inside structured Content data, HTTP JSON, or a PostgreSQL result.
Supported path syntax:
- the root
$; - property segments such as
.env; - zero-based array indexes such as
[0].
_, or -. Wildcards, recursive descent, quoted keys, filters,
slices, and negative indexes are not supported.
When matching transformations overlap, Forge selects:
Filtering
For Content Policies,filter is valid only at post_tool. For Resource
Policies, it is valid for an HTTP response body or PostgreSQL results. It
removes elements from one structured collection while preserving the order of
retained elements.
Example:
collectionPath or the predicate path cannot be evaluated,
onUnavailable: "allow" returns the original result unchanged.
onUnavailable: "block" converts the transformation failure into a blocked
outcome. Forge does not coerce comparison types.
Resource transformations
Resource Policies add one requireddataTarget for redact or filter:
For HTTP, the shared path grammar addresses decoded JSON. Forge accepts at
most 32 KiB of decoded body data and transforms it before forwarding any
targeted body. A matching enforcing policy fails closed when the body is
missing, malformed, compressed, oversized, streaming, or not JSON. It does not
return the original data because a transformation could not run.
For a successfully decoded JSON value,
onUnavailable still controls a missing
filter collection or predicate path; it cannot override the body-format and
size checks.
For PostgreSQL redaction, each path names an exact result column, such as
$.email. Paths are required. For PostgreSQL filtering,
collectionPath is $.rows, and removeWhere.path names a column relative to
each row. Filtering runs before redaction. Forge preserves NULL and adjusts
delivered SELECT and FETCH row counts after filtering. nullify works with
text and binary fields; comparisons and all other redaction strategies require
a text-compatible field format.
MySQL uses the same $.column paths and $.rows filter collection. Text
results support safe scalar comparisons and all shared textual strategies.
Binary results support nullification for safely framed values and textual
strategies for character columns. Missing, duplicate, malformed, or
incompatible targeted columns fail closed before the original value is sent.
COPY results, missing or ambiguous column descriptions, malformed messages,
and incompatible value formats fail closed before an original targeted value
is released. Forge does not retain HTTP bodies or PostgreSQL/MySQL row values in
Activity or backtests.