{"_id":"@credentum/sanitize-log-output","name":"@credentum/sanitize-log-output","dist-tags":{"latest":"0.0.1"},"versions":{"0.0.1":{"name":"@credentum/sanitize-log-output","version":"0.0.1","description":"Strip CRLF injection, ANSI escapes, null bytes, and control characters from strings before logging. Prevents OWASP Log Injection.","main":"index.js","types":"index.d.ts","type":"module","license":"MIT","keywords":["sanitize","log-injection","crlf","ansi-escape","control-characters","owasp","security","logging","sanitize-log-output","log-forging"],"dependencies":{},"repository":{"type":"git","url":"git+https://github.com/credentum/sanitize-log-output.git"},"_id":"@credentum/sanitize-log-output@0.0.1","gitHead":"3a6ee0afdcf9339d47955b03278da4635f9ded7a","bugs":{"url":"https://github.com/credentum/sanitize-log-output/issues"},"homepage":"https://github.com/credentum/sanitize-log-output#readme","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-ydGKAjA6y/hNKKXx92PcEBlq6e8Co/k0gILUHaQbdQQ6xoiZQPwSOF5O1FJu3BYkNlsgDjXSTDee4sRhogfSTg==","shasum":"55003ce23368f03150a80338a7b832c4988d5a1a","tarball":"https://registry.npmjs.org/@credentum/sanitize-log-output/-/sanitize-log-output-0.0.1.tgz","fileCount":4,"unpackedSize":6479,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDLV7TRzc2zeKgWwSpw3/TqFTDoN1sg2XsDciSUSsTTVAiEAnLX44xxGWG+gQ2oX3RT1mDOq+aPmAEeKKd6/n8eFfj0="}]},"_npmUser":{"name":"credentum","email":"credento@credentum.ai"},"directories":{},"maintainers":[{"name":"credentum","email":"credento@credentum.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sanitize-log-output_0.0.1_1769907754814_0.09614033746817174"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-01T01:02:34.707Z","0.0.1":"2026-02-01T01:02:34.957Z","modified":"2026-02-01T01:02:35.195Z"},"maintainers":[{"name":"credentum","email":"credento@credentum.ai"}],"description":"Strip CRLF injection, ANSI escapes, null bytes, and control characters from strings before logging. Prevents OWASP Log Injection.","homepage":"https://github.com/credentum/sanitize-log-output#readme","keywords":["sanitize","log-injection","crlf","ansi-escape","control-characters","owasp","security","logging","sanitize-log-output","log-forging"],"repository":{"type":"git","url":"git+https://github.com/credentum/sanitize-log-output.git"},"bugs":{"url":"https://github.com/credentum/sanitize-log-output/issues"},"license":"MIT","readme":"# sanitize-log-output\n\nStrip CRLF injection, ANSI escape sequences, null bytes, and control characters from strings before logging. Prevents [OWASP Log Injection](https://owasp.org/www-community/attacks/Log_Injection).\n\n## Installation\n\n```bash\nnpm install @credentum/sanitize-log-output\n```\n\n## Usage\n\n```ts\nimport { sanitizeLogOutput } from '@credentum/sanitize-log-output';\n\nconst userInput = 'admin\\r\\n[INFO] Fake log entry\\x1B[31m hidden';\nconsole.log(`Login attempt: ${sanitizeLogOutput(userInput)}`);\n// => \"Login attempt: admin[INFO] Fake log entry hidden\"\n```\n\n## Why Use This?\n\nEvery security audit flags it. [CodeQL detects it](https://codeql.github.com/codeql-query-help/javascript/js-log-injection/) (`js-log-injection`). [Snyk blogs about it](https://snyk.io/blog/how-to-prevent-log-injection/). OWASP names it. And the recommended fix is always the same: manually call `String.prototype.replace` with a regex you copy-pasted from a blog post.\n\nThis package replaces that copy-paste pattern with a tested, typed, zero-dependency function that handles what your hand-rolled regex misses:\n\n- **CRLF injection** (`\\r\\n`, `\\r`, `\\n`) — forges fake log entries\n- **ANSI escape sequences** (`\\x1B[31m`, `\\x1B]0;title\\x07`) — hides text, hijacks terminals\n- **Null bytes** (`\\0`) — truncates log lines\n- **Control characters** (U+0000-U+001F, U+007F-U+009F) — binary injection\n\nTabs are preserved by default (legitimate in structured output).\n\n## API\n\n### `sanitizeLogOutput(input, options?)`\n\nSanitizes a string for safe inclusion in log output.\n\n**Parameters:**\n\n| Parameter | Type | Default | Description |\n|-----------|------|---------|-------------|\n| `input` | `string` | — | The string to sanitize |\n| `options.replacement` | `string` | `\"\"` | Replacement for stripped characters. Use `\"labeled\"` for forensic markers (`[NL]`, `[CR]`, `[ANSI]`, `[NULL]`, `[CTRL]`). |\n| `options.preserveTabs` | `boolean` | `true` | Keep tab characters (`\\t`). Set `false` to strip them. |\n\n**Returns:** `string` — the sanitized string.\n\n**Examples:**\n\n```ts\n// Default: strip silently, preserve tabs\nsanitizeLogOutput('line1\\nline2\\ttab');\n// => \"line1line2\\ttab\"\n\n// Labeled: forensic markers for incident response\nsanitizeLogOutput('inject\\r\\nfake\\x1B[31mred', { replacement: 'labeled' });\n// => \"inject[CR][NL]fake[ANSI]red\"\n\n// Custom replacement character\nsanitizeLogOutput('line1\\nline2', { replacement: ' ' });\n// => \"line1 line2\"\n\n// Strip tabs too\nsanitizeLogOutput('col1\\tcol2\\nline2', { preserveTabs: false });\n// => \"col1col2line2\"\n```\n\n## What This Does NOT Do\n\n- **PII masking** — use [pino-redaction](https://github.com/pinojs/pino/blob/main/docs/redaction.md)\n- **Structured log formatting** — use [pino](https://github.com/pinojs/pino) or [winston](https://github.com/winstonjs/winston)\n- **HTML sanitization** — use [DOMPurify](https://github.com/cure53/DOMPurify)\n- **Log file analysis** — use [logshield](https://www.npmjs.com/package/logshield)\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-c2f1cac445b7547aa0f4aeb7d1419197"}