#!/usr/bin/env bash # Redact sensitive fields from a Pi-hole pihole.toml before committing. # Called automatically by pull-config.sh; can also be run manually. # # Usage: sanitize-config.sh # Edits the file in-place, replacing sensitive field values with "". set -euo pipefail usage() { echo "Usage: $(basename "$0") " >&2 exit 1 } [[ $# -eq 1 ]] || usage FILE="$1" [[ -f "$FILE" ]] || { echo "Error: file not found: $FILE" >&2; exit 1; } REDACTED=0 redact_field() { local field="$1" # Match lines like: pwhash = "some-value" and blank the value if grep -qE "^\s+${field}\s*=\s*\"[^\"]{1,}\"" "$FILE"; then sed -i -E "s|^(\s+${field}\s*=\s*)\"[^\"]*\"|\1\"\"|" "$FILE" echo " redacted: ${field}" REDACTED=$((REDACTED + 1)) fi } echo "Sanitizing $(basename "$FILE")..." redact_field "pwhash" redact_field "app_pwhash" redact_field "totp_secret" if [[ $REDACTED -eq 0 ]]; then echo " (nothing to redact)" else echo " ${REDACTED} field(s) redacted." fi