寻求支持配置指定字段的XML键值标签内容脱敏工具
Hey there! I totally get your frustration with rigid XPath-based solutions—having to update code every time a new field gets added is such a pain. Here are some great tools and approaches that let you configure which keys to redact without touching core logic, keeping things scalable:
1. XMLStarlet (Command-Line Tool)
XMLStarlet is a powerful command-line utility for XML processing, and you can pair it with XSLT templates that pull redaction rules from a config (instead of hardcoding keys).
How to set it up:
- Create an XSLT template (
redact.xsl) that accepts a parameter listing keys to redact. This way, you can pass different configs without changing the template:
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"> <!-- Parameter for keys to redact (pass via command line) --> <xsl:param name="redact-keys" select="'key1,key3'"/> <xsl:template match="@*|node()"> <xsl:copy> <xsl:apply-templates select="@*|node()"/> </xsl:copy> </xsl:template> <!-- Redact value if key is in our list --> <xsl:template match="entry[contains($redact-keys, key/text())]/value/text()"> <xsl:text>***REDACTED***</xsl:text> </xsl:template> </xsl:stylesheet>
- Run it via the command line, updating the
redact-keysparameter whenever you add new fields:
xmlstarlet tr redact.xsl -s redact-keys="key2,key3" input.xml > output.xml
For even better scalability, you can adjust the XSLT to load redact keys from an external XML config file instead of passing them as a parameter.
2. Python with xmltodict + Config Files
If you prefer a scriptable approach, Python’s xmltodict library makes it easy to convert XML to a dictionary, apply redaction rules from a config file (JSON/YAML), then convert back to XML.
Example workflow:
- Install dependencies:
pip install xmltodict pyyaml
- Create a config file (
redact_config.yaml) listing keys to redact:
redact_keys: - key1 - key3
- Write a simple script:
import xmltodict import yaml def redact_xml(xml_content, config_path): # Load redaction config with open(config_path, 'r') as f: config = yaml.safe_load(f) redact_keys = set(config['redact_keys']) # Convert XML to dict xml_dict = xmltodict.parse(xml_content) # Iterate through entries and redact matching keys entries = xml_dict['root']['entries']['entry'] for entry in entries: if entry['key'] in redact_keys: entry['value'] = '***REDACTED***' # Convert back to XML return xmltodict.unparse(xml_dict, pretty=True) # Usage with open('input.xml', 'r') as f: xml_input = f.read() redacted_xml = redact_xml(xml_input, 'redact_config.yaml') with open('output.xml', 'w') as f: f.write(redacted_xml)
Now, whenever you add a new field to redact, just update the YAML config—no changes to the script needed.
3. Apache Camel (Enterprise Integration)
If you’re working in an enterprise integration context, Apache Camel has robust XML processing capabilities with configurable routing rules. You can define redaction keys in a properties file and use Camel’s XPath or simple language to match and redact values dynamically.
Quick example route snippet:
// Load redact keys from properties file String redactKeys = context.resolvePropertyPlaceholders("{{redact.keys}}"); from("file:input?fileName=input.xml") .setBody() .xpath("//entry[key[contains('" + redactKeys + "', text())]]/value", String.class) .constant("***REDACTED***") .to("file:output?fileName=output.xml");
Update the redact.keys property in your config file whenever you need to add new fields.
All these approaches keep your redaction rules separate from core logic, making them easy to scale as your XML structure evolves.
内容的提问来源于stack exchange,提问作者Ankit Jain

