maskSecret function

String maskSecret(
  1. String? secret
)

Renders secret safe to put in a log line: first four characters, ...., last four.

maskSecret('dg_a1b2c3d4e5f9b2')  // dg_a....f9b2

Anything shorter than twelve characters masks fully, to **** — with eight of them shown, a short key would be more revealed than hidden. Null and empty mask the same way, so a call site never has to check first.

Use this for every secret that reaches a log line, not just the ones that look sensitive. A dev console gets pasted into support tickets and screenshots, and the SDK's default verbosity outside release is debug — so anything logged is, in practice, logged everywhere.

Implementation

String maskSecret(String? secret) {
  if (secret == null || secret.length < 12) return '****';
  return '${secret.substring(0, 4)}....${secret.substring(secret.length - 4)}';
}