scrubCredentials function
Replaces credential-shaped substrings of text with <redacted>.
An endpoint URL is configuration, not a credential, and survives
byte-identical — the same call the panel receipt's kSecretNames makes in
tool/verify_panel_selfdrive_receipt.dart.
Implementation
String scrubCredentials(String text) => text
.replaceAllMapped(_kAuthorizationHeader, (Match m) => '${m[1]}<redacted>')
.replaceAllMapped(_kBearerToken, (Match m) => '${m[1]}<redacted>')
.replaceAllMapped(_kQueryCredential, (Match m) => '${m[1]}<redacted>')
.replaceAllMapped(_kApiKeyLiteral, (Match m) => '${m[1]}<redacted>');