file_policy
file_policy
¶
File sensitivity policy — block access to secrets, credentials, and keys.
Functions¶
is_sensitive_file
¶
Return True if path matches a sensitive file pattern.
Checks the original path, symlink targets, and resolved path against
DEFAULT_SENSITIVE_PATTERNS. A symlink must not bypass the policy by
hiding a sensitive name anywhere in its chain.
Uses the Rust implementation when available, falls back to Python.