Hand-written. ../harvested/authentication.md is what the documents say; this file is what the
implementation found, and it wins. Each entry names the harvested entry it answers by that entry's
stable key.
- Two renderings are one short:
ppgives aDataits own#pretty_print, which walks the members and never calls an#inspectoverride, so a credential that redacts in#to_sand#inspectalone prints its secret underpp. Correctsauthentication/f8a5bc6a("Every credential type overrides both#inspectand#to_sto satisfy the redact-in-string-form requirement, since Ruby interpolation calls#to_sand a debugger calls#inspect"), whose two renderings are right and whose enumeration is incomplete for exactly the base type design §4 fixes for every value. Verified on 2026-09-18 against 3.2.11, 3.3.12, 3.4.10 and 4.0.6, identically:D = Data.define(:token) { def inspect = "#<redacted>" }, thenPP.pp(D.new(token: "SECRET"), out), writes#<data D token="SECRET">— pp.rb definesData#pretty_printovermembers, andPP::ObjectMixin#pretty_print's "use#inspectwhen it is overridden" rule is what a plain class gets, not what aDatagets. A plain class with the same override pretty-prints through#inspect, so the two key-credential classes are safe by that route and the twoDatacredentials are not.AUTH-8says "any string/diagnostic representation", andppis the diagnostic representation a developer reaches for first. What the SDK does, perdocs/work/mvp/phase6/phase6c/2026-09-09-phase6c-authentication-design.md's as-built row P6-72:Dexpace::Auth::BearerTokenandDexpace::Auth::PasswordCredentialoverride#pretty_print(printer)asprinter.text(inspect), the third rendering beside the two the rule names, andbearer_token_test.rbandpassword_credential_test.rbeach assert theppoutput;#to_h,#membersand#deconstruct_keysstill expose the real fields, whichAUTH-8permits (redaction "MUST NOT be achieved by mutating, nulling, or otherwise corrupting the real fields"). What it licenses for later phases: anyDatathat carries a secret — a phase-7 or downstream value type — needs all three overrides, and a test that pretty-prints it. What it does not license: treatingMarshal,YAMLor#to_has renderings the object must redact; those are serialisations of the real fields and are the caller's. review ·docs/work/mvp/phase6/phase6c/2026-09-09-phase6c-authentication-checklist.md· high · sha:manual-phase6c-data-pretty-print