cf1c491f64
Untrusted text could wrap a real secret's plaintext in a fabricated friendly-name prefix around a hash suffix borrowed from any OTHER already-obfuscated secret. obfuscate() treated the whole forged token - including the exposed secret literal standing in for the prefix - as already redacted, letting it reach the provider untouched. isGeneratedPlaceholder() now refuses the friendly-name-independent alias fallback whenever the dropped prefix contains a configured secret's literal value, while still accepting a stale prefix left over from a legitimate friendly-name rename (same secret, same key).