pub struct SessionAnonymizer { /* private fields */ }Expand description
Stateful pseudonym assignment shared across texts: the same
(category, value) pair yields the same token for the lifetime of the
session, which is what keeps tokens consistent across the grains of one
recall and across the calls of one process session (session scope).
Long-lived holders bound it with SessionAnonymizer::evict_to — an
unbounded in-process re-identification table is exactly what D5 forbids.
Implementations§
Source§impl SessionAnonymizer
impl SessionAnonymizer
pub fn new(policy: AnonPolicy) -> Result<Self>
Sourcepub fn new_keyed(policy: AnonPolicy, key: [u8; 32]) -> Result<Self>
pub fn new_keyed(policy: AnonPolicy, key: [u8; 32]) -> Result<Self>
A session whose pseudonym ids derive from key — the memory-scope
and ingress form. The same (key, category, value) always yields the
same token, on any handle.
pub fn policy(&self) -> &AnonPolicy
Sourcepub fn mapping(&self) -> &BTreeMap<String, String>
pub fn mapping(&self) -> &BTreeMap<String, String>
The accumulated placeholder → value map (pseudonym spans only).
pub fn into_mapping(self) -> BTreeMap<String, String>
pub fn len(&self) -> usize
pub fn is_empty(&self) -> bool
Sourcepub fn mapping_id(&self, key: Option<&[u8]>) -> Result<String>
pub fn mapping_id(&self, key: Option<&[u8]>) -> Result<String>
The keyed round-trip handle over the current mapping state (D11).
Sourcepub fn transform_text(
&mut self,
text: &str,
known_identities: &[String],
) -> Result<(String, usize)>
pub fn transform_text( &mut self, text: &str, known_identities: &[String], ) -> Result<(String, usize)>
Detect + apply actions over one text; returns (transformed, spans replaced). Tokens already literally present in the text are reserved so minted tokens renumber around them.
Sourcepub fn transform_text_with(
&mut self,
text: &str,
known_identities: &[String],
backends: &[&dyn DetectorBackend],
) -> Result<(String, usize)>
pub fn transform_text_with( &mut self, text: &str, known_identities: &[String], backends: &[&dyn DetectorBackend], ) -> Result<(String, usize)>
Self::transform_text with host detector backends (fail-closed on
a demanded-but-missing kind — see scan_with).
Sourcepub fn transform_value(&mut self, category: &str, value: &str) -> String
pub fn transform_value(&mut self, category: &str, value: &str) -> String
Structural single-value transform: a whole field value whose category
the schema already knows (a subject is a person by construction).
Applies the category’s action to the entire value.
Sourcepub fn token_if_known(&self, category: &str, value: &str) -> Option<&str>
pub fn token_if_known(&self, category: &str, value: &str) -> Option<&str>
The token already assigned to (category, value), if any — exact
lookup, no detection. Lets callers keep bare entity-term lists
(graph reads) consistent with values pseudonymized elsewhere.
Sourcepub fn evict_to(&mut self, max_entries: usize)
pub fn evict_to(&mut self, max_entries: usize)
Bound the session table, evicting oldest-first. An evicted value loses its stable token (and its mapping entry — old responses citing it stop rehydrating); the next sighting mints a fresh one. That is the deliberate cost of bounding a long-lived re-identification table.
Sourcepub fn take_pending(&mut self) -> Vec<(String, String)>
pub fn take_pending(&mut self) -> Vec<(String, String)>
New (token, value) pairs minted since the last drain — the vault write-behind hook (proposal §7). Seeded entries never appear here.
Sourcepub fn seed(&mut self, entries: Vec<(String, String)>)
pub fn seed(&mut self, entries: Vec<(String, String)>)
Seed the session from persisted vault rows so tokens continue across process restarts instead of colliding. Counter-based sessions bump their counters past every seeded numeric id.
Sourcepub fn scrub_values(&mut self, identities: &[String]) -> usize
pub fn scrub_values(&mut self, identities: &[String]) -> usize
Drop every entry whose value matches one of identities — the
in-memory half of REQ-ANON-1 (an erased subject must not survive in
any live mapping).
Trait Implementations§
Source§impl Clone for SessionAnonymizer
impl Clone for SessionAnonymizer
Source§fn clone(&self) -> SessionAnonymizer
fn clone(&self) -> SessionAnonymizer
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more