Skip to main content

SessionAnonymizer

Struct SessionAnonymizer 

Source
pub struct SessionAnonymizer { /* private fields */ }
Expand description

Stateful pseudonym assignment shared across texts: the same (category, value) pair yields the same token for the lifetime of the session, which is what keeps tokens consistent across the grains of one recall and across the calls of one process session (session scope). Long-lived holders bound it with SessionAnonymizer::evict_to — an unbounded in-process re-identification table is exactly what D5 forbids.

Implementations§

Source§

impl SessionAnonymizer

Source

pub fn new(policy: AnonPolicy) -> Result<Self>

Source

pub fn new_keyed(policy: AnonPolicy, key: [u8; 32]) -> Result<Self>

A session whose pseudonym ids derive from key — the memory-scope and ingress form. The same (key, category, value) always yields the same token, on any handle.

Source

pub fn policy(&self) -> &AnonPolicy

Source

pub fn mapping(&self) -> &BTreeMap<String, String>

The accumulated placeholder → value map (pseudonym spans only).

Source

pub fn into_mapping(self) -> BTreeMap<String, String>

Source

pub fn len(&self) -> usize

Source

pub fn is_empty(&self) -> bool

Source

pub fn mapping_id(&self, key: Option<&[u8]>) -> Result<String>

The keyed round-trip handle over the current mapping state (D11).

Source

pub fn transform_text( &mut self, text: &str, known_identities: &[String], ) -> Result<(String, usize)>

Detect + apply actions over one text; returns (transformed, spans replaced). Tokens already literally present in the text are reserved so minted tokens renumber around them.

Source

pub fn transform_text_with( &mut self, text: &str, known_identities: &[String], backends: &[&dyn DetectorBackend], ) -> Result<(String, usize)>

Self::transform_text with host detector backends (fail-closed on a demanded-but-missing kind — see scan_with).

Source

pub fn transform_value(&mut self, category: &str, value: &str) -> String

Structural single-value transform: a whole field value whose category the schema already knows (a subject is a person by construction). Applies the category’s action to the entire value.

Source

pub fn token_if_known(&self, category: &str, value: &str) -> Option<&str>

The token already assigned to (category, value), if any — exact lookup, no detection. Lets callers keep bare entity-term lists (graph reads) consistent with values pseudonymized elsewhere.

Source

pub fn evict_to(&mut self, max_entries: usize)

Bound the session table, evicting oldest-first. An evicted value loses its stable token (and its mapping entry — old responses citing it stop rehydrating); the next sighting mints a fresh one. That is the deliberate cost of bounding a long-lived re-identification table.

Source

pub fn take_pending(&mut self) -> Vec<(String, String)>

New (token, value) pairs minted since the last drain — the vault write-behind hook (proposal §7). Seeded entries never appear here.

Source

pub fn seed(&mut self, entries: Vec<(String, String)>)

Seed the session from persisted vault rows so tokens continue across process restarts instead of colliding. Counter-based sessions bump their counters past every seeded numeric id.

Source

pub fn scrub_values(&mut self, identities: &[String]) -> usize

Drop every entry whose value matches one of identities — the in-memory half of REQ-ANON-1 (an erased subject must not survive in any live mapping).

Trait Implementations§

Source§

impl Clone for SessionAnonymizer

Source§

fn clone(&self) -> SessionAnonymizer

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SessionAnonymizer

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more