pub struct DlpEngine { /* private fields */ }Expand description
The compiled DLP engine. Built once per config (re)load and carried on the proxy
Runtime.
Implementations§
Source§impl DlpEngine
impl DlpEngine
Sourcepub fn build(cfg: &DlpCfg) -> Result<Option<DlpEngine>>
pub fn build(cfg: &DlpCfg) -> Result<Option<DlpEngine>>
Build from [llm.dlp]. Returns Ok(None) when the mode is off (the proxy then skips DLP
entirely). A bad custom regex / mode / style — or [llm.dlp.ner].enabled without the ner
feature compiled in — fails here, at startup/reload.
pub fn mode(&self) -> DlpMode
pub fn scan_request(&self) -> bool
pub fn scan_response(&self) -> bool
Sourcepub fn stream_redact(&self) -> bool
pub fn stream_redact(&self) -> bool
Whether streamed SSE frames should be rewritten (deterministic spans only) in redact mode.
Never true in reversible mode — there the response is unmasked, not redacted.
Sourcepub fn reversible(&self) -> bool
pub fn reversible(&self) -> bool
Whether reversible masking is active (redact mode + [llm.dlp].reversible). When true, an
inbound finding is replaced with a placeholder recorded in a MaskMap, and the response is
unmasked from that map instead of being scanned/redacted.
Sourcepub fn scan(&self, text: &str) -> Vec<Finding>
pub fn scan(&self, text: &str) -> Vec<Finding>
Scan text, returning every finding including the NER family when compiled/enabled. Used on the
buffered request/response bodies. Findings are returned sorted by start offset, overlaps merged.
Sourcepub fn scan_stream(&self, text: &str) -> Vec<Finding>
pub fn scan_stream(&self, text: &str) -> Vec<Finding>
Scan text with the deterministic families only (signature / gazetteer / entropy) — never the
NER model. Used on the streaming path, where running ML over partial, mid-token frames would be
both slow and unreliable. Findings are sorted by start offset, overlaps merged.
Sourcepub fn redact(&self, text: &str, findings: &[Finding]) -> String
pub fn redact(&self, text: &str, findings: &[Finding]) -> String
Replace each finding’s span per the configured RedactStyle. findings must be the sorted,
merged output of scan / scan_stream.
Sourcepub fn redact_reversible(
&self,
text: &str,
findings: &[Finding],
map: &mut MaskMap,
) -> String
pub fn redact_reversible( &self, text: &str, findings: &[Finding], map: &mut MaskMap, ) -> String
Redact reversibly: replace each finding’s span with a placeholder minted by map (identical
values reuse one placeholder), recording the placeholder→original mapping so the response can be
unmasked later. findings must be sorted/merged (as scan returns). Used inbound
when [llm.dlp].reversible is on; the provider sees only placeholders.