Expand description
Removing personal data from what the credit registration pipeline keeps of its Suotar exchanges: the call log’s bodies, the ledger’s event details and error messages.
Enums§
Constants§
- NEVER_
SCANNED_ 🔒KEYS - Keys whose values the value scan must leave alone: they carry ids shaped like student numbers —
request item ids, Sisu ids such as
hy-CUR-135176012— that the scan would mangle. - REDACTED
- Replaces a redacted value; the key is kept so the payload shape survives.
- REDACTED_
KEYS 🔒 - Keys whose values identify a person or authenticate a request. Matched case-insensitively at any depth.
Statics§
- EMAIL_
RE 🔒 - STUDENT_
NUMBER_ 🔒RE - Student-number-shaped digit runs. The id shapes come first because the
regexcrate has no lookaround: leftmost-first alternation is the only way to say “digits not part of an id”. The word boundaries keep the digit branch off longer numbers such as millisecond timestamps.
Functions§
- keep_
scalars 🔒 - Keeps bare ids and lists of ids, but hands objects back to
scrub_suotar_bodyso an exemption cannot smuggle a nested error message past the value scan. - key_
policy 🔒 - normalize_
key 🔒 - scrub_
suotar_ body - Best-effort removal of personal data from a Suotar request or response body. Not a guarantee and not an exhaustive PII filter.
- scrub_
text - Scrubs a bare error message with the same rules as a JSON body’s free text.
- suotar_
exchange_ details - Both sides of a Suotar exchange, scrubbed on construction so there is no way to build an
unscrubbed
details. The request is kept because the ledger row no longer reflects it after a retry.