Skip to main content

Module scrub

Expand description

Removing personal data from what the credit registration pipeline keeps of its Suotar exchanges: the call log’s bodies, the ledger’s event details and error messages.

Enums§

KeyPolicy 🔒

Constants§

NEVER_SCANNED_KEYS 🔒
Keys whose values the value scan must leave alone: they carry ids shaped like student numbers — request item ids, Sisu ids such as hy-CUR-135176012 — that the scan would mangle.
REDACTED
Replaces a redacted value; the key is kept so the payload shape survives.
REDACTED_KEYS 🔒
Keys whose values identify a person or authenticate a request. Matched case-insensitively at any depth.

Statics§

EMAIL_RE 🔒
STUDENT_NUMBER_RE 🔒
Student-number-shaped digit runs. The id shapes come first because the regex crate has no lookaround: leftmost-first alternation is the only way to say “digits not part of an id”. The word boundaries keep the digit branch off longer numbers such as millisecond timestamps.

Functions§

keep_scalars 🔒
Keeps bare ids and lists of ids, but hands objects back to scrub_suotar_body so an exemption cannot smuggle a nested error message past the value scan.
key_policy 🔒
normalize_key 🔒
scrub_suotar_body
Best-effort removal of personal data from a Suotar request or response body. Not a guarantee and not an exhaustive PII filter.
scrub_text
Scrubs a bare error message with the same rules as a JSON body’s free text.
suotar_exchange_details
Both sides of a Suotar exchange, scrubbed on construction so there is no way to build an unscrubbed details. The request is kept because the ledger row no longer reflects it after a retry.