feat(privacy): scan ingested sources for customer-identifying data
Detection-only scan (internal/privacy) attached to every AnalysisResult: a customer-domain guess plus a findings list (category, file, line, match, hint), ported from the KB grep playbook. Runs on archive uploads and the serialized Redfish tree; gated by LOGPILE_PRIVACY_SCAN (default on). Surfaced at GET /api/privacy-scan, in the "Customer data" UI panel, and as privacy_report.json in the raw-export bundle. IP policy keeps RFC1918 and example ranges out of findings; allowlist covers standards-body and vendor infrastructure domains. No customer tokens in the repo. See ADL-066 and bible-local/docs/privacy-scan.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
3311bafd8e
commit
4a4910f207
@@ -19,6 +19,7 @@ const (
|
||||
rawExportBundlePackageFile = "raw_export.json"
|
||||
rawExportBundleLogFile = "collect.log"
|
||||
rawExportBundleFieldsFile = "parser_fields.json"
|
||||
rawExportBundlePrivacyFile = "privacy_report.json"
|
||||
)
|
||||
|
||||
type RawExportPackage struct {
|
||||
@@ -150,6 +151,20 @@ func buildRawExportBundle(pkg *RawExportPackage, result *models.AnalysisResult,
|
||||
return nil, err
|
||||
}
|
||||
|
||||
if result != nil && result.PrivacyScan != nil {
|
||||
pf, err := zw.Create(rawExportBundlePrivacyFile)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
privacyJSON, err := json.MarshalIndent(result.PrivacyScan, "", " ")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if _, err := pf.Write(privacyJSON); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
if err := zw.Close(); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user