feat(sanitize): in-place, length-preserving log de-identification
Adds internal/sanitize: rewrites the customer-identifying spans that internal/privacy detects (domain/FQDN/e-mail/AD/public-IP/timezone) with same-length neutral fillers, in place, without changing the file format. - Fillers keep byte length: "sigma.sbrf.ru" -> "xxxxx.xxxx.xx", IP -> "00.000.000.00", "Europe/Moscow" -> "Etc/Universal" (same-length valid neutral IANA zone), offset "180" -> "000". Timestamps are not recomputed. - Lossless recursive archive walk (tar/.sds/gz/tgz/zip): entry names, modes, and all embedded timestamps preserved; untouched zip entries copied raw; member payload length unchanged so tar headers stay byte-identical; only the .gz/.zip compression layer is rebuilt. 0 redactions -> byte-identical output. - privacy.FindSpans is the one matcher shared by detection and redaction; fillers are recognised by isRedactionFiller so a re-scan / second pass is a no-op. New privacy FPs fixed along the way: syslog selectors (local7.info), "MEVersion" firmware quads, *.conf_bak vendor templates, bundled viewer domains. - Binary members (FRU.bin, localtime, redis-dump.rdb, SOL captures) and unreadable nested archives are reported in Result.SkippedBinary, never edited. - Surfaces: POST /api/sanitize (+ GET /api/sanitize/download), the "Обезличить и скачать копию" button in the Customer-data panel, and logpile -sanitize <file> (restores mtime/atime). Verified: re-parsing a sanitized Dell TSR / xFusion / Inspur onekeylog / H3C .sds yields the identical hardware inventory; re-scan is clean. ADL-067, bible-local/docs/log-sanitization.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
e74e01ad05
commit
a63bb17438
@@ -1046,3 +1046,53 @@ code {
|
||||
font-size: 0.82em;
|
||||
color: var(--muted);
|
||||
}
|
||||
|
||||
.privacy-sanitize {
|
||||
padding: 10px 12px;
|
||||
border-bottom: 1px solid var(--border);
|
||||
}
|
||||
|
||||
.privacy-sanitize.hidden,
|
||||
.privacy-sanitize-preview.hidden {
|
||||
display: none;
|
||||
}
|
||||
|
||||
#privacy-sanitize-btn,
|
||||
.privacy-sanitize-dl {
|
||||
font-size: 0.85em;
|
||||
padding: 5px 12px;
|
||||
cursor: pointer;
|
||||
}
|
||||
|
||||
.privacy-sanitize-preview {
|
||||
margin-top: 10px;
|
||||
font-size: 0.88em;
|
||||
}
|
||||
|
||||
.privacy-sanitize-preview table {
|
||||
margin: 6px 0;
|
||||
}
|
||||
|
||||
.privacy-sanitize-dl {
|
||||
margin-top: 8px;
|
||||
font-weight: 600;
|
||||
}
|
||||
|
||||
.privacy-sanitize-warn {
|
||||
margin-top: 8px;
|
||||
padding: 6px 8px;
|
||||
background: #fff8f0;
|
||||
border: 1px solid #f0e0c0;
|
||||
border-radius: 4px;
|
||||
}
|
||||
|
||||
.privacy-sanitize-warn ul {
|
||||
margin: 4px 0 0;
|
||||
padding-left: 18px;
|
||||
font-family: monospace;
|
||||
font-size: 0.82em;
|
||||
}
|
||||
|
||||
.privacy-sanitize-err {
|
||||
color: var(--crit-fg);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user