Documentation
¶
Overview ¶
Package audit is the transparency layer for what leaves the machine: an append-only audit log of counts (never content), an opt-in store of the exact redacted payloads of recent sends, and an optional confirm step.
Index ¶
Constants ¶
const FileName = "redaction-audit.jsonl"
FileName is the audit log's name inside the state directory.
const ReviewFileName = "redaction-review.json"
ReviewFileName is the review store's name inside the state directory.
Variables ¶
var ErrDeclined = errors.New("send declined at the confirm prompt")
ErrDeclined means the user answered no to the confirm prompt; nothing was sent or recorded.
Functions ¶
func SortedKeys ¶
SortedKeys lists a count map's keys, highest count first, ties by name.
Types ¶
type Entry ¶
type Entry struct {
Time time.Time `json:"time"`
Agent string `json:"agent"`
QuestionSet string `json:"question_set"`
Payload string `json:"payload"`
}
Entry is one stored send: the exact already-redacted payload.
type Log ¶
type Log struct {
Path string
// contains filtered or unexported fields
}
Log is an append-only JSONL file, 0600 in a 0700 directory.
type Record ¶
type Record struct {
Time time.Time `json:"time"`
Agent string `json:"agent"`
QuestionSet string `json:"question_set"`
BytesBefore int `json:"bytes_before"`
BytesAfter int `json:"bytes_after"`
Hits map[string]int `json:"hits"`
}
Record is one audit line. It carries rule ids and counts only: never matched content, and never the payload.
type Review ¶
type Review struct {
Path string
Enabled bool
// Max and TTL default to 20 and 24h when zero.
Max int
TTL time.Duration
// Now is the clock; nil means time.Now.
Now func() time.Time
// contains filtered or unexported fields
}
Review keeps the last Max sends for TTL. It is off unless Enabled, because stored payloads are themselves sensitive; while off it holds nothing and deletes anything a previous run left behind.
type Summary ¶
type Summary struct {
Sends int `json:"sends"`
BytesBefore int `json:"bytes_before"`
BytesAfter int `json:"bytes_after"`
First time.Time `json:"first,omitempty"`
Last time.Time `json:"last,omitempty"`
Agents map[string]int `json:"agents"`
QuestionSets map[string]int `json:"question_sets"`
Hits map[string]int `json:"hits"`
}
Summary aggregates records.
type Transparency ¶
type Transparency struct {
Log *Log
Review *Review
// Prompter is set only by interactive callers (`jevkit key test`, MCP
// jev_ask style calls). Hooks leave it nil so they never block, even when
// redact.confirm is on.
Prompter Prompter
Now func() time.Time
}
Transparency wraps the send path with an audit line, the review store and the optional confirm step.
func (*Transparency) Gate ¶
func (t *Transparency) Gate(ctx context.Context, cfg *config.Config, m Meta, subject, text string, send config.Send) (out, pattern string, sent bool, err error)
Gate is config.Gate with transparency: never_send, then redaction, then the confirm prompt, then the audit line and review entry, then send. A failure to record stops the send: what cannot be audited is not sent.