DLP: the detector framework, the region-free detectors, word lists and attachment text
Phase 2a of the DLP and mail flow rules spec: pure functions in crates/features/src/mailflow, nothing wired into the mail path yet. - Detectors report distinct values found, each either checked by its published check digit or counted only beside a corroborating word within 50 characters. This PR adds the region-free ones: payment cards (issuer prefixes, Luhn), IBAN (registry lengths, mod 97), SWIFT/BIC, email addresses and phone numbers in bulk, dates of birth, passport numbers, private keys and published service-token formats. Regional identifiers follow, a region per PR. - Word lists (Aho-Corasick, whole words, any case) and patterns (regex with a compiled-size limit) count occurrences. - Attachment text: text files with or without a UTF-16 mark, HTML, DOCX/XLSX/PPTX, ODT/ODS/ODP and ZIP archives one level deep, read with the zip and quick-xml crates the workspace already has. Encrypted files, PDF, legacy binary Office files, nested archives and anything past the limits come back as not inspectable, with why. 21 unit tests, against the networks' test card numbers and the IBAN registry's own examples among others.
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
//! Data loss prevention and mail flow rules (dlp-and-mail-flow-rules spec).
|
||||
//!
|
||||
//! Pure functions over text and attachment bytes, so everything here is
|
||||
//! unit-tested without a server:
|
||||
//!
|
||||
//! - [`detectors`]: find identifiers in text (payment cards, IBANs,
|
||||
//! national ID numbers, keys), each by its published format and check
|
||||
//! (§2.3);
|
||||
//! - [`words`]: an organization's own word lists and patterns;
|
||||
//! - [`extract`]: the text of an attachment, or why it can't be read.
|
||||
//!
|
||||
//! Nothing here writes what it finds anywhere: callers get counts, and the
|
||||
//! matched text never leaves the evaluation (§2.7).
|
||||
|
||||
pub mod detectors;
|
||||
pub mod extract;
|
||||
pub mod words;
|
||||
Reference in New Issue
Block a user