@glideco/dsar
v0.1.0
Published
DSAR redaction primitives for activity_log: bitmap encoding, transactional redaction with append-only-trigger session var, tombstone (full erasure) workflow.
Downloads
15
Maintainers
Readme
@glideco/dsar
DSAR (Data Subject Access Request) redaction primitives for Glide's agent activity log. Provides:
- Bitmap encoding — 32-bit
redacted_fields_bitmapwith 8 v1 field positions redact()— partial-field redaction (additive bitmap OR)tombstone()— full-erasure all-fields redaction- Append-only-trigger session-var helper — sets
app.dsar_context_idso the trigger lets the UPDATE through - DB-agnostic — operator passes in an
executorinterface
Install
npm install @glideco/dsarUsage
import { redact, type DsarExecutor } from '@glideco/dsar';
// Operator wires the executor over their DB driver (Drizzle, raw pg, etc.):
const executor: DsarExecutor = {
async setSessionVar(name, value) {
await db.execute(sql`SELECT set_config(${name}, ${value}, true)`);
},
async setBitmap(rowId, bitmap) {
await db
.update(activityLog)
.set({ redactedFieldsBitmap: bitmap })
.where(eq(activityLog.id, rowId));
},
async getBitmap(rowId) {
const [row] = await db
.select({ redactedFieldsBitmap: activityLog.redactedFieldsBitmap })
.from(activityLog)
.where(eq(activityLog.id, rowId))
.limit(1);
return row?.redactedFieldsBitmap ?? null;
},
async appendAuditRow(audit) {
await db.insert(activityLog).values({
action: audit.action,
details: audit.details,
});
},
};
// Apply a redaction inside a transaction:
await db.transaction(async (tx) => {
// (Wrap executor with `tx` instead of `db` if your driver requires it.)
await redact(executor, {
rowId: 'row_abc',
fields: ['amount', 'counterparty'],
reason: 'GDPR right-to-erasure request from [email protected]',
actorUserId: 'admin_xyz',
});
});Append-only trigger contract
This package assumes the operator's activity_log table has an
append-only trigger that:
- Rejects
UPDATE/DELETE/TRUNCATEunlessapp.dsar_context_idis set in the current session. - When the session var is set, allows
UPDATEonly onredacted_fields_bitmap.
See apps/web/drizzle/0042_activity_log_agent_cols.sql
in the source repo for the reference trigger definition.
v1 field positions
Bitmap bits are stable v1; new fields go in unused positions (8-31). Removing or repositioning a field is a major-version bump.
| Bit | Field |
| --- | --------------- |
| 0 | input_digest |
| 1 | output_digest |
| 2 | on_chain_tx |
| 3 | counterparty |
| 4 | amount |
| 5 | vendor_used |
| 6 | grant_id |
| 7 | step_up_sigil |
License
MIT.
