feat(ai): add AWS Comprehend PII redaction utility (#290) - #648
social5h3ll wants to merge 3 commits into
Conversation
Add chainable AWSComprehend utilities that detect and redact PII in prompts before existing OpenAI/Gemini/Llama endpoint calls, plus tests and a Jsonnet example. Co-authored-by: Argus <git@5h3ll.site>
Keep Jsonnet for the prompt template and secrets, and run AWSComprehend plus OpenAI.chat() in the example server so the HTTP response is not double-encoded by sync-rpc natives. Co-authored-by: Argus <git@5h3ll.site>
|
CLA Assistant Lite bot: Thank you for your submission, we really appreciate it. Before we can accept your contribution, we ask that you sign the Arakoo Contributor License Agreement. You can sign the CLA by adding a new comment to this pull request and pasting exactly the following text. I have read the Arakoo CLA Document and I hereby sign the CLA You can retrigger this bot by commenting recheck in this Pull Request |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a6956f83b3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ...args.slice(1), | ||
| ]; | ||
| } | ||
| return args; |
There was a problem hiding this comment.
Redact message-array arguments in chains
When a whitelisted gptFnChat endpoint receives its usual message array as the first argument, this falls through because arrays are neither strings nor records and forwards every message unchanged. The repository uses exactly this shape in HydeSearchService.ts:113-118, so chaining that endpoint silently sends its PII to the model; handle arrays of messages by redacting each string content before forwarding them.
Useful? React with 👍 / 👎.
| const original = redactedText.slice(beginOffset, endOffset); | ||
| const redaction = this.buildReplacement(entity, original, options); | ||
| return redactedText.slice(0, beginOffset) + redaction + redactedText.slice(endOffset); |
There was a problem hiding this comment.
Convert Comprehend offsets before slicing UTF-16 strings
When text contains an astral Unicode character such as an emoji before a detected entity, Comprehend's UTF-8 code-point offsets no longer match JavaScript's UTF-16 code-unit indices. Using those offsets directly with slice shifts the replacement boundary—for example, an emoji before an SSN can leave part of the SSN unredacted and replace adjacent text—so the offsets must first be translated to JavaScript string indices.
Useful? React with 👍 / 👎.
Translate DetectPiiEntities Unicode code-point offsets to UTF-16 indices before slice so emoji before PII cannot leak. Redact gptFnChat-style message arrays in chain(), and split prompts over the 100KB UTF-8 limit while rebasing entity offsets. Co-authored-by: Argus <git@5h3ll.site>
|
I have read the Arakoo CLA Document and I hereby sign the CLA |
|
recheck |
|
I have read the Arakoo CLA Document and I hereby sign the CLA |
|
recheck |
@algora-pbc /claim #290
Fixes #290
Summary
Adds Amazon Comprehend PII detection/redaction to the JavaScript SDK so prompts can be sanitized before they reach existing AI endpoint classes.
The current JS SDK (
OpenAI,GeminiAI,LlamaAI) is Promise-based rather than RxJS. This change follows that pattern instead of introducing a parallel Observable stack:AWSComprehenduses@aws-sdk/client-comprehend(DetectPiiEntities) and applies redaction locally from entity offsets, matching the AWS PII redaction modes (REPLACE_WITH_PII_ENTITY_TYPEandMASK).chain(endpoint)wraps existing endpoint methods (chat,streamedChat,gptFn, …) so PII is redacted before the call.pipe()/asOperator()compose the same async steps used elsewhere in the SDK.What's included
JS/edgechains/arakoodev/src/ai/src/lib/aws-comprehend/aws-comprehend.tssrc/ai/src/tests/awsComprehend.test.ts(mocked Comprehend client)JS/edgechains/examples/aws-comprehend-redactionwith a Jsonnet prompt template and TypeScriptAWSComprehend.chain(openai)Usage
Validation
npm run buildinJS/edgechains/arakoodevnpx vitest run src/ai/src/tests/awsComprehend.test.ts— 18 tests passednpm run demoinJS/edgechains/examples/aws-comprehend-redaction(credential-free mock client)POST /redactandPOST /chaton the example server return redacted promptsCloses #290