Skip to content

Add observable Comprehend prompt redaction - #669

Draft
QIU-Guanzong wants to merge 3 commits into
arakoodev:tsfrom
QIU-Guanzong:feat/comprehend-pii-redaction
Draft

QIU-Guanzong wants to merge 3 commits into
arakoodev:tsfrom
QIU-Guanzong:feat/comprehend-pii-redaction

Conversation

@QIU-Guanzong

@QIU-Guanzong QIU-Guanzong commented Sep 27, 2026 •

Copy link
Copy Markdown

Adds a JavaScript Comprehend redactor for #290. It plugs into RxJS pipelines and wraps the existing chat methods so prompt and message text are redacted before the endpoint is called.

The patch validates character ranges, merges overlaps, preserves Unicode code-point offsets, and stops the chain on detection errors, cancellation or timeout. Inputs are copied before asynchronous detection. destroy() releases an owned SDK client and blocks later forwarding.

Validation on dd0632cb2d96ac8c2bf17bd0f19e6a737039b3a2:

  • 34 focused Vitest tests passed, including a real AWS SDK request to a local HTTP fixture, mutable-input regressions and client cleanup.
  • TypeScript package build and git diff --check passed.
  • The runnable example uses the existing OpenAI class with a synthetic response adapter. It verifies redacted downstream input and zero downstream calls after a detection failure.

Reproduce from JS/edgechains/arakoodev:

npm install
npm run build
npx vitest run src/redaction/src/redaction.test.ts
node ../examples/pii-redaction/demo.mjs

Draft: acceptance evidence is incomplete. No real AWS or OpenAI service call was made, and the requested Loom recording is still missing. The README explains the offline fixture and the separately gated live mode. I asked about the demonstration requirement in this comment. No bounty claim is being made with this draft.

The AWS dependency requires Node 20+; validation used the local environment, not the repository's Node 18 workflow. Supported redaction paths are plain-text prompt and messages[].content; metadata and tool arguments are outside scope. Comprehend may miss PII, so this is not a guarantee of anonymization.

Developed and reviewed with AI assistance (Codex). The demo contains only synthetic input.

Offline review recording

31-second recording, full original video and execution logs. The recording shows the actual local fixture run followed by 34 passing tests. Idle intervals were removed; no execution frames were replaced. All nine uploaded asset sizes and SHA-256 digests were read back and matched locally. This remains offline evidence, not live AWS validation or the requested Loom submission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant