feat(pii): self-service per-column masking policy enforced for the LLM

- pii_catalog: persistent per-column masking policy (default masked); GET/POST
  /api/pii/policy and POST /api/pii/lookup which redacts masked values server-side.
- get_pii masked flag now reflects the policy; dataflow exposes the dataset key.
- Data Flow PII inspector: per-column lock/unlock toggles + mask-all/unmask-all,
  so operators control exactly which data the assistant may reveal.
This commit is contained in:
mo
2026-06-27 11:36:36 +02:00
parent 9fb5b0a780
commit 215ce111f1
5 changed files with 227 additions and 22 deletions
+1
View File
@@ -143,6 +143,7 @@ def _build() -> dict[str, Any]:
p = pii_by_node.get(n["id"])
if p:
node["pii"] = {
"key": p["key"],
"has_pii": p["has_pii"], "pii_count": p["pii_count"], "all_masked": p["all_masked"],
"masked_layer": p.get("masked_layer", False),
"categories": sorted({c["category"] for c in p["pii_columns"]}),