curl --request POST \
--url http://localhost:8080/api/v1/pipeline/protect/preset \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"preset": "hipaa-safe-harbor",
"pipeline": "<string>",
"fields": [
{
"name": "<string>",
"type": "<string>"
}
]
}
'import requests
url = "http://localhost:8080/api/v1/pipeline/protect/preset"
payload = {
"preset": "hipaa-safe-harbor",
"pipeline": "<string>",
"fields": [
{
"name": "<string>",
"type": "<string>"
}
]
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
preset: 'hipaa-safe-harbor',
pipeline: '<string>',
fields: [{name: '<string>', type: '<string>'}]
})
};
fetch('http://localhost:8080/api/v1/pipeline/protect/preset', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "8080",
CURLOPT_URL => "http://localhost:8080/api/v1/pipeline/protect/preset",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'preset' => 'hipaa-safe-harbor',
'pipeline' => '<string>',
'fields' => [
[
'name' => '<string>',
'type' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:8080/api/v1/pipeline/protect/preset"
payload := strings.NewReader("{\n \"preset\": \"hipaa-safe-harbor\",\n \"pipeline\": \"<string>\",\n \"fields\": [\n {\n \"name\": \"<string>\",\n \"type\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:8080/api/v1/pipeline/protect/preset")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"preset\": \"hipaa-safe-harbor\",\n \"pipeline\": \"<string>\",\n \"fields\": [\n {\n \"name\": \"<string>\",\n \"type\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:8080/api/v1/pipeline/protect/preset")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"preset\": \"hipaa-safe-harbor\",\n \"pipeline\": \"<string>\",\n \"fields\": [\n {\n \"name\": \"<string>\",\n \"type\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"preset": "<string>",
"fields": [
{
"name": "<string>",
"class": "name",
"method": "hmac",
"preserve": "last4",
"reason": "<string>",
"current": {
"method": "hmac",
"preserve": "last4",
"params": {}
}
}
],
"unclassified": [
"<string>"
],
"review": [
"<string>"
]
}{
"error": "<string>"
}Propose field protection from a preset (HIPAA Safe Harbor)
Classifies source fields against the preset’s fixed name table (the 18 HIPAA Safe Harbor identifier classes) and proposes each recognised field’s default method, clamped by the same rules as /api/v1/pipeline/protect/suggest (keyFields columns only hmac or none; non-string source or destination types only drop or none). Deterministic: no model call. Stateless: nothing is saved and nothing is audited. Pass preset with either pipeline (its stored source schema and constraints are used) or fields. At most 150 fields per call; _json and _xml are skipped. A stored JSON, XML or unstructured pipeline is refused with 400. Needs the same capability as reading a pipeline. An aid to applying Safe Harbor, not a certification.
curl --request POST \
--url http://localhost:8080/api/v1/pipeline/protect/preset \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"preset": "hipaa-safe-harbor",
"pipeline": "<string>",
"fields": [
{
"name": "<string>",
"type": "<string>"
}
]
}
'import requests
url = "http://localhost:8080/api/v1/pipeline/protect/preset"
payload = {
"preset": "hipaa-safe-harbor",
"pipeline": "<string>",
"fields": [
{
"name": "<string>",
"type": "<string>"
}
]
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
preset: 'hipaa-safe-harbor',
pipeline: '<string>',
fields: [{name: '<string>', type: '<string>'}]
})
};
fetch('http://localhost:8080/api/v1/pipeline/protect/preset', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "8080",
CURLOPT_URL => "http://localhost:8080/api/v1/pipeline/protect/preset",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'preset' => 'hipaa-safe-harbor',
'pipeline' => '<string>',
'fields' => [
[
'name' => '<string>',
'type' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:8080/api/v1/pipeline/protect/preset"
payload := strings.NewReader("{\n \"preset\": \"hipaa-safe-harbor\",\n \"pipeline\": \"<string>\",\n \"fields\": [\n {\n \"name\": \"<string>\",\n \"type\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:8080/api/v1/pipeline/protect/preset")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"preset\": \"hipaa-safe-harbor\",\n \"pipeline\": \"<string>\",\n \"fields\": [\n {\n \"name\": \"<string>\",\n \"type\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:8080/api/v1/pipeline/protect/preset")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"preset\": \"hipaa-safe-harbor\",\n \"pipeline\": \"<string>\",\n \"fields\": [\n {\n \"name\": \"<string>\",\n \"type\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"preset": "<string>",
"fields": [
{
"name": "<string>",
"class": "name",
"method": "hmac",
"preserve": "last4",
"reason": "<string>",
"current": {
"method": "hmac",
"preserve": "last4",
"params": {}
}
}
],
"unclassified": [
"<string>"
],
"review": [
"<string>"
]
}{
"error": "<string>"
}Authorizations
Optional API key for authentication (enabled via application.yaml)
Body
Response
The proposal
One entry per recognised field, in input order
Show child attributes
Show child attributes
Field names the table does not recognise, for a person to review
Notes for rules a method cannot express (ages over 89, small-population ZIP prefixes, free text, unclassified date-like fields)
