logging.rs (928B)
1 //! PII-safe logging utilities. 2 //! 3 //! Provides hashing functions for sensitive data (emails, IDs) so that 4 //! log entries preserve correlation without exposing raw PII. 5 6 use sha2::{Digest, Sha256}; 7 8 /// Hash an email for logging (preserves privacy while enabling correlation). 9 /// The same email always produces the same hash, so you can correlate 10 /// log entries for a customer without storing their raw email. 11 pub fn hash_email(email: &str) -> String { 12 let mut hasher = Sha256::new(); 13 hasher.update(email.as_bytes()); 14 let result = hasher.finalize(); 15 // Truncate to 8 bytes (64 bits) for readability 16 format!("sha256:{}", hex::encode(&result[..8])) 17 } 18 19 /// Hash a numeric ID for logging. 20 #[allow(dead_code)] 21 pub fn hash_id(id: i32) -> String { 22 let mut hasher = Sha256::new(); 23 hasher.update(id.to_le_bytes()); 24 let result = hasher.finalize(); 25 format!("sha256:{}", hex::encode(&result[..8])) 26 }