Skip to content

Commit 581145d

Browse files
Polishing few things
1 parent 9d1d1e9 commit 581145d

File tree

2 files changed

+29
-20
lines changed

2 files changed

+29
-20
lines changed

docs/utilities/data_masking.md

Lines changed: 26 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -109,14 +109,14 @@ Erasing will remove the original data and replace it with a `*****`. This means
109109
1. See [working with nested data](#working-with-nested-data) to learn more about the `fields` parameter. </br></br>If we omit `fields` parameter, the entire dictionary will be erased with `*****`.
110110

111111
=== "generic_data_input.json"
112-
```json hl_lines="7 9 14"
113-
--8<-- "examples/data_masking/src/generic_data_input.json"
114-
```
112+
```json hl_lines="7 9 14"
113+
--8<-- "examples/data_masking/src/generic_data_input.json"
114+
```
115115

116116
=== "getting_started_erase_data_output.json"
117-
```json hl_lines="5 7 12"
118-
--8<-- "examples/data_masking/src/getting_started_erase_data_output.json"
119-
```
117+
```json hl_lines="5 7 12"
118+
--8<-- "examples/data_masking/src/getting_started_erase_data_output.json"
119+
```
120120

121121
### Encrypting data
122122

@@ -135,14 +135,14 @@ Under the hood, we delegate a [number of operations](#encrypt-operation-with-enc
135135
1. You can use more than one KMS Key for higher availability but increased latency. </br></br>Encryption SDK will ensure the data key is encrypted with both keys.
136136

137137
=== "generic_data_input.json"
138-
```json hl_lines="7-9 14"
139-
--8<-- "examples/data_masking/src/generic_data_input.json"
140-
```
138+
```json
139+
--8<-- "examples/data_masking/src/generic_data_input.json"
140+
```
141141

142142
=== "encrypt_data_output.json"
143-
```json hl_lines="5-7 12"
144-
--8<-- "examples/data_masking/src/encrypt_data_output.json"
145-
```
143+
```json
144+
--8<-- "examples/data_masking/src/encrypt_data_output.json"
145+
```
146146

147147
### Decrypting data
148148

@@ -164,21 +164,23 @@ Under the hood, we delegate a [number of operations](#decrypt-operation-with-enc
164164
1. Note that KMS key alias or key ID won't work.
165165
2. You can use more than one KMS Key for higher availability but increased latency. </br></br>Encryption SDK will call `Decrypt` API with all master keys when trying to decrypt the data key.
166166

167-
=== "encrypt_data_output.json"
167+
=== "getting_started_decrypt_data_input.json"
168168

169-
```json hl_lines="5-7 12"
170-
--8<-- "examples/data_masking/src/encrypt_data_output.json"
171-
```
169+
```json
170+
--8<-- "examples/data_masking/src/getting_started_decrypt_data_input.json"
171+
```
172172

173173
=== "getting_started_decrypt_data_output.json"
174174

175-
```json hl_lines="5-7 12-17"
176-
--8<-- "examples/data_masking/src/getting_started_decrypt_data_output.json"
177-
```
175+
```json
176+
--8<-- "examples/data_masking/src/getting_started_decrypt_data_output.json"
177+
```
178178

179179
### Encryption context for integrity and authenticity
180180

181+
<!-- markdownlint-disable MD013 -->
181182
For a stronger security posture, you can add metadata to each encryption operation, and verify them during decryption. This is known as additional authenticated data (AAD). These are non-sensitive data that can help protect authenticity and integrity of your encrypted data, and even help to prevent a [confused deputy](https://docs.aws.amazon.com/IAM/latest/UserGuide/confused-deputy.html){target="_blank"} situation.
183+
<!-- markdownlint-enable MD013 -->
182184

183185
???+ danger "Important considerations you should know"
184186
1. **Exact match verification on decrypt**. Be careful using random data like `timestamps` as encryption context if you can't provide them on decrypt.
@@ -205,7 +207,7 @@ For a stronger security posture, you can add metadata to each encryption operati
205207

206208
???+ note "Current limitations"
207209
1. The `fields` parameter is currently exclusive to the `erase` method, with potential future inclusion into `encrypt` and `decrypt`.
208-
2. We support `JSON` data types only - see [data serialization for more details](#data-serialization-and-preservation)."
210+
2. We support `JSON` data types only - see [data serialization for more details](#data-serialization)."
209211

210212
You can use the `fields` parameter with the dot notation `.` to choose one or more parts of your data to `erase`. This is useful when you want to keep data structure intact except the confidential fields.
211213

@@ -424,6 +426,8 @@ You can modify the following values when initializing the `AWSEncryptionSDKProvi
424426
| **max_messages_encrypted** | `4294967296` | The maximum number of messages that may be encrypted under a cache entry |
425427
| **max_bytes_encrypted** | `9223372036854775807` | The maximum number of bytes that may be encrypted under a cache entry |
426428

429+
If required, you have the option to customize the default values when initializing the `AWSEncryptionSDKProvider` class.
430+
427431
=== "aws_encryption_provider_example.py"
428432

429433
```python hl_lines="14-19"
@@ -594,11 +598,13 @@ sequenceDiagram
594598
Testing your code with a simple erase operation
595599

596600
=== "test_lambda_mask.py"
601+
597602
```python hl_lines="22"
598603
--8<-- "examples/data_masking/tests/test_lambda_mask.py"
599604
```
600605

601606
=== "lambda_mask.py"
607+
602608
```python hl_lines="3 12"
603609
--8<-- "examples/data_masking/tests/lambda_mask.py"
604610
```
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
{
2+
"body": "AgV4uF5K2YMtNhYrtviTwKNrUHhqQr73l/jNfukkh+qLOC8AXwABABVhd3MtY3J5cHRvLXB1YmxpYy1rZXkAREEvcjEyaFZHY1R5cjJuTDNKbTJ3UFA3R3ZjaytIdi9hekZqbXVUb25Ya3J5SzFBOUlJZDZxZXpSR1NTVnZDUUxoZz09AAEAB2F3cy1rbXMAS2Fybjphd3M6a21zOnVzLWVhc3QtMToyMDA5ODQxMTIzODY6a2V5LzZkODJiMzRlLTM2NjAtNDRlMi04YWJiLTdmMzA1OGJlYTIxMgC4AQIBAHjxYXAO7wQGd+7qxoyvXAajwqboF5FL/9lgYUNJTB8VtAHBP2hwVgw+zypp7GoMNTPAAAAAfjB8BgkqhkiG9w0BBwagbzBtAgEAMGgGCSqGSIb3DQEHATAeBglghkgBZQMEAS4wEQQMx/B25MTgWwpL7CmuAgEQgDtan3orAOKFUfyNm3v6rFcglb+BVVVDV71fj4aRljhpg1ixsYFaKsoej8NcwRktIiWE+mw9XmTEVb6xFQIAABAA9DeLzlRaRQgTcXMJG0iBu/YTyyDKiROD+bU1Y09X9RBz5LA1nWIENJKq2seAhNSB/////wAAAAEAAAAAAAAAAAAAAAEAAAEBExLJ9wI4n7t+wyPEEP4kjYFBdkmNuLLsVC2Yt8mv9Y1iH2G+/g9SaIcdK57pkoW0ECpBxZVOxCuhmK2s74AJCUdem9McjS1waUKyzYTi9vv2ySNBsABIDwT990rE7jZJ3tEZAqcWZg/eWlxvnksFR/akBWZKsKzFz6lF57+cTgdISCEJRV0E7fcUeCuaMaQGK1Qw2OCmIeHEG5j5iztBkZG2IB2CVND/AbxmDUFHwgjsrJPTzaDYSufcGMoZW1A9X1sLVfqNVKvnOFP5tNY7kPF5eAI9FhGBw8SjTqODXz4k6zuqzy9no8HtXowP265U8NZ5VbVTd/zuVEbZyK5KBqzP1sExW4RhnlpXMoOs9WSuAGcwZQIxANTeEwb9V7CacV2Urt/oCqysUzhoV2AcT2ZjryFqY79Tsg+FRpIx7cBizL4ieRzbhQIwcRasNncO5OZOcmVr0MqHv+gCVznndMgjXJmWwUa7h6skJKmhhMPlN0CsugxtVWnD"
3+
}

0 commit comments

Comments
 (0)