Files
anonymizer/test/anonymizer.test.ts
Mobiletic 5ed8001101 feat: multi-turn conversation support (0.4.0)
anonymizeTurn(text, session) threads a serializable AnonymizerSession
({mapping, legend, history}) so one entity keeps one id across a whole chat
(applyKnown reuse + usedIds + de-collision merge). Adds conversation()
in-memory wrapper and an optional LlmProvider.anonymizeInConversation(text, ctx)
for rich cross-turn context; providers without it fall back to the batch path.

openAICompatibleProvider gains includeMappingInContext (default false — only
send real values to a trusted anonymizer endpoint) + historyMaxTurns (default
10). Verified live vs Gemma 4: Nora stays PER_1 across 4 turns (name/email/AVS/
IBAN), Yanis = PER_2; 41 tests, 98% coverage.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 14:26:41 +01:00

298 lines
14 KiB
TypeScript

import { describe, it, expect, vi } from 'vitest';
import {
Anonymizer,
AnonymizationError,
presets,
type LlmProvider,
type AnonymizerSession,
} from '../src/index.js';
/** An LLM provider that is configured but always fails → forces the regex fallback. */
const failingLlm = (overrides: Partial<LlmProvider> = {}): LlmProvider => ({
isConfigured: () => true,
anonymize: vi.fn().mockRejectedValue(new Error('LLM_NOT_CONFIGURED')),
anonymizeBatch: vi.fn().mockRejectedValue(new Error('LLM_NOT_CONFIGURED')),
...overrides,
});
describe('Anonymizer (Swiss preset)', () => {
const svc = new Anonymizer({ llm: failingLlm(), patterns: presets.swiss });
it('skips anonymization (no LLM call) when there is no PII', async () => {
const llm = failingLlm();
const s = new Anonymizer({ llm, patterns: presets.swiss });
const r = await s.anonymize('Explique la différence entre INNER JOIN et LEFT JOIN');
expect(r.mapping).toEqual({});
expect(r.anon).toContain('INNER JOIN');
expect(llm.anonymize).not.toHaveBeenCalled();
});
it('falls back to regex for structured PII (email/phone/AVS)', async () => {
const r = await svc.anonymize('Contact: jean@exemple.ch, +41 79 123 45 67, AVS 756.1234.5678.90');
expect(r.anon).not.toContain('jean@exemple.ch');
expect(r.anon).not.toContain('756.1234.5678.90');
expect(Object.values(r.mapping)).toContain('jean@exemple.ch');
expect(svc.deanonymize(r.anon, r.mapping)).toContain('jean@exemple.ch');
});
it('deanonymizes a placeholder split across stream tokens (critical)', () => {
const mapping = { '[PER_1.NOM:M]': 'Alain JACCARD' };
const d = svc.makeStreamDeanonymizer(mapping);
let out = '';
out += d.push('Bonjour [PER_');
out += d.push('1.NOM');
out += d.push(':M], ravi');
out += d.flush();
expect(out).toBe('Bonjour Alain JACCARD, ravi');
expect(out).not.toContain('[PER_');
});
it('streams plain text through unchanged', () => {
const d = svc.makeStreamDeanonymizer({});
expect(d.push('Un INNER JOIN ') + d.push('retourne...') + d.flush()).toBe('Un INNER JOIN retourne...');
});
describe('anonymizeChunks', () => {
it('PII-free chunks → no LLM call, returned as-is', async () => {
const llm = failingLlm();
const s = new Anonymizer({ llm, patterns: presets.swiss });
const r = await s.anonymizeChunks(['Un INNER JOIN combine deux tables.'], { mapping: {} });
expect(llm.anonymizeBatch).not.toHaveBeenCalled();
expect(r.anon[0]).toContain('INNER JOIN');
expect(r.mapping).toEqual({});
});
it('reuses the question placeholder for the same person (deterministic, no LLM)', async () => {
const llm = failingLlm();
const s = new Anonymizer({ llm, patterns: presets.swiss });
const seed = { '[PER_1.NOM:M]': 'Alain JACCARD' };
const r = await s.anonymizeChunks(['Le dossier de Alain JACCARD est complet.'], { mapping: seed });
expect(llm.anonymizeBatch).not.toHaveBeenCalled();
expect(r.anon[0]).toContain('[PER_1.NOM:M]');
expect(r.anon[0]).not.toContain('Alain JACCARD');
expect(r.mapping).toEqual(seed);
});
it('renumbers a NEW person that collides with the question placeholder', async () => {
const anonymizeBatch = vi.fn().mockResolvedValue({
segments: ['[PER_1.NOM:M] a signé.'],
mapping: { '[PER_1.NOM:M]': 'Bob Martin' },
legend: { PER: 'Personne', NOM: 'Nom de famille', M: 'Masculin' },
});
const s = new Anonymizer({ llm: failingLlm({ anonymizeBatch }), patterns: presets.swiss });
const seed = { '[PER_1.NOM:M]': 'Alain JACCARD' };
const r = await s.anonymizeChunks(['Bob Martin a signé.'], { mapping: seed });
expect(anonymizeBatch).toHaveBeenCalledTimes(1);
expect(r.anon[0]).toContain('[PER_2.NOM:M]');
expect(r.mapping['[PER_1.NOM:M]']).toBe('Alain JACCARD');
expect(r.mapping['[PER_2.NOM:M]']).toBe('Bob Martin');
// legend covers the abbreviations used in the anonymized chunk
expect(r.legend).toMatchObject({ PER: 'Personne', NOM: 'Nom de famille', M: 'Masculin' });
});
it('falls back to regex (structured ids) when the LLM is unavailable', async () => {
const s = new Anonymizer({ llm: failingLlm(), patterns: presets.swiss });
const r = await s.anonymizeChunks(['Contact : jean@exemple.ch'], { mapping: {} });
expect(r.anon[0]).not.toContain('jean@exemple.ch');
expect(Object.values(r.mapping)).toContain('jean@exemple.ch');
});
});
describe('regex-only mode (no LLM provider)', () => {
const s = new Anonymizer({ patterns: presets.swiss });
it('still anonymizes structured PII without any provider', async () => {
const r = await s.anonymize('Écris à jean@exemple.ch');
expect(r.anon).not.toContain('jean@exemple.ch');
expect(Object.values(r.mapping)).toContain('jean@exemple.ch');
});
it('leaves a bare proper name untouched (no LLM to catch it)', async () => {
const r = await s.anonymize('Alain Jaccard a réussi');
// The name-hint flags it, but with no LLM the regex fallback finds no structured id.
expect(r.anon).toContain('Alain Jaccard');
expect(r.mapping).toEqual({});
});
});
describe('configurable presets', () => {
it('generic preset anonymizes an IPv4 address', async () => {
const s = new Anonymizer({ patterns: presets.generic });
const r = await s.anonymize('Serveur 192.168.1.42 indisponible');
expect(r.anon).not.toContain('192.168.1.42');
expect(Object.values(r.mapping)).toContain('192.168.1.42');
});
it('accepts a fully custom pattern set', async () => {
const s = new Anonymizer({ patterns: [{ tag: 'TICKET', re: /\bJIRA-\d+\b/g }] });
const r = await s.anonymize('Voir JIRA-123');
expect(r.anon).toContain('[TICKET_1]');
expect(r.mapping['[TICKET_1]']).toBe('JIRA-123');
});
});
describe('legend', () => {
it('the regex fallback produces a French legend from tag meanings', async () => {
const s = new Anonymizer({ patterns: presets.swiss });
const r = await s.anonymize('Écris à jean@exemple.ch');
expect(r.legend).toEqual({ EMAIL: 'Adresse e-mail' });
});
it('backfills a missing legend entry from the built-in default (LLM omitted it)', async () => {
const anonymize = vi.fn().mockResolvedValue({
anon: 'Dossier de [PER_1.NOM:M]',
mapping: { '[PER_1.NOM:M]': 'Alain Jaccard' },
legend: {}, // model returned no legend
});
const s = new Anonymizer({ llm: failingLlm({ anonymize }), patterns: presets.swiss });
const r = await s.anonymize('Dossier de Alain Jaccard');
expect(r.legend).toEqual({ PER: 'Personne', NOM: 'Nom de famille', M: 'Masculin' });
});
it('a custom tag with a meaning surfaces it in the legend', async () => {
const s = new Anonymizer({
patterns: [{ tag: 'TICKET', re: /\bJIRA-\d+\b/g, meaning: 'Ticket de suivi' }],
});
const r = await s.anonymize('Voir JIRA-123');
expect(r.legend).toEqual({ TICKET: 'Ticket de suivi' });
});
});
describe('fail-closed (optional fallback)', () => {
it('throws if neither an LLM nor patterns are provided', () => {
expect(() => new Anonymizer({})).toThrowError(AnonymizationError);
});
it('LLM-only: a provider failure throws AnonymizationError with the cause', async () => {
const cause = new Error('LLM_HTTP_500');
const s = new Anonymizer({ llm: failingLlm({ anonymize: vi.fn().mockRejectedValue(cause) }) });
await expect(s.anonymize('Contact: jean@exemple.ch')).rejects.toBeInstanceOf(AnonymizationError);
await expect(s.anonymize('Contact: jean@exemple.ch')).rejects.toMatchObject({ cause });
});
it('LLM-only: bypasses the pre-filter so PII-free text still hits the provider', async () => {
const anonymize = vi.fn().mockResolvedValue({ anon: 'INNER JOIN', mapping: {}, legend: {} });
const s = new Anonymizer({ llm: failingLlm({ anonymize }) });
await s.anonymize('Explique INNER JOIN'); // no structured PII, no name hint
expect(anonymize).toHaveBeenCalledTimes(1);
});
it('LLM-only: anonymizeChunks rejects with AnonymizationError on provider failure', async () => {
const s = new Anonymizer({ llm: failingLlm() }); // anonymizeBatch rejects
await expect(s.anonymizeChunks(['Bob Martin a signé.'], { mapping: {} })).rejects.toBeInstanceOf(
AnonymizationError,
);
});
});
});
describe('multi-turn conversation (anonymizeTurn)', () => {
it('keeps stable ids across turns and accumulates the session', async () => {
const anonymizeInConversation = vi
.fn()
.mockResolvedValueOnce({
anon: 'Je suis [PER_1.NOM:F]',
mapping: { '[PER_1.NOM:F]': 'Nora Steiner' },
legend: { PER: 'Personne', NOM: 'Nom de famille', F: 'Féminin' },
})
.mockResolvedValueOnce({
anon: 'Ma collègue [PER_2.NOM:F] a aussi un souci',
mapping: { '[PER_2.NOM:F]': 'Yanis Berger' },
legend: { PER: 'Personne', NOM: 'Nom de famille', F: 'Féminin' },
});
const llm = failingLlm({ anonymizeInConversation });
const a = new Anonymizer({ llm });
const t1 = await a.anonymizeTurn('Je suis Nora Steiner');
expect(t1.mapping).toEqual({ '[PER_1.NOM:F]': 'Nora Steiner' });
const t2 = await a.anonymizeTurn('Ma collègue Yanis Berger a aussi un souci', t1.session);
expect(t2.mapping['[PER_1.NOM:F]']).toBe('Nora Steiner'); // stable across turns
expect(t2.mapping['[PER_2.NOM:F]']).toBe('Yanis Berger'); // new person, no collision
expect(t2.session.history).toHaveLength(2);
// the second call was told PER_1 is already used
expect(anonymizeInConversation.mock.calls[1][1].usedIds).toContain('[PER_1.NOM:F]');
});
it('conversation() wrapper threads the session and de-anonymizes', async () => {
const anonymizeInConversation = vi
.fn()
.mockResolvedValueOnce({
anon: '[PER_1.PRENOM:M]',
mapping: { '[PER_1.PRENOM:M]': 'Idris' },
legend: {},
})
.mockResolvedValueOnce({
anon: '[PER_1.PRENOM:M] et [PER_2.PRENOM:F]',
mapping: { '[PER_2.PRENOM:F]': 'Lina' },
legend: {},
});
const conv = new Anonymizer({ llm: failingLlm({ anonymizeInConversation }) }).conversation();
await conv.anonymize('Idris');
await conv.anonymize('Idris et Lina');
expect(conv.session().mapping).toEqual({ '[PER_1.PRENOM:M]': 'Idris', '[PER_2.PRENOM:F]': 'Lina' });
expect(conv.deanonymize('[PER_1.PRENOM:M]')).toBe('Idris');
});
it('falls back to the batch path when the provider has no anonymizeInConversation', async () => {
const anonymizeBatch = vi.fn().mockResolvedValue({
segments: ['[PER_1.NOM:M]'],
mapping: { '[PER_1.NOM:M]': 'Bruno Keller' },
legend: {},
});
const a = new Anonymizer({ llm: failingLlm({ anonymizeBatch }) });
const t = await a.anonymizeTurn('Bruno Keller');
expect(anonymizeBatch).toHaveBeenCalledWith(['Bruno Keller'], []);
expect(t.mapping['[PER_1.NOM:M]']).toBe('Bruno Keller');
});
it('realistic e-learning chat: stable coreference + attribute attribution + round-trips', async () => {
const turns = [
{
text: "Bonjour, je suis Nora Steiner, inscrite à la formation « Assistante médicale ». Je n'ai pas reçu ma convocation.",
anon: "Bonjour, je suis [PER_1.PRENOM:F] [PER_1.NOM:F], inscrite à la formation « Assistante médicale ». Je n'ai pas reçu ma convocation.",
mapping: { '[PER_1.PRENOM:F]': 'Nora', '[PER_1.NOM:F]': 'Steiner' },
},
{
text: 'Mon e-mail est nora.steiner@hotmail.ch et mon numéro AVS 756.2233.4455.66 au cas où.',
anon: 'Mon e-mail est [PER_1.EMAIL:F] et mon numéro AVS [PER_1.AVS:F] au cas où.',
mapping: { '[PER_1.EMAIL:F]': 'nora.steiner@hotmail.ch', '[PER_1.AVS:F]': '756.2233.4455.66' },
},
{
text: "En fait c'est aussi pour ma collègue Yanis Berger — elle veut s'inscrire, son tél. 078 111 22 33.",
anon: "En fait c'est aussi pour ma collègue [PER_2.PRENOM:F] [PER_2.NOM:F] — elle veut s'inscrire, son tél. [PER_2.TELEPHONE:F].",
mapping: {
'[PER_2.PRENOM:F]': 'Yanis',
'[PER_2.NOM:F]': 'Berger',
'[PER_2.TELEPHONE:F]': '078 111 22 33',
},
},
{
text: 'Le paiement se fera depuis mon IBAN CH88 0900 0000 1234 5678 9. Merci !',
anon: 'Le paiement se fera depuis mon IBAN [PER_1.IBAN:F]. Merci !',
mapping: { '[PER_1.IBAN:F]': 'CH88 0900 0000 1234 5678 9' },
},
];
const anonymizeInConversation = vi.fn();
for (const t of turns) {
anonymizeInConversation.mockResolvedValueOnce({ anon: t.anon, mapping: t.mapping, legend: {} });
}
const a = new Anonymizer({ llm: failingLlm({ anonymizeInConversation }) });
let session: AnonymizerSession = { mapping: {}, legend: {}, history: [] };
for (const t of turns) {
const r = await a.anonymizeTurn(t.text, session);
session = r.session;
// each turn restores to the exact original
expect(a.deanonymize(r.anon, r.mapping)).toBe(t.text);
}
// Nora = PER_1 throughout (name + email + AVS + IBAN attached to her); Yanis = PER_2.
expect(session.mapping['[PER_1.PRENOM:F]']).toBe('Nora');
expect(session.mapping['[PER_1.EMAIL:F]']).toBe('nora.steiner@hotmail.ch');
expect(session.mapping['[PER_1.IBAN:F]']).toBe('CH88 0900 0000 1234 5678 9');
expect(session.mapping['[PER_2.PRENOM:F]']).toBe('Yanis');
expect(session.mapping['[PER_2.TELEPHONE:F]']).toBe('078 111 22 33');
expect(session.history).toHaveLength(4);
});
});