The data masking utility can encrypt, decrypt, or irreversibly erase sensitive information to protect data confidentiality.
Powertools for AWS Lambda (TypeScript) is a developer toolkit to implement Serverless best practices and increase developer velocity. You can use the library in both TypeScript and JavaScript code bases.
To get started, install the package by running:
npm i @aws-lambda-powertools/data-masking
Erasing will remove the original data and replace it with *****. This means you cannot recover erased data, and the data type will change to string for all erased values.
Field paths support dot notation and .*/[*] wildcards to reach nested data.
import { DataMasking } from '@aws-lambda-powertools/data-masking';
const masker = new DataMasking();
const data = {
name: 'Jane Doe',
customer: { ssn: '123-45-6789', city: 'Anytown' },
orders: [{ id: 1, card: '4111-1111-1111-1111' }],
};
const masked = masker.erase(data, {
fields: ['customer.ssn', 'orders[*].card'],
});
// {
// name: 'Jane Doe',
// customer: { ssn: '*****', city: 'Anytown' },
// orders: [{ id: 1, card: '*****' }],
// }
You can also use custom masking rules to partially mask data while keeping some of its structure, for example to preserve the domain of an email address or the length of a value:
import { DataMasking } from '@aws-lambda-powertools/data-masking';
const masker = new DataMasking();
const masked = masker.erase(
{ email: 'jane@example.com', ssn: '123-45-6789' },
{
maskingRules: {
email: { regexPattern: /^(.)([^@]*)(@.*)$/, maskFormat: '$1****$3' },
ssn: { dynamicMask: true },
},
}
);
// { email: 'j****@example.com', ssn: '***********' }
To encrypt and decrypt data, you need an encryption provider. By default, we use Amazon Key Management Service (KMS) via the AWS Encryption SDK provider, which is available as its own sub-path export so the @aws-crypto/client-node peer dependency is only required when you use it:
npm i @aws-crypto/client-node
import { DataMasking } from '@aws-lambda-powertools/data-masking';
import { AWSEncryptionSDKProvider } from '@aws-lambda-powertools/data-masking/providers/kms';
const masker = new DataMasking({
provider: new AWSEncryptionSDKProvider({
keys: ['arn:aws:kms:us-east-1:123456789012:key/my-key'],
}),
});
const encrypted = await masker.encrypt(data, {
fields: ['customer.ssn'],
});
const decrypted = await masker.decrypt(encrypted, {
fields: ['customer.ssn'],
});
For more information on how to use this utility, please refer to the documentation.
If you are interested in contributing to this project, please refer to our Contributing Guidelines.
The roadmap of Powertools for AWS Lambda (TypeScript) is driven by customers’ demand.
Help us prioritize upcoming functionalities or utilities by upvoting existing RFCs and feature requests, or creating new ones, in this GitHub repository.
#typescript - Invite linkKnowing which companies are using this library is important to help prioritize the project internally. If your company is using Powertools for AWS Lambda (TypeScript), you can request to have your name and logo added to the README file by raising a Support Powertools for AWS Lambda (TypeScript) (become a reference) issue.
The following companies, among others, use Powertools:
Share what you did with Powertools for AWS Lambda (TypeScript) 💞💞. Blog post, workshops, presentation, sample apps and others. Check out what the community has already shared about Powertools for AWS Lambda (TypeScript).
This helps us understand who uses Powertools for AWS Lambda (TypeScript) in a non-intrusive way, and helps us gain future investments for other Powertools for AWS Lambda languages. When using Layers, you can add Powertools as a dev dependency to not impact the development process.
This library is licensed under the MIT-0 License. See the LICENSE file.