File size: 10,978 Bytes
56257d2
b580df0
 
56257d2
 
3177659
56257d2
 
3177659
56257d2
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
e4347be
56257d2
 
e4347be
 
56257d2
 
 
 
 
 
e4347be
 
 
 
fe47b4f
 
 
 
e4347be
 
 
56257d2
 
 
 
3177659
 
 
 
56257d2
 
 
 
 
 
 
3177659
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
56257d2
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
b580df0
 
a439670
 
56257d2
b580df0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
import sys
import os
sys.path.insert(0, os.path.abspath(os.path.join(os.path.dirname(__file__), '..')))

import uvicorn
from fastapi import FastAPI, HTTPException, Request
from fastapi.responses import HTMLResponse
from pydantic import BaseModel
from typing import Optional
from env.core import GDPRAuditorEnvironment
from models import Action as ActionModel

app = FastAPI(title="GDPR Auditor")
env = GDPRAuditorEnvironment()

HTML_CONTENT = """
<!DOCTYPE html>
<html>
<head>
    <title>GDPR Compliance Auditor</title>
    <meta name="description" content="OpenEnv environment for AI-powered GDPR compliance auditing">
    <style>
        * { box-sizing: border-box; margin: 0; padding: 0; }
        body {
            font-family: 'Segoe UI', system-ui, -apple-system, sans-serif;
            background: linear-gradient(135deg, #0f0c29, #302b63, #24243e);
            color: #e0e0e0;
            min-height: 100vh;
            padding: 30px;
        }
        .container { max-width: 960px; margin: 0 auto; }
        h1 {
            font-size: 2rem;
            background: linear-gradient(90deg, #7f5af0, #2cb67d);
            -webkit-background-clip: text;
            -webkit-text-fill-color: transparent;
            margin-bottom: 8px;
        }
        .subtitle { color: #94a1b2; margin-bottom: 24px; font-size: 0.95rem; }
        .card {
            background: rgba(255,255,255,0.05);
            backdrop-filter: blur(12px);
            border: 1px solid rgba(255,255,255,0.08);
            border-radius: 12px;
            padding: 20px;
            margin-bottom: 16px;
        }
        .card h3 { color: #fffffe; margin-bottom: 12px; font-size: 1rem; }
        select, textarea {
            width: 100%;
            background: rgba(255,255,255,0.06);
            border: 1px solid rgba(255,255,255,0.12);
            border-radius: 8px;
            color: #fffffe;
            padding: 10px 14px;
            font-family: inherit;
            font-size: 0.9rem;
            outline: none;
            transition: border-color 0.2s;
        }
        select:focus, textarea:focus { border-color: #7f5af0; }
        textarea { height: 120px; resize: vertical; margin-bottom: 12px; }
        .btn {
            background: linear-gradient(135deg, #7f5af0, #6246d8);
            color: #fffffe;
            border: none;
            padding: 10px 24px;
            border-radius: 8px;
            cursor: pointer;
            font-weight: 600;
            font-size: 0.9rem;
            transition: transform 0.15s, box-shadow 0.15s;
            margin-top: 10px;
        }
        .btn:hover { transform: translateY(-1px); box-shadow: 0 4px 20px rgba(127,90,240,0.35); }
        .btn:active { transform: translateY(0); }
        #output {
            background: rgba(0,0,0,0.4);
            color: #2cb67d;
            padding: 16px;
            border-radius: 8px;
            white-space: pre-wrap;
            font-family: 'Cascadia Code', 'Fira Code', monospace;
            font-size: 0.85rem;
            max-height: 420px;
            overflow-y: auto;
            line-height: 1.5;
        }
        .row { display: flex; gap: 10px; align-items: center; }
        .row select { flex: 1; }
        .badge {
            display: inline-block;
            padding: 2px 8px;
            border-radius: 4px;
            font-size: 0.75rem;
            font-weight: 600;
        }
        .badge-easy { background: #2cb67d33; color: #2cb67d; }
        .badge-medium { background: #e1a94033; color: #e1a940; }
        .badge-hard { background: #e0463633; color: #e04636; }
        .badge-elite { background: #7f5af033; color: #7f5af0; }
    </style>
</head>
<body>
    <div class="container">
        <h1>πŸ”’ GDPR Compliance Auditor</h1>
        <p class="subtitle">OpenEnv environment β€” Audit privacy policies for GDPR/CCPA compliance violations</p>

        <div class="card">
            <h3>Reset Environment</h3>
            <div class="row">
                <select id="task">
                    <option value="easy">Easy β€” Clause Existence Check</option>
                    <option value="medium">Medium β€” Purpose Mapping</option>
                    <option value="hard">Hard β€” Dark Pattern Detection</option>
                    <option value="elite">Elite β€” Multi-Document Reasoning</option>
                </select>
                <button class="btn" onclick="resetEnv()">Reset</button>
            </div>
        </div>

        <div class="card">
            <h3>Submit Finding</h3>
            <textarea id="action" placeholder="Describe your compliance finding...&#10;Examples:&#10;- Missing Right to be Forgotten clause&#10;- Health data shared with advertisers&#10;- Policy contradicts cookie section"></textarea>
            <button class="btn" onclick="submitStep()">Submit Finding</button>
        </div>

        <div class="card">
            <h3>Output</h3>
            <div id="output">Select a task and click Reset to begin...</div>
        </div>
    </div>

    <script>
        async function resetEnv() {
            const task = document.getElementById('task').value;
            try {
                const res = await fetch('/reset?task=' + task);
                const data = await res.json();
                const obs = data.observation;
                let output = '=== Task: ' + obs.task_name + ' ===\\n';
                output += 'Difficulty: ' + obs.difficulty + '\\n\\n';
                output += '--- PRIVACY POLICY ---\\n';
                if (obs.documents && obs.documents.length > 0) {
                    output += obs.documents[0].content + '\\n\\n';
                }
                output += '--- DATA PRACTICES ---\\n';
                if (obs.data_practices) {
                    obs.data_practices.forEach((dp, i) => {
                        output += (i+1) + '. ' + dp.category + ': ' + dp.purpose + ' (shared: ' + dp.shared_with_third_parties + ')\\n';
                    });
                }
                output += '\\n--- COMPLIANCE REQUIREMENTS ---\\n';
                if (obs.compliance_requirements) {
                    obs.compliance_requirements.forEach(req => {
                        output += '- ' + req + '\\n';
                    });
                }
                document.getElementById('output').textContent = output;
            } catch (e) {
                document.getElementById('output').textContent = 'Error: ' + e.message;
            }
        }

        async function submitStep() {
            const action = document.getElementById('action').value;
            if (!action.trim()) return;
            try {
                const res = await fetch('/step', {
                    method: 'POST',
                    headers: {'Content-Type': 'application/json'},
                    body: JSON.stringify({message: action})
                });
                const data = await res.json();
                let output = document.getElementById('output').textContent;
                output += '\\n\\n--- STEP ' + data.observation.step + ' ---\\n';
                output += 'Reward: ' + data.reward.value.toFixed(3) + '\\n';
                output += 'Reason: ' + data.reward.reason + '\\n';
                output += 'Issues Found: ' + data.reward.issues_found + '/' + data.reward.total_issues + '\\n';
                output += 'Done: ' + data.done + '\\n';
                document.getElementById('output').textContent = output;
                document.getElementById('action').value = '';
            } catch (e) {
                document.getElementById('output').textContent += '\\nError: ' + e.message;
            }
        }
    </script>
</body>
</html>
"""


@app.get("/", response_class=HTMLResponse)
async def root():
    """Serve the interactive web UI."""
    return HTML_CONTENT


@app.get("/json")
async def api_info():
    """API information and available endpoints."""
    return {
        "name": "GDPR Compliance Auditor",
        "version": "1.0.0",
        "description": "OpenEnv environment for AI-powered GDPR/CCPA compliance auditing",
        "tasks": ["easy_clause_existence", "medium_purpose_mapping", "hard_dark_patterns", "elite_multi_doc_reasoning"],
        "endpoints": {
            "health": "GET /health",
            "tasks": "GET /tasks",
            "reset": "GET /reset?task=<task_id>  or  POST /reset {task: <task_id>}",
            "step": "POST /step {message: string}",
            "state": "GET /state",
        },
    }


@app.get("/tasks")
async def list_tasks():
    """Enumerate all available tasks (as declared in openenv.yaml)."""
    return [
        {"id": "easy_clause_existence",    "name": "Clause Existence Check",    "difficulty": "easy",   "max_steps": 8, "reward_range": [0.001, 0.999]},
        {"id": "medium_purpose_mapping",   "name": "Purpose Mapping",           "difficulty": "medium", "max_steps": 8, "reward_range": [0.001, 0.999]},
        {"id": "hard_dark_patterns",       "name": "Dark Pattern Detection",     "difficulty": "hard",   "max_steps": 8, "reward_range": [0.001, 0.999]},
        {"id": "elite_multi_doc_reasoning","name": "Multi-Document Reasoning",  "difficulty": "elite",  "max_steps": 8, "reward_range": [0.001, 0.999]},
    ]


class ActionRequest(BaseModel):
    message: str


class ResetRequest(BaseModel):
    task: Optional[str] = "easy"


@app.get("/health")
async def health():
    """Health check endpoint."""
    return {"status": "ok"}


@app.get("/reset")
async def reset_get(task: str = "easy"):
    """Reset the environment for a given task (GET)."""
    try:
        obs = env.reset(task_id=task)
        return {"observation": obs.model_dump(), "done": False}
    except Exception as e:
        raise HTTPException(status_code=500, detail=str(e))


@app.post("/reset")
async def reset_post(request: Request):
    """Reset the environment for a given task (POST)."""
    try:
        body = await request.json()
        task = body.get("task", "easy") if body else "easy"
    except Exception:
        task = "easy"
    try:
        obs = env.reset(task_id=task)
        return {"observation": obs.model_dump(), "done": False}
    except Exception as e:
        raise HTTPException(status_code=500, detail=str(e))


@app.post("/step")
async def step(action: ActionRequest):
    """Submit an action (compliance finding) to the environment."""
    try:
        action_obj = ActionModel(message=action.message)
        obs, reward, done, info = env.step(action_obj)

        return {
            "observation": obs.model_dump(),
            "reward": reward.model_dump(),
            "done": done,
            "info": info,
        }
    except Exception as e:
        raise HTTPException(status_code=500, detail=str(e))


@app.get("/state")
async def state():
    """Get the current environment state."""
    return env.state()


def main():
    uvicorn.run("server.app:app", host="0.0.0.0", port=7860)


if __name__ == "__main__":
    main()