mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
feat: pipeline templates, analytics opt-out, 83 conversion presets, positioning + e2e modernization
Lands five integrated branches: pipeline templates (#355), analytics opt-out (#354), 83 conversion presets bringing the catalog to 240 tools (#356), self-hosted positioning (#353), and e2e modernization (#351). Integration fixes: aligned stale web analytics tests with the opt-out/allow-list model, closed 3 CodeQL incomplete-sanitization alerts in the i18n generator, resolved settings/index/docs/format-matrix conflicts, and corrected tool counts to 240.
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
// Defense in depth: only these keys may leave the server per event, and only as
|
||||
// primitives. Free-text fields (error_message, params, search query) are never
|
||||
// allow-listed, so tool settings and filenames cannot reach PostHog.
|
||||
const ALLOWED: Record<string, ReadonlySet<string>> = {
|
||||
tool_used: new Set(["tool_id", "status", "duration_ms", "category", "is_ai_tool", "error_code"]),
|
||||
pipeline_executed: new Set([
|
||||
"step_count",
|
||||
"tool_ids",
|
||||
"is_batch",
|
||||
"file_count",
|
||||
"duration_ms",
|
||||
"status",
|
||||
]),
|
||||
ai_bundle_action: new Set(["bundle_id", "action", "duration_ms"]),
|
||||
};
|
||||
|
||||
function isAllowedValue(value: unknown): boolean {
|
||||
if (value === null) return false;
|
||||
const t = typeof value;
|
||||
if (t === "string" || t === "number" || t === "boolean") return true;
|
||||
// tool_ids is an array of strings (low-cardinality ids); allow that one shape.
|
||||
return Array.isArray(value) && value.every((v) => typeof v === "string");
|
||||
}
|
||||
|
||||
export function sanitizeEventProperties(
|
||||
event: string,
|
||||
properties: Record<string, unknown>,
|
||||
): Record<string, unknown> {
|
||||
const allow = ALLOWED[event];
|
||||
if (!allow) return {};
|
||||
const out: Record<string, unknown> = {};
|
||||
for (const [key, value] of Object.entries(properties)) {
|
||||
if (allow.has(key) && isAllowedValue(value)) out[key] = value;
|
||||
}
|
||||
return out;
|
||||
}
|
||||
Reference in New Issue
Block a user