mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix: error-only Sentry telemetry, storm-proof capture, and crash fixes (#476)
Removes Sentry tracing entirely (BullMQ idle polling burned 4.8M transactions in 2 days at the baked 0.1 rate), decouples PostHog sampling, and replaces the type-only error scrub with a vetted-field sanitizer plus SafeError/ToolInputError contracts. One classified capture path with per-signature throttles and a per-process ceiling makes storms impossible (NODE-1E was 4,541 events from one 30s loop). Browser errors move to a dedicated web Sentry project with their own source maps. Adds the SNAPOTTER_TELEMETRY runtime kill switch and silences test fleets. Crash fixes: remote 204/304 SSRF process kill (NODE-20), conversion-preset boot crash loop (NODE-21), Redis version preflight + unhandled subscribe rejection (NODE-1T), Sign PDF on plain-http origins (NODE-1K/1M), wavesurfer/pdf.js teardown rejections (NODE-1P/1N), bundle-import ZlibError to 400 (NODE-1Z), chart-maker input errors declassified (NODE-1H/1J), asset requests skip the session DB lookup (NODE-1D).
This commit is contained in:
@@ -1100,8 +1100,19 @@ function isPublicRoute(url: string): boolean {
|
||||
return PUBLIC_PATHS.some((path) => url.startsWith(path));
|
||||
}
|
||||
|
||||
/** SPA bundle assets are public by definition (the login page needs them). */
|
||||
export function isStaticAssetRequest(method: string, url: string): boolean {
|
||||
return (
|
||||
(method === "GET" || method === "HEAD") && url.startsWith("/assets/") && !url.includes("..")
|
||||
);
|
||||
}
|
||||
|
||||
export async function authMiddleware(app: FastifyInstance): Promise<void> {
|
||||
app.addHook("preHandler", async (request: FastifyRequest, reply: FastifyReply) => {
|
||||
// Skip the session DB lookup for bundle assets: they are served on every
|
||||
// page load and an unreachable DB must not 500 them (Sentry NODE-1D).
|
||||
if (isStaticAssetRequest(request.method, request.url)) return;
|
||||
|
||||
if (!env.AUTH_ENABLED) {
|
||||
(request as FastifyRequest & { user?: AuthUser }).user = {
|
||||
id: "anonymous",
|
||||
|
||||
Reference in New Issue
Block a user