fix: error-only Sentry telemetry, storm-proof capture, and crash fixes (#476)

Removes Sentry tracing entirely (BullMQ idle polling burned 4.8M transactions in 2 days at the baked 0.1 rate), decouples PostHog sampling, and replaces the type-only error scrub with a vetted-field sanitizer plus SafeError/ToolInputError contracts. One classified capture path with per-signature throttles and a per-process ceiling makes storms impossible (NODE-1E was 4,541 events from one 30s loop). Browser errors move to a dedicated web Sentry project with their own source maps. Adds the SNAPOTTER_TELEMETRY runtime kill switch and silences test fleets.

Crash fixes: remote 204/304 SSRF process kill (NODE-20), conversion-preset boot crash loop (NODE-21), Redis version preflight + unhandled subscribe rejection (NODE-1T), Sign PDF on plain-http origins (NODE-1K/1M), wavesurfer/pdf.js teardown rejections (NODE-1P/1N), bundle-import ZlibError to 400 (NODE-1Z), chart-maker input errors declassified (NODE-1H/1J), asset requests skip the session DB lookup (NODE-1D).
This commit is contained in:
SnapOtter
2026-07-10 21:41:49 +08:00
committed by GitHub
parent 3d1744aec8
commit ae6a4c8b7c
75 changed files with 2198 additions and 260 deletions
+7 -5
View File
@@ -17,13 +17,14 @@ const posthogApiKey = on
? (process.env.SNAPOTTER_POSTHOG_PROJECT_ID ?? process.env.SNAPOTTER_POSTHOG_KEY ?? "")
: "";
const sentryDsn = on ? (process.env.SNAPOTTER_SENTRY_DSN ?? "") : "";
const sentryDsnWeb = on ? (process.env.SNAPOTTER_SENTRY_DSN_WEB ?? "") : "";
const posthogHost = posthogApiKey ? "https://us.i.posthog.com" : "";
// Enabled only when turned on AND there is somewhere to report to, so a
// credential-less source build never initializes the SDKs.
const enabled = on && (posthogApiKey !== "" || sentryDsn !== "");
// tracesSampleRate only governs performance transactions; errors are always
// captured. Keep low so fleet-wide tracing does not drain Sentry quota.
const sampleRate = sentryDsn ? 0.1 : 0;
const enabled = on && (posthogApiKey !== "" || sentryDsn !== "" || sentryDsnWeb !== "");
// PostHog event sampling only. Sentry tracing was removed in 2.0.1; do not
// reintroduce a shared "sampleRate" that doubles as a traces rate.
const posthogSampleRate = on ? 0.1 : 0;
const content = `// AUTO-GENERATED by scripts/bake-analytics.mjs -- do not edit manually
export const ANALYTICS_BAKED = {
@@ -31,7 +32,8 @@ export const ANALYTICS_BAKED = {
posthogApiKey: "${posthogApiKey}",
posthogHost: "${posthogHost}",
sentryDsn: "${sentryDsn}",
sampleRate: ${sampleRate},
sentryDsnWeb: "${sentryDsnWeb}",
posthogSampleRate: ${posthogSampleRate},
} as const;
`;