mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix: error-only Sentry telemetry, storm-proof capture, and crash fixes (#476)
Removes Sentry tracing entirely (BullMQ idle polling burned 4.8M transactions in 2 days at the baked 0.1 rate), decouples PostHog sampling, and replaces the type-only error scrub with a vetted-field sanitizer plus SafeError/ToolInputError contracts. One classified capture path with per-signature throttles and a per-process ceiling makes storms impossible (NODE-1E was 4,541 events from one 30s loop). Browser errors move to a dedicated web Sentry project with their own source maps. Adds the SNAPOTTER_TELEMETRY runtime kill switch and silences test fleets. Crash fixes: remote 204/304 SSRF process kill (NODE-20), conversion-preset boot crash loop (NODE-21), Redis version preflight + unhandled subscribe rejection (NODE-1T), Sign PDF on plain-http origins (NODE-1K/1M), wavesurfer/pdf.js teardown rejections (NODE-1P/1N), bundle-import ZlibError to 400 (NODE-1Z), chart-maker input errors declassified (NODE-1H/1J), asset requests skip the session DB lookup (NODE-1D).
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { isStaticAssetRequest } from "../../../apps/api/src/plugins/auth.js";
|
||||
|
||||
describe("isStaticAssetRequest", () => {
|
||||
it("matches GET/HEAD under /assets/ only", () => {
|
||||
expect(isStaticAssetRequest("GET", "/assets/react-D3OgQKsK.js")).toBe(true);
|
||||
expect(isStaticAssetRequest("HEAD", "/assets/x.css")).toBe(true);
|
||||
expect(isStaticAssetRequest("GET", "/api/v1/settings")).toBe(false);
|
||||
expect(isStaticAssetRequest("POST", "/assets/x.js")).toBe(false);
|
||||
expect(isStaticAssetRequest("GET", "/assetsish")).toBe(false);
|
||||
expect(isStaticAssetRequest("GET", "/assets/../api/v1/settings")).toBe(false);
|
||||
expect(isStaticAssetRequest("GET", "/assets/x.js?v=abc")).toBe(true);
|
||||
expect(isStaticAssetRequest("GET", "/assets")).toBe(false);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user