Files
SnapOtterandGitHub ae6a4c8b7c fix: error-only Sentry telemetry, storm-proof capture, and crash fixes (#476)
Removes Sentry tracing entirely (BullMQ idle polling burned 4.8M transactions in 2 days at the baked 0.1 rate), decouples PostHog sampling, and replaces the type-only error scrub with a vetted-field sanitizer plus SafeError/ToolInputError contracts. One classified capture path with per-signature throttles and a per-process ceiling makes storms impossible (NODE-1E was 4,541 events from one 30s loop). Browser errors move to a dedicated web Sentry project with their own source maps. Adds the SNAPOTTER_TELEMETRY runtime kill switch and silences test fleets.

Crash fixes: remote 204/304 SSRF process kill (NODE-20), conversion-preset boot crash loop (NODE-21), Redis version preflight + unhandled subscribe rejection (NODE-1T), Sign PDF on plain-http origins (NODE-1K/1M), wavesurfer/pdf.js teardown rejections (NODE-1P/1N), bundle-import ZlibError to 400 (NODE-1Z), chart-maker input errors declassified (NODE-1H/1J), asset requests skip the session DB lookup (NODE-1D).
2026-07-10 21:41:49 +08:00

53 lines
2.2 KiB
TypeScript

import { expect, test } from "./helpers";
// The /privacy page describes the opt-out analytics model (PR #336 removed the
// old consent/opt-in flow). These assertions track the live page copy; there is
// no consent page or banner to assert anymore.
test.describe("Privacy Policy Page", () => {
test("renders at /privacy", async ({ loggedInPage: page }) => {
await page.goto("/privacy");
await expect(page.getByRole("heading", { name: "Privacy Policy", level: 1 })).toBeVisible({
timeout: 5_000,
});
});
test("mentions PostHog as analytics provider", async ({ loggedInPage: page }) => {
await page.goto("/privacy");
// The page legitimately mentions PostHog more than once; first() avoids a
// strict-mode collision without weakening the presence assertion.
await expect(page.getByText(/posthog/i).first()).toBeVisible({ timeout: 5_000 });
});
test("mentions Sentry as error tracking provider", async ({ loggedInPage: page }) => {
await page.goto("/privacy");
await expect(page.getByText(/sentry/i)).toBeVisible({ timeout: 5_000 });
});
test("describes local processing", async ({ loggedInPage: page }) => {
await page.goto("/privacy");
await expect(page.getByRole("heading", { name: "Local Processing" })).toBeVisible({
timeout: 5_000,
});
await expect(page.getByText(/processing happens entirely on the server/i)).toBeVisible({
timeout: 5_000,
});
});
test("frames analytics as opt-out, not opt-in/consent", async ({ loggedInPage: page }) => {
await page.goto("/privacy");
// Analytics is on by default and can be turned off (the opt-out model).
await expect(page.getByRole("heading", { name: "Analytics" })).toBeVisible({ timeout: 5_000 });
await expect(page.getByText(/can be disabled/i)).toBeVisible({ timeout: 5_000 });
// No consent / opt-in wording should survive.
await expect(page.getByText(/opt.?in|consent|i agree|accept analytics/i)).toHaveCount(0);
});
test("no auth required to access privacy page", async ({ page }) => {
await page.goto("/privacy");
// Should NOT redirect to login.
await page.waitForTimeout(2000);
expect(page.url()).toContain("/privacy");
});
});