mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
PostHog SDK was initialized on app mount based only on the server-level config flag, ignoring user consent. This caused network requests to us-assets.i.posthog.com (config.js, web-vitals.js, dead-clicks-autocapture.js) even when the user had not opted in or had explicitly declined telemetry. - Replace static imports of posthog-js and @sentry/react with dynamic import() so the SDK bundles are not downloaded until consent is granted - Gate initAnalytics on analyticsConsent.analyticsEnabled === true, not just server config.enabled - Add consent re-check after each await import() to handle revocation during the async load - Add shutdownAnalytics() that calls opt_out_capturing() + reset() for mid-session consent revocation - setAnalyticsConsent(false) now triggers full SDK shutdown automatically - Rewrite analytics test suite with 44 tests covering init gating, shutdown lifecycle, consent toggle, race conditions, and Sentry callbacks Closes #98