Files
SnapOtter/tests/unit/api/analytics-allowlist.test.ts
T
SnapOtterandGitHub e1b8c24e5d feat(analytics): instance census, full capture, richer error context (#511)
Add a once-per-boot instance_started event (arch, os, deploy_mode,
gpu_present) so the fleet architecture mix is measurable. It reuses the
existing per-instance instance_id and is exempt from the volume sample
rate, since a census that fires once per boot must not be thinned.

Restore useful capture depth now that the sponsored plan removes the
quota pressure behind the earlier hardening:

- PostHog sample rate 0.1 to 1.0 (full analytics when enabled); the
  property allowlist still blocks file data.
- Sentry per-instance ceiling 20 to 500/hr, breadcrumb trail restored
  (sanitized: urls/paths redacted, data payloads dropped), full stack
  paths kept; local vars, request bodies, and PII still dropped. Both
  api and web.

Honor ANALYTICS_ENABLED=false as an opt-out alias: it was documented on
the Docker Hub README but never wired in 2.x, so anyone who set it was
still tracked.

All capture stays behind the analytics opt-out gate.
2026-07-13 14:23:16 +08:00

57 lines
1.7 KiB
TypeScript

import { describe, expect, it } from "vitest";
import { sanitizeEventProperties } from "../../../apps/api/src/lib/analytics-allowlist.js";
describe("sanitizeEventProperties", () => {
it("keeps only allow-listed keys for tool_used", () => {
const out = sanitizeEventProperties("tool_used", {
tool_id: "resize",
status: "completed",
duration_ms: 12,
category: "image",
is_ai_tool: false,
error_message: "stack with /uploads/secret.docx",
params: { watermark_text: "CONFIDENTIAL" },
});
expect(out).toEqual({
tool_id: "resize",
status: "completed",
duration_ms: 12,
category: "image",
is_ai_tool: false,
});
expect(out).not.toHaveProperty("error_message");
expect(out).not.toHaveProperty("params");
});
it("drops non-primitive values", () => {
const out = sanitizeEventProperties("ai_bundle_action", {
bundle_id: "ocr",
action: "installed",
duration_ms: { nested: 1 } as unknown as number,
});
expect(out).toEqual({ bundle_id: "ocr", action: "installed" });
});
it("returns no properties for an unknown event", () => {
const out = sanitizeEventProperties("totally_new_event", { anything: "x" });
expect(out).toEqual({});
});
it("keeps only allow-listed keys for instance_started", () => {
const out = sanitizeEventProperties("instance_started", {
arch: "arm64",
os_platform: "linux",
deploy_mode: "embedded",
gpu_present: false,
hostname: "leaked-hostname",
});
expect(out).toEqual({
arch: "arm64",
os_platform: "linux",
deploy_mode: "embedded",
gpu_present: false,
});
expect(out).not.toHaveProperty("hostname");
});
});