mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
Comprehensive telemetry quality improvements across Sentry and PostHog, grounded in an audit of the live data plus current best-practice research. Sentry: job_id/instance_id tags, operational fingerprinting, PII-safe settings context on bug events, web tag population + extension-noise filtering, an early-crash buffer, http status/method kept on breadcrumbs, and a gated-off-by-default performance-tracing re-enable (tracesSampler that zeroes db/redis/queue-poll root spans + drops the Redis integration) with worker job spans and canonical-host cron monitors. PostHog: history_change SPA pageviews, instance_id super property for fleet rollups, enriched tool_used (formats, byte sizes, is_batch, execution_hint, real error_kind taxonomy), the previously-dead result_saved/batch_processed/ai_bundle_prompted events fired, search click-through, editor + Automate authoring + auth instrumentation, a before_send PII boundary, and minimal opt-in landing-site pageviews.
54 lines
1.6 KiB
TypeScript
54 lines
1.6 KiB
TypeScript
// Defense in depth: only these keys may leave the server per event, and only as
|
|
// primitives. Free-text fields (error_message, params, search query) are never
|
|
// allow-listed, so tool settings and filenames cannot reach PostHog.
|
|
const ALLOWED: Record<string, ReadonlySet<string>> = {
|
|
tool_used: new Set([
|
|
"tool_id",
|
|
"status",
|
|
"duration_ms",
|
|
"category",
|
|
"is_ai_tool",
|
|
"is_batch",
|
|
"input_format",
|
|
"output_format",
|
|
"bytes_in",
|
|
"bytes_out",
|
|
"execution_hint",
|
|
"error_code",
|
|
"error_kind",
|
|
]),
|
|
pipeline_executed: new Set([
|
|
"step_count",
|
|
"tool_ids",
|
|
"is_batch",
|
|
"file_count",
|
|
"duration_ms",
|
|
"status",
|
|
]),
|
|
ai_bundle_action: new Set(["bundle_id", "action", "duration_ms"]),
|
|
instance_started: new Set(["arch", "os_platform", "deploy_mode", "gpu_present"]),
|
|
auth_login: new Set(["method"]),
|
|
auth_login_failed: new Set(["method"]),
|
|
};
|
|
|
|
function isAllowedValue(value: unknown): boolean {
|
|
if (value === null) return false;
|
|
const t = typeof value;
|
|
if (t === "string" || t === "number" || t === "boolean") return true;
|
|
// tool_ids is an array of strings (low-cardinality ids); allow that one shape.
|
|
return Array.isArray(value) && value.every((v) => typeof v === "string");
|
|
}
|
|
|
|
export function sanitizeEventProperties(
|
|
event: string,
|
|
properties: Record<string, unknown>,
|
|
): Record<string, unknown> {
|
|
const allow = ALLOWED[event];
|
|
if (!allow) return {};
|
|
const out: Record<string, unknown> = {};
|
|
for (const [key, value] of Object.entries(properties)) {
|
|
if (allow.has(key) && isAllowedValue(value)) out[key] = value;
|
|
}
|
|
return out;
|
|
}
|