mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
Removes Sentry tracing entirely (BullMQ idle polling burned 4.8M transactions in 2 days at the baked 0.1 rate), decouples PostHog sampling, and replaces the type-only error scrub with a vetted-field sanitizer plus SafeError/ToolInputError contracts. One classified capture path with per-signature throttles and a per-process ceiling makes storms impossible (NODE-1E was 4,541 events from one 30s loop). Browser errors move to a dedicated web Sentry project with their own source maps. Adds the SNAPOTTER_TELEMETRY runtime kill switch and silences test fleets. Crash fixes: remote 204/304 SSRF process kill (NODE-20), conversion-preset boot crash loop (NODE-21), Redis version preflight + unhandled subscribe rejection (NODE-1T), Sign PDF on plain-http origins (NODE-1K/1M), wavesurfer/pdf.js teardown rejections (NODE-1P/1N), bundle-import ZlibError to 400 (NODE-1Z), chart-maker input errors declassified (NODE-1H/1J), asset requests skip the session DB lookup (NODE-1D).
42 lines
1.9 KiB
JavaScript
42 lines
1.9 KiB
JavaScript
import { writeFileSync } from "node:fs";
|
|
import { dirname, resolve } from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
const __dirname = dirname(fileURLToPath(import.meta.url));
|
|
const outPath = resolve(__dirname, "../packages/shared/src/analytics/baked.ts");
|
|
|
|
const mode = process.argv[2] || "on";
|
|
|
|
const on = mode === "on";
|
|
// Real telemetry creds are injected at build time from the environment -- the
|
|
// official image's CI supplies them from secrets, so they are NOT committed and
|
|
// a build from source stays silent. A Sentry DSN and a PostHog project key are
|
|
// public (they ship in the browser bundle), so this is about not making forks /
|
|
// source builds phone home by default, not about secrecy.
|
|
const posthogApiKey = on
|
|
? (process.env.SNAPOTTER_POSTHOG_PROJECT_ID ?? process.env.SNAPOTTER_POSTHOG_KEY ?? "")
|
|
: "";
|
|
const sentryDsn = on ? (process.env.SNAPOTTER_SENTRY_DSN ?? "") : "";
|
|
const sentryDsnWeb = on ? (process.env.SNAPOTTER_SENTRY_DSN_WEB ?? "") : "";
|
|
const posthogHost = posthogApiKey ? "https://us.i.posthog.com" : "";
|
|
// Enabled only when turned on AND there is somewhere to report to, so a
|
|
// credential-less source build never initializes the SDKs.
|
|
const enabled = on && (posthogApiKey !== "" || sentryDsn !== "" || sentryDsnWeb !== "");
|
|
// PostHog event sampling only. Sentry tracing was removed in 2.0.1; do not
|
|
// reintroduce a shared "sampleRate" that doubles as a traces rate.
|
|
const posthogSampleRate = on ? 0.1 : 0;
|
|
|
|
const content = `// AUTO-GENERATED by scripts/bake-analytics.mjs -- do not edit manually
|
|
export const ANALYTICS_BAKED = {
|
|
enabled: ${enabled},
|
|
posthogApiKey: "${posthogApiKey}",
|
|
posthogHost: "${posthogHost}",
|
|
sentryDsn: "${sentryDsn}",
|
|
sentryDsnWeb: "${sentryDsnWeb}",
|
|
posthogSampleRate: ${posthogSampleRate},
|
|
} as const;
|
|
`;
|
|
|
|
writeFileSync(outPath, content, "utf-8");
|
|
console.log(`bake-analytics: wrote ${outPath} (mode=${mode}, enabled=${enabled})`);
|