Skip to content

Add bilingual usage research and privacy-aware product analytics - #12

Merged
lifeodyssey merged 1 commit into
mainfrom
codex/usage-report-and-analytics
Sep 23, 2026
Merged

lifeodyssey merged 1 commit into
mainfrom
codex/usage-report-and-analytics

Conversation

@lifeodyssey

@lifeodyssey lifeodyssey commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

Share HTML lacked a reliable record of actual agent tool outcomes and consenting browser acquisition. This adds first-party Worker analytics with separate HTTP, MCP and browser evidence, and a dedicated Share HTML GA4 stream using sanitized manual events and explicit browser consent.

The static bilingual /report/0923/ report combines 2,797 creation records, timestamped content-request events, public-artifact analysis, sampled Cloudflare browser traffic and request-egress geography. It separates product-page loads, content requests and creation operations, and explains the API-led September increase, concentrated educational-content activity and weak MCP link-opening behavior. Fixed seven-day follow-up windows avoid comparing immature shares with older ones. Verified deployment evidence is plotted alongside observed activity. The report includes labeled charts, a source–purpose–request Sankey, accessible data tables and month filters. Records and requests are not represented as unique people or causal SEO/GEO lift. /report redirects to the dated report.

Measurement and privacy

  • Allowlisted, bounded telemetry excludes uploaded HTML, filenames, titles, share identifiers, access keys, raw IPs and arbitrary query strings. Coarse country comes only from Cloudflare metadata; browser events require opt-in and respect DNT/GPC.
  • GA is isolated from the zhenjia.dev blog by property, stream, cookie prefix and hostname scope. Enhanced measurement is off. Share wrappers and uploaded HTML do not initialize GA.
  • The approved additive Supabase migrations are applied: RLS, secret-constrained ingestion, atomic rate limits/deduplication, and daily retention/aggregation. Raw events retain 90 days; daily aggregates retain 730 days. Existing content tables are unchanged.
  • Public report data contains aggregate counts and anonymized descriptions. Private HTML was not fetched. Historical content counters include both embedded loads and direct opens.

Validation

  • 573 tests passed across 22 files, including consent, sanitization, attribution, actual MCP-handler classification, country validation, event bounds and report routing.
  • Production database probes verified unauthorized rejection, RLS, idempotent maintenance and country rollup, then rolled back probe data. The scheduled job is enabled; its first automatic run remains to be observed.
  • Frozen populations and chart margins were independently reconciled, including 14,969 period requests versus 14,939 requests on the July–September creation cohort. Cloudflare RUM estimates retain their sampling and bot-flag qualifications. Offline DOM checks passed for both languages, all 18 figures, 24 tables and month filters. Build/typecheck passed. Native Chrome confirmed the earlier white report; final-edition/mobile visual checks remain pending because the Mac is locked.

Deployment verification

Merged as f5b2748757948726ecb0890f3f6fdc3baf6da297; both the protected-branch Build and Cloudflare Workers Build completed successfully. Cloudflare deployed version b8aef6ed-8b6e-4c47-91d4-2df099541d41 at 2026-09-23 18:14:32 UTC (September 24 02:14 Taipei) with 100% traffic.

  • The fixed report URL is live at https://sharehtml.zhenjia.dev/report/0923/. Production embedded data, chart JavaScript and CSS match the verified local artifacts. /report?lang=en redirects correctly; the report is noindex and missing report assets return 404.
  • Seventeen production HTTP/configuration checks passed. Follow-up database queries verified nine internal events: main page response, consented-browser endpoint ingestion, content response, discovery response, failed upload, MCP initialize/read-tool success, and two synthetic WebMCP endpoint checks. The repeated event ID produced exactly one row, with normalized routes and coarse country attribution.
  • WebMCP endpoint checks establish ingestion only; an actual browser WebMCP invocation remains unverified. No successful test share was created. Two new non-internal share_created success events were already present after release; the production marker does not establish external-user identity.
  • The dedicated GA configuration is served, isolated from the blog. Actual Google receipt and final-edition/mobile visual checks remain unverified because the Mac is locked. Daily maintenance is enabled and manually validated; its first automatic scheduled run is still pending.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @lifeodyssey, your pull request is larger than the review limit of 150,000 diff characters

@coderabbitai

coderabbitai Bot commented Sep 23, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: cabcaa16-05b5-425e-a70c-646d43bceda7

📥 Commits

Reviewing files that changed from the base of the PR and between 1c4c6f4 and c74e6ae.

📒 Files selected for processing (39)
  • .gitignore
  • .impeccable.md
  • README.md
  • docs/analytics/2026-09-23-report-methodology.md
  • docs/analytics/measurement-contract.md
  • docs/analytics/operations.md
  • docs/analytics/report-outline-2026-09-23.md
  • docs/analytics/skills-and-figure-review.md
  • docs/analytics/traffic-research.md
  • docs/analytics/validation-2026-09-23.md
  • index.html
  • public/report/0923/index.html
  • public/report/0923/report.css
  • public/report/0923/report.js
  • scripts/analytics/build_usage_report.py
  • scripts/analytics/render_usage_report.py
  • scripts/analytics/usage-followup.sql
  • scripts/analytics/usage-report.template.html
  • src/client/AnalyticsNotice.tsx
  • src/client/analytics.ts
  • src/client/api.ts
  • src/client/main.tsx
  • src/client/router.tsx
  • src/client/styles.css
  • src/client/webmcp.ts
  • src/worker/analytics.ts
  • src/worker/index.ts
  • src/worker/mcp.ts
  • src/worker/shares.ts
  • supabase/migrations/20260923154418_analytics_measurement.sql
  • supabase/migrations/20260923155702_analytics_page_served.sql
  • supabase/migrations/20260923163924_analytics_webmcp.sql
  • supabase/migrations/20260923170444_analytics_country.sql
  • tests/analytics.test.ts
  • tests/client/analytics.test.ts
  • tests/client/webmcp.test.ts
  • tests/shares.test.ts
  • tests/worker-index.test.ts
  • wrangler.jsonc
 ___________________________________________
< GPU-powered code review. It's the future. >
 -------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lifeodyssey
lifeodyssey merged commit f5b2748 into main Sep 23, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant