Enable analytics by default with preserved opt-outs - #13
Conversation
There was a problem hiding this comment.
Sorry @lifeodyssey, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 3 days and 17 hours by commenting @sourcery-ai review. Upgrade to get a review now.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (8)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR enables sanitized browser, Google, and eligible WebMCP analytics by default for visitors without a saved preference, while preserving opt-outs and privacy signals, making opt-out robust to storage failures, exposing the setting in the footer, and documenting the resulting measurement-coverage change. Sequence diagram for analytics preference changessequenceDiagram
actor Visitor
participant Footer as AnalyticsNotice
participant Analytics as analytics.ts
participant Storage as localStorage
participant Collectors as Browser/WebMCP/GA
Visitor->>Footer: Click Analytics preferences
Footer->>Analytics: readAnalyticsConsent()
Analytics->>Storage: getItem(CONSENT_KEY)
Storage-->>Analytics: saved preference or unavailable
Analytics-->>Footer: current setting
Visitor->>Footer: choose(denied)
Footer->>Analytics: setAnalyticsConsent(denied)
Analytics->>Storage: setItem(CONSENT_KEY, denied)
Analytics->>Collectors: clear tab context and suppress collection
Collectors-->>Visitor: Analytics off
Visitor->>Footer: choose(granted)
Footer->>Analytics: setAnalyticsConsent(granted)
Analytics->>Storage: setItem(CONSENT_KEY, granted)
Analytics->>Collectors: allow eligible sanitized events
Collectors-->>Visitor: Analytics on
Flow diagram for default-on analytics eligibilityflowchart TD
A[Visitor opens site] --> B{Analytics service enabled?}
B -- No --> Z[No browser analytics]
B -- Yes --> C{DNT or GPC active?}
C -- Yes --> Z
C -- No --> D{Preference storage readable?}
D -- No --> Z
D -- Yes --> E{Saved opt-out?}
E -- Yes --> Z
E -- No --> F[Analytics enabled by default]
F --> G[Sanitized browser and eligible WebMCP events]
G --> H[Optional Google Analytics events]
Flow diagram for failed opt-out persistenceflowchart TD
A[Visitor selects turn off analytics] --> B["setAnalyticsConsent(denied)"]
B --> C{localStorage write succeeds?}
C -- Yes --> D[Persist denied preference]
C -- No --> E[Keep denied in memory]
D --> F[Clear session/acquisition context]
E --> F
F --> G[Suppress collection for current page]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Visitors previously generated no browser or Google Analytics events until they clicked the analytics prompt. Enable sanitized analytics by default for visitors without a saved preference, while preserving existing opt-outs and browser DNT/GPC signals. The footer shows the current setting and lets visitors turn collection off or back on. Opting out takes effect even if saving the preference fails.
Share routes remain excluded from Google, and the existing content/key/URL sanitization is unchanged. Document this as a collection-coverage change, not evidence of user growth.
Validation: 581 tests across 23 files passed, production build and TypeScript checks passed, Worker deployment dry run passed, independent review found no blocking issues. Released to production on 2026-09-25 at 17:13:08 UTC (September 26 at 01:13:08 Asia/Taipei), initial Worker version
c9b3853d-5ade-494a-81d1-eff067339dca; merged commit7b0668b73c554541d4716e795a42e4a6bd7cb3f3.A fresh Chrome Incognito session loaded the production bundle
index-D2dTX9YF.jswithout clicking any analytics consent control. Google tag loading returned 200 and the GA collect request forG-8B4LL2C8L7returned 204. First-partypage_viewandwebmcp_availablewere verified in production storage with the internal validation campaigndefault_on_0926; these checks must not be counted as customer growth.The production preferences control was then switched off and the page reloaded. The off state persisted, and the Network panel showed no Google tag/collect requests and no
/api/analytics/eventsrequests. Existing independent Cloudflare service measurement was unchanged.