Skip to content

chore(promote): analytics capture, QA fixes, and dependency patches to production - #61

Merged
scttbnsn merged 15 commits into
mainfrom
dev
Aug 28, 2026
Merged

chore(promote): analytics capture, QA fixes, and dependency patches to production#61
scttbnsn merged 15 commits into
mainfrom
dev

Conversation

@scttbnsn

Copy link
Copy Markdown
Collaborator

Promotes everything on dev since the #56 cut:

  • feat(analytics): capture $pageleave and send $pathname (feat(analytics): capture $pageleave and send $pathname #60). Prod events currently carry neither, which leaves PostHog's Page/Entry/Exit tables empty and counts every session as a zero-duration bounce.
  • fix(seo): JSON-LD logo pointed at a file that never existed (404 for crawlers), base URLs could emit double slashes when NEXT_PUBLIC_SITE_URL had a trailing slash, /studio/ now explicitly disallowed in robots, stable *.vercel.app aliases 308 to codeswhat.com.
  • fix(api): subscribe route returns a fixed error message instead of passing EmailOctopus's detail field through to clients.
  • build(deps): next bumped to ^16.2.11 (resolves 16.3.3), clearing all 35 Dependabot alerts (next, postcss, nanoid, sharp). npm audit is now clean.
  • chore: gitignore entries for .vercel/, *.bundle, and .claude/ (chore: ignore .claude/ with a tracked line #59); biome pre-commit job tolerates biome-ignored files.
  • docs: roadmap entries for the web-analytics follow-ups (ops X37) and the acquisition-data standard pointer.

Verified before this PR: biome + tsc clean, scene and posthog suites green, next build generates all 8 routes, pageleave wiring confirmed in the built client bundle, and a 9-agent QA pass over every production surface.

biggest-littlest and others added 14 commits August 15, 2026 18:45
…stion (#52)

PostHog's cookieless server-hash step reads $raw_user_agent and $host
straight off event.properties and drops the event with a
cookieless_missing_user_agent/cookieless_missing_host ingestion warning
if either is absent. createCommonProperties rebuilt an allowlisted
properties object that dropped both, so every event was silently
discarded at ingestion. Forward them through; never add $ip, which
PostHog's capture service fills in server-side from the connection.

Co-authored-by: scttbnsn <80784472+scttbnsn@users.noreply.github.com>
* fix(analytics): promote cookieless ingestion fix to production (#53)

PostHog's cookieless server-hash step reads $raw_user_agent and $host
straight off event.properties and drops the event with a
cookieless_missing_user_agent/cookieless_missing_host ingestion warning
if either is absent. createCommonProperties rebuilt an allowlisted
properties object that dropped both, so every event was silently
discarded at ingestion. Forward them through; never add $ip, which
PostHog's capture service fills in server-side from the connection.

Co-authored-by: biggest-littlest <zap_inane.2p@icloud.com>

* chore(config): drop the stale Cursor rules folder

* docs(config): drop dangling .cursorrules references

---------

Co-authored-by: biggest-littlest <zap_inane.2p@icloud.com>
Measured over the shared PostHog project, 208 of 432 sessions across
the five instrumented sites record zero duration, and PostHog's
built-in Web analytics Page/Entry page/Exit page tables return zero
rows. capture_pageleave was false, so a session's last recorded
timestamp is its last pageview, and a five-minute read of one page
scores as zero seconds.

Flipping the option alone fixes nothing: sanitizeEvent allowlisted
only $pageview, cta activated, and $web_vitals, so every $pageleave
posthog-js emitted would have been dropped silently with no error and
no ingestion warning. This adds a $pageleave branch that rebuilds the
event the same way $pageview does. capture_pageview is false here
(pageviews are captured by hand), so posthog-js's
_shouldCapturePageleave gate needs an explicit true rather than the
default.

$pathname is the property PostHog's page tables actually key off, and
it was never sent. It's bound to the already-sanitized `path` value,
never the raw pathname, so it can't carry a route outside
ALLOWED_ROUTES and adds no information the event wasn't already
sending. A regression test asserts the two never diverge.

No privacy option changes: cookieless_mode, person_profiles,
persistence, disable_persistence, respect_dnt, save_referrer, and
save_campaign_params are untouched.

Part of X16 in the ops execution plan.
- fix(seo): point Organization.logo at /icon-512x512.png; the referenced
  /logos/codeswhat-logo-green.png never existed, so crawlers got a 404
- fix(seo): strip trailing slashes from BASE_URL and reuse it in robots.ts
  and sitemap.ts, so a NEXT_PUBLIC_SITE_URL set with a trailing slash can't
  emit //sitemap.xml-style URLs
- chore(seo): disallow /studio/ in robots.txt; the capture pages already
  404 in production but the exclusion shouldn't depend on that guard
- chore(seo): 308 the stable *.vercel.app production aliases to
  codeswhat.com instead of serving duplicate content
- fix(api): stop forwarding EmailOctopus error detail to subscribe clients;
  log it server-side and return a fixed message
One-line range bump; npm resolves next 16.3.3, which also pulls the
patched transitive versions: postcss 8.5.23, nanoid 3.3.18, sharp 0.35.4.
npm audit now reports zero vulnerabilities. No code changes needed: the
app has no middleware, rewrites, server actions, CSP nonces, or
next/image usage, so none of the fixed CVEs required app-side work.
- build(deps): pick up the root-params.d.ts reference next 16.3 adds
- ci(hooks): pass --no-errors-on-unmatched to the biome pre-commit job so
  committing only biome-ignored files (like next-env.d.ts) doesn't fail
It was covered only by .git/info/exclude, which protects one clone and nobody else's. Without a tracked line, `git add -A` in the parent stages a nested worktree as an embedded gitlink and `git clean -ffd` deletes it.
@scttbnsn

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@vercel

vercel Bot commented Aug 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
codeswhat-website Ready Ready Preview Aug 28, 2026 11:42pm

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown
❌ Action failed

Review failed.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 56 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 34e898c6-ee30-476f-aeea-18c44ca6d931

📥 Commits

Reviewing files that changed from the base of the PR and between 213fac4 and 5aade3b.

⛔ Files ignored due to path filters (1)
  • frontend/package-lock.json is excluded by !**/package-lock.json, !**/package-lock.json
📒 Files selected for processing (14)
  • .gitignore
  • ROADMAP.md
  • frontend/app/api/subscribe/route.ts
  • frontend/app/robots.ts
  • frontend/app/sitemap.ts
  • frontend/instrumentation-client.ts
  • frontend/lib/posthog-privacy.ts
  • frontend/lib/site-config.ts
  • frontend/next-env.d.ts
  • frontend/next.config.ts
  • frontend/package.json
  • frontend/test/posthog-source.test.mjs
  • frontend/test/posthog.test.ts
  • lefthook.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@scttbnsn
scttbnsn merged commit 5663daa into main Aug 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants