Repository navigation
Merge the initial browser pageview with a server page-load ID - #98
simple-analytics-ai[bot] wants to merge 9 commits into
Conversation
Documentation update
|
Claude review checkpointReviewed commit |
|
SDLC label: |
Address review feedback: document compiled-byte optimization and public naming in AGENTS.md, leave UUID validation and client-source detection to the queue, and explain the ignored-page leave guard.
Summary
Closes #104
Accept a UUID v4 from
window.sa_settings.pageLoadIdordata-page-load-id, with JavaScript settings taking precedence. The first browser pageview enriches the server-created record; later navigations create separate records. Events retain the per-documentsession_idand the current page'spage_id. An absent ID preserves normal collection. The queue validates supplied IDs and saves the full pageview with a fresh UUID when an ID is malformed. Ignored paths cannot attribute events or leave data to the server record.Capture each accepted pageview's path, query, metrics, referrer and IDs before waiting for browser client hints. Previously, two navigations during that wait could rewrite the first server record to the second path and count the second page twice. The fix also keeps intervening events associated with the correct page, regardless of client-hints response order.
As requested in review, keep the browser script lightweight: remove its UUID validation and client collection field. Queue #98 infers client collection for
/simple.gifand/append, including older and SRI-pinned scripts. Explain why the ignored-page leave guard is needed, and extendAGENTS.mdwith guidance on compiled size, predefined variable reuse, and readable but short public option/attribute names.Regenerate the v12 distribution files. Update development dependencies, use native fetch in the BrowserStack metadata loader, retain Selenium 4.3.1 for its required legacy capabilities, and preserve existing package trust controls. Patch serialize-javascript to 7.1.2 and align agent guidance with the existing Node 24.18.0 pin.
Changes:
Security implications
Has security impact - described as: a page-supplied
pageLoadIdnow controls which existing analytics record the browser script mutates throughtype=append, so the public append mechanism is used for first-page enrichment. IDs are per page load and are not stored in cookies or browser storage, existing DNT and metric settings remain effective, and ignored paths cannot attribute events or leave data to the server record. Client-side UUID validation was removed, so the queue is now the only place that rejects malformed or non-v4 IDs. The last dependency audit reports no production findings and one high development advisory through nodemon's unpatchedbraces@3.0.3.Testing
npm run build(exit 0,dist/latest/latest.dev.jsunchanged against the committed output) andnpm run test:unit(33 passing) ond9ca524, and confirmed against the queue repository thatuuid.validaterejects non-v4original_idvalues.d9ca524da551041ae6acc435cd8fcafe66ab6b2f. Automated-review CI passes and its fallback finding is fixed in queue commit363b88d9ce16753cd527d1a5862088d06f6a4bfa. BrowserStack CI passes: https://github.com/simpleanalytics/scripts/actions/runs/37474383926. Automated-review CI passes: https://github.com/simpleanalytics/scripts/actions/runs/37474387294.Checklist