Skip to content

[HORO-1700] 🔒 docs: Protect analytics URL and referrer privacy - #173

Merged
Chisanan232 merged 18 commits into
mainfrom
HORO-1700/fix/docs-analytics-privacy
Oct 8, 2026
Merged

Chisanan232 merged 18 commits into
mainfrom
HORO-1700/fix/docs-analytics-privacy

Conversation

@Chisanan232

@Chisanan232 Chisanan232 commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Description

Constrain hosted Hub analytics to fixed public identity and finite event vocabularies. Assemble current Core plus every eligible historical tag, then execute Core's reviewed publication hardener before manifest verification. Pin 5f37f5f1e97c089b1199ee170bba807dbca4583a until it reaches Core's default branch, require a nonzero processed-page report and clean temporary source on failure. No product copy or runtime boundary changes.

Type of Change

  • 🐛 Bug fix
  • 🔧 Configuration / CI change

Related Issues

Documentation Checklist

  • Actual-source Node VM regression and local mdBook/complete final aggregation pass. No blanket no-warning claim is made.
  • Native metadata and complete aggregate verification pass; internal-link and version-manifest gates execute in the publisher. Full metadata baseline has pre-existing rule-13 failures; established diff-scoped check passes.
  • Page registration in SUMMARY.md: N/A, no new page.
  • No self-hosting instructions added.
  • Last-reviewed footer: N/A, no page-copy changes.
  • Every published historical commit follows GitEmoji convention: new corrections comply; earlier naming deviations are recorded in SPE-33 and remain unchanged.

Exact final head e4f2397. Root independently re-fetched aggregate37192842632/job111408485719 success, CodeQL/Sonar/metadata success and deployment skipped. Root independently inspected CLEAN generated /tmp/horo1700-final-public-e4f2397: 1622 Core HTML pages, 962 analytics-bearing pages, all962 hardened and all20 archived tag directories. Actual SDK prompt/repo cases on Hub root/Core latest/rc7 safe with no page errors. The prior macOS silent-no-op local proof was rejected and superseded; final assembly required no manual repair.

Material Risks / Publication Gate

OVERALL PRIVACY ACCEPTANCE FAILS: automatic GA site-search still emits q/search canaries on all three tested channels; Cloudflare automatic RUM still emits arbitrary URL paths. All probe collectors were intercepted before transmission. Current account credentials deny required settings edits. Required code-owner approval and post-rollout independent live verification remain mandatory; no merge/deployment occurred. Current sole CODEOWNER is also the PR author, so that account cannot satisfy the required approval. Self-review and independent source/artifact review are recorded as scoped evidence, not a substitute for the server-side review gate.

@Chisanan232 Chisanan232 changed the title 🛡️(docs): close analytics URL and referrer leakage [HORO-1700] 🔒 docs: Protect analytics URL and referrer privacy Oct 4, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

@Chisanan232

Copy link
Copy Markdown
Contributor Author

Owner self-review (AAASM-5858 condition 1-8 checklist) — LGTM

Reviewed PR head e4f2397ed16c34a7f1e0bc1353b5a2f663b8caf7 (unchanged since this review).

  1. Substantive review complete. hub-metadata-check.yml wires a new privacy VM test into CI. aggregate.sh applies the Core-owned hardener after every version/root-redirect is assembled, pinned to a specific reviewed Core commit (5f37f5f1e97c089b1199ee170bba807dbca4583a — the same head just merged in agent-assembly#2597) when the hardener isn't yet present locally, with a strict pass/fail on hardener exit status and a check that it actually changed ≥1 rendered file. aa-funnel-events.js replaces raw location.hostname/page_path/document.title/link_url/a.hostname with a closed-vocabulary page_id/link_domain mapping — no longer capable of carrying arbitrary runtime strings. head.hbs mirrors Core's bootstrap pattern.
  2. This comment is the durable LGTM record.
  3. CI gates: all required checks green (CodeQL, SonarCloud, metadata-sync, python/actions analyze) — zero failures, Deploy to GitHub Pages legitimately skipped (PR context, not a push to main).
  4. No unresolved correctness/security defect — analytics-privacy.test.mjs VM-executes the real head.hbs bootstrap + aa-funnel-events.js together with a hostile location.href/document.title containing PRIVATE_CANARY, asserts the canary never appears in any emitted call, and asserts the exact sanitized page_location/page_referrer/page_title values.
  5. No REQUEST_CHANGES, no unresolved review thread — zero reviews, zero threads.
  6. Head unchanged since this review (verified immediately before posting).
  7. No merge conflicts (mergeable: MERGEABLE).
  8. Evidence present — the privacy test is part of this diff and the green CI run above.

Condition 9: reviewDecision: REVIEW_REQUIRED, same-identity author/CODEOWNER/org-admin deadlock, freshly verified via gh api orgs/ai-agent-assembly/memberships/Chisanan232 → role: admin.

Merging under the AAASM-5858 owner-only admin-merge exception (.claude/rules/04-agent-escalation.md, ratified in PR #68).

@Chisanan232
Chisanan232 merged commit 9eba353 into main Oct 8, 2026
8 checks passed
@Chisanan232
Chisanan232 deleted the HORO-1700/fix/docs-analytics-privacy branch October 8, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant