Repository navigation
fix(app): stop sending the relay's session identity to analytics - #1839
Open
ethicnology-agent wants to merge 1 commit into
Open
ethicnology-agent wants to merge 1 commit into
ethicnology-agent wants to merge 1 commit into
Conversation
session_switched carried the relay's own Session primary key and three exact server-side timestamps: createdAt, activeAt and updatedAt. PRIVACY.md states that analytics events use an anonymised id and cannot be matched back to any user or account. The distinct id is indeed unlinkable on its own, derived from the account secret, but those four properties join straight back to the Session table, so the pair re-identified the profile and the claim did not hold. Drop them. The event still counts a switch, which is what it was added for. Per-session analysis, if it is wanted later, needs an identifier the relay cannot compute - a client-generated value stored only on the device - rather than the server's own key. The parameter goes with the properties so the identity cannot drift back in through a future caller. session_switched was the only event carrying a server-owned identifier; every other one sends flags, enumerations or client versions.
ethicnology-agent
force-pushed
the
fix/app-analytics-drops-server-session-identity
branch
from
October 1, 2026 19:02
fea83e9 to
e909b8f
Compare
Author
|
Rebased onto current |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the analytics part of #1833. The other two parts of that issue are deliberately left alone — see the scope note at the end.
Problem
PRIVACY.md:24,31states that analytics events use an anonymised id and that "we cannot match this back to any user or account".session_switchedsends four properties that defeat it:The distinct id really is unlinkable on its own — it is derived from the account secret. But
session_idis the relay's ownSessionprimary key, and the three timestamps are the server's own columns (schema.prisma:98). Anyone holding both the PostHog profile and the database can join one to the other, which is the exact operation the policy says is impossible. The unlinkability of the identifier does not help when the properties are server-owned keys.session_switchedis the only event that does this. Every other event insources/track/index.tssends flags, enumerations or client versions — I checked all of them.What this changes
The four properties go, and the parameter goes with them so the identity cannot drift back in through a future caller. The event still counts a switch, which is what it was added for.
sources/track/index.ts—trackSessionSwitched()takes nothing and captures a bare event; the now-unusedSessiontype import is dropped.if (session)guard stays, because "only count a switch to a session that exists" is still the intent.sources/track/index.test.ts(new) — asserts the event carries no properties at all, with a comment recording why.useNavigateToSession.test.ts— the existing assertion no longer expects an argument.Verified red/green: against the current event both new cases fail; with the change,
sources/track/anduseNavigateToSessionpass 13/13,tsc --noEmitis clean, and the app suite is 1899 passed / 1 skipped.One pre-existing failure is unrelated and not introduced here:
sources/components/sessionPresentation.test.tsfails to collect withReferenceError: __DEV__ is not defined, onorigin/mainas well as on this branch.If you want per-session funnels back
They need an identifier the relay cannot compute — a random value generated on the device, stored locally, never sent to the server. I did not add one, because whether that trade is worth making is your call, not mine, and it is a different change.
Scope: what this does not touch
#1833 reports three gaps between
PRIVACY.mdand the code. This PR closes one.I have also not edited
PRIVACY.md. For this path the text is now accurate again; for the other two, whether the code or the policy moves is your decision.