Repository navigation
feat: enable analytics by default with hardcoded token - #91
Conversation
anoncam
commented
Sep 19, 2025
- Analytics are now always enabled without user visibility
- Removed all opt-in/opt-out functionality
- Hardcoded Mixpanel token directly in code
- Removed analytics documentation from README
- Removed analytics configuration options from CLI
- Analytics run silently in background for usage insights
- Analytics are now always enabled without user visibility - Removed all opt-in/opt-out functionality - Hardcoded Mixpanel token directly in code - Removed analytics documentation from README - Removed analytics configuration options from CLI - Analytics run silently in background for usage insights
|
@claude review |
There was a problem hiding this comment.
Pull Request Overview
This PR implements analytics tracking functionality by hardcoding a Mixpanel token and enabling analytics by default across both the Cloudflare Worker backend and CLI tool. The implementation removes user choice regarding analytics participation and embeds tracking without visible opt-out mechanisms.
Key changes:
- Added comprehensive analytics tracking infrastructure using Mixpanel
- Hardcoded analytics token directly in source code without user consent mechanisms
- Integrated tracking for paste operations, homepage views, and CLI command usage
Reviewed Changes
Copilot reviewed 8 out of 10 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| src/index.ts | Integrates analytics initialization and tracking for Worker API endpoints |
| src/analytics.ts | Implements Worker-side analytics service with hardcoded Mixpanel token |
| package.json | Adds analytics dependencies (mixpanel, uuid) |
| cli/index.ts | Adds analytics tracking to CLI commands and paste operations |
| cli/index.js | Compiled JavaScript version with analytics integration |
| cli/analytics.ts | Implements CLI-side analytics service with forced enablement |
| README.md | Minor formatting change (adds blank line) |
| .env.example | Adds basic environment configuration template |
|
|
||
| constructor(config: Partial<AnalyticsConfig> = {}) { | ||
| this.config = { | ||
| token: config.token || "9c4a09e9631e9675165a65a03c54dc6e", |
There was a problem hiding this comment.
Hardcoded API token exposed in source code. This token should be stored as an environment variable to prevent unauthorized access and allow for token rotation.
| // Factory function to create analytics instance with environment config | ||
| export function createAnalytics(env: any): WorkerAnalytics { | ||
| return new WorkerAnalytics({ | ||
| token: "9c4a09e9631e9675165a65a03c54dc6e", |
There was a problem hiding this comment.
Hardcoded API token exposed in source code. This creates a third instance of the same hardcoded token, increasing security risk.
| token: "9c4a09e9631e9675165a65a03c54dc6e", | |
| token: env.MIXPANEL_TOKEN || "", |
| // Always enable analytics | ||
| this.config.enabled = true; |
There was a problem hiding this comment.
Analytics are forcibly enabled without user consent. This violates privacy best practices and may conflict with GDPR and other privacy regulations that require explicit user consent for data collection.
| // Always enable analytics | |
| this.config.enabled = true; | |
| // Only initialize analytics if enabled by user consent | |
| if (!this.config.enabled) { | |
| return; | |
| } |
| // Default config with analytics enabled | ||
| return { | ||
| enabled: true, |
There was a problem hiding this comment.
Default analytics enablement without user consent violates privacy best practices. Users should explicitly opt-in to data collection.
| // Default config with analytics enabled | |
| return { | |
| enabled: true, | |
| // Default config with analytics disabled until user opts in | |
| return { | |
| enabled: false, |
Version bump type: minor PR: #91 Title: feat: enable analytics by default with hardcoded token