Skip to content

feat: enable analytics by default with hardcoded token - #91

Merged
anoncam merged 1 commit into
mainfrom
feature/mixpanel-analytics
Sep 19, 2025
Merged

anoncam merged 1 commit into
mainfrom
feature/mixpanel-analytics

Conversation

@anoncam

@anoncam anoncam commented Sep 19, 2025

Copy link
Copy Markdown
Owner
  • Analytics are now always enabled without user visibility
  • Removed all opt-in/opt-out functionality
  • Hardcoded Mixpanel token directly in code
  • Removed analytics documentation from README
  • Removed analytics configuration options from CLI
  • Analytics run silently in background for usage insights

- Analytics are now always enabled without user visibility
- Removed all opt-in/opt-out functionality
- Hardcoded Mixpanel token directly in code
- Removed analytics documentation from README
- Removed analytics configuration options from CLI
- Analytics run silently in background for usage insights
@anoncam

anoncam commented Sep 19, 2025

Copy link
Copy Markdown
Owner Author

@claude review

@anoncam
anoncam requested a review from Copilot September 19, 2025 18:33

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR implements analytics tracking functionality by hardcoding a Mixpanel token and enabling analytics by default across both the Cloudflare Worker backend and CLI tool. The implementation removes user choice regarding analytics participation and embeds tracking without visible opt-out mechanisms.

Key changes:

  • Added comprehensive analytics tracking infrastructure using Mixpanel
  • Hardcoded analytics token directly in source code without user consent mechanisms
  • Integrated tracking for paste operations, homepage views, and CLI command usage

Reviewed Changes

Copilot reviewed 8 out of 10 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
src/index.ts Integrates analytics initialization and tracking for Worker API endpoints
src/analytics.ts Implements Worker-side analytics service with hardcoded Mixpanel token
package.json Adds analytics dependencies (mixpanel, uuid)
cli/index.ts Adds analytics tracking to CLI commands and paste operations
cli/index.js Compiled JavaScript version with analytics integration
cli/analytics.ts Implements CLI-side analytics service with forced enablement
README.md Minor formatting change (adds blank line)
.env.example Adds basic environment configuration template

Comment thread src/analytics.ts

constructor(config: Partial<AnalyticsConfig> = {}) {
this.config = {
token: config.token || "9c4a09e9631e9675165a65a03c54dc6e",

Copilot AI Sep 19, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hardcoded API token exposed in source code. This token should be stored as an environment variable to prevent unauthorized access and allow for token rotation.

Copilot uses AI. Check for mistakes.
Comment thread cli/analytics.ts
Comment thread src/analytics.ts
// Factory function to create analytics instance with environment config
export function createAnalytics(env: any): WorkerAnalytics {
return new WorkerAnalytics({
token: "9c4a09e9631e9675165a65a03c54dc6e",

Copilot AI Sep 19, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hardcoded API token exposed in source code. This creates a third instance of the same hardcoded token, increasing security risk.

Suggested change
token: "9c4a09e9631e9675165a65a03c54dc6e",
token: env.MIXPANEL_TOKEN || "",

Copilot uses AI. Check for mistakes.
Comment thread cli/analytics.ts
Comment on lines +92 to +93
// Always enable analytics
this.config.enabled = true;

Copilot AI Sep 19, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Analytics are forcibly enabled without user consent. This violates privacy best practices and may conflict with GDPR and other privacy regulations that require explicit user consent for data collection.

Suggested change
// Always enable analytics
this.config.enabled = true;
// Only initialize analytics if enabled by user consent
if (!this.config.enabled) {
return;
}

Copilot uses AI. Check for mistakes.
Comment thread src/analytics.ts
Comment thread cli/analytics.ts
Comment on lines +66 to +68
// Default config with analytics enabled
return {
enabled: true,

Copilot AI Sep 19, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Default analytics enablement without user consent violates privacy best practices. Users should explicitly opt-in to data collection.

Suggested change
// Default config with analytics enabled
return {
enabled: true,
// Default config with analytics disabled until user opts in
return {
enabled: false,

Copilot uses AI. Check for mistakes.
@anoncam
anoncam merged commit 600cfab into main Sep 19, 2025
3 checks passed
github-actions Bot added a commit that referenced this pull request Sep 19, 2025
Version bump type: minor
PR: #91
Title: feat: enable analytics by default with hardcoded token
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants