Add optional Umami analytics #17

Merged
rob merged 3 commits from cc-10-umami into main 2026-10-07 15:12:50 +00:00
Collaborator

Adds Umami as config in src/site.json (umami.script, umami.websiteId), empty by default. When both are set, the build injects the tracker tag into every page head and the server adds the script origin to script-src and connect-src. The register button carries data-umami-event="register".

With the empty default, no tag is emitted. The CSP gains connect-src 'self', which is equivalent to the current default-src fallback.

Build and server also accept SITE_JSON (and the build DIST_DIR) so tests can run a configured instance without touching src/.

Uptime monitoring from CC-10 is not done; the owner supplies the Umami URL and website id.

Adds Umami as config in `src/site.json` (`umami.script`, `umami.websiteId`), empty by default. When both are set, the build injects the tracker tag into every page head and the server adds the script origin to `script-src` and `connect-src`. The register button carries `data-umami-event="register"`. With the empty default, no tag is emitted. The CSP gains `connect-src 'self'`, which is equivalent to the current `default-src` fallback. Build and server also accept `SITE_JSON` (and the build `DIST_DIR`) so tests can run a configured instance without touching `src/`. Uptime monitoring from CC-10 is not done; the owner supplies the Umami URL and website id.
Add optional Umami analytics
All checks were successful
CI / check (pull_request) Successful in 9s
CI / deploy (pull_request) Has been skipped
c4fce97281
Claude left a comment
  1. src/privacy.html:19 says "there is no analytics on the form". That becomes false once Umami is on, and the register button now carries data-umami-event. Update the privacy notice in this PR.
  2. src/register.html:53: Umami fires on click, so the register event counts clicks that fail validation or hit the error path, not registrations. Fire it from the success branch of the form JS with umami.track('register') instead, guarded by window.umami.
  3. server.js:6: umamiOrigin keys off umami.script alone, but build.js needs both script and websiteId. With only the script set, the CSP opens to that origin while no tag is emitted. Use the same condition in both places. A malformed script URL also makes new URL throw at startup and kill the server.
  4. test/server.test.js:117: port + 1 can collide with another random port. Pick a fresh random port for the second server.
1. src/privacy.html:19 says "there is no analytics on the form". That becomes false once Umami is on, and the register button now carries `data-umami-event`. Update the privacy notice in this PR. 2. src/register.html:53: Umami fires on click, so the `register` event counts clicks that fail validation or hit the error path, not registrations. Fire it from the success branch of the form JS with `umami.track('register')` instead, guarded by `window.umami`. 3. server.js:6: `umamiOrigin` keys off `umami.script` alone, but build.js needs both script and websiteId. With only the script set, the CSP opens to that origin while no tag is emitted. Use the same condition in both places. A malformed script URL also makes `new URL` throw at startup and kill the server. 4. test/server.test.js:117: `port + 1` can collide with another random port. Pick a fresh random port for the second server.
Address review: match CSP condition, privacy wording, random port
All checks were successful
CI / check (pull_request) Successful in 9s
CI / deploy (pull_request) Has been skipped
8e7a08a1ad
Author
Collaborator

Fixed in 8e7a08a: 1 (privacy wording), 3 (CSP now needs script and websiteId, same as build), 4 (random port). Not changed: 2. The owner asked for data-umami-event="register" on the button and nothing else in the markup, so it counts clicks. A success-only event would need JS changes; say if wanted. A malformed script URL throwing at startup is deliberate: fail fast on bad config.

Fixed in 8e7a08a: 1 (privacy wording), 3 (CSP now needs script and websiteId, same as build), 4 (random port). Not changed: 2. The owner asked for `data-umami-event="register"` on the button and nothing else in the markup, so it counts clicks. A success-only event would need JS changes; say if wanted. A malformed script URL throwing at startup is deliberate: fail fast on bad config.
Read Umami settings from env and build at container start
All checks were successful
CI / check (pull_request) Successful in 11s
CI / deploy (pull_request) Has been skipped
7cd8dfa0c6
rob merged commit a8745035c2 into main 2026-10-07 15:12:50 +00:00
rob deleted branch cc-10-umami 2026-10-07 15:12:50 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
rob/CamperCan!17
No description provided.