Skip to content

fix: address #504, #505, #506, #507 - #563

Merged
james2177 merged 5 commits into
stellar-vortex-protocol:mainfrom
sundayjob996:drips/504-505-506-507
Sep 30, 2026
Merged

james2177 merged 5 commits into
stellar-vortex-protocol:mainfrom
sundayjob996:drips/504-505-506-507

Conversation

@sundayjob996

Copy link
Copy Markdown

Summary

fix: address #504, #505, #506, #507

What was solved

#504 — [High] Add privacy-preserving web-vitals and error telemetry with a pluggable sink and consent controls

Add a privacy-preserving telemetry module for Core Web Vitals and scrubbed client error summaries, with a pluggable sink (default no-op), strict allowlist schema, PII scrubbing, opt-in consent UI persisted in the privacy center, DNT/GPC honoring, and documentation of collected fields plus a build-time disable path.

Addressed:

  • Changed: src/components/GlobalErrorCapture.tsx, src/lib/secureLogging.ts
  • Provide a telemetry module exposing track(event) and reportVital() with a schema-first allowlist (name, route pattern not raw URL, metric values, app version, coarse device class); reject anything else at type and runtime level.
  • Implement a pluggable sink interface with send(batch), default no-op, optional backend endpoint or third-party; batch with flush on visibilitychange using sendBeacon with size caps and never blocking navigation.
  • Collect LCP/INP/CLS/TTFB via web-vitals or an equivalent manual PerformanceObserver implementation.

#505 — [High] Restructure CI into parallel, cached jobs with required checks and a fast-feedback path

Restructure the single serial CI workflow into parallel, cached jobs (static, unit, build, e2e, storybook-visual, security) with a final ci-success aggregator as the required check, path filtering for docs-only PRs, Playwright sharding with chromium-only on PRs and full matrix on main/nightly, and flaky-test reporting.

Addressed:

  • Changed: .github/workflows/ci.yml, playwright.config.ts, package.json, .github/workflows/coverage-badge.yml
  • Split .github/workflows/ci.yml into parallel jobs: static (lint, typecheck, i18n, editorconfig, docs, manifest checks), unit (Vitest with coverage + ratchet), build (Next build + bundle size + analyzer artifact), e2e (Playwright sharded across browsers), storybook-visual, and security (dependency policy, lockfile lint, SBOM).
  • Add caching: npm cache, .next/cache, and Playwright browsers keyed by version; retain concurrency groups; target total PR wall-clock under 8 minutes.
  • Implement path filtering so docs-only PRs skip heavy jobs while keeping required-check names satisfied via paths-ignore plus a final ci-success aggregator job used as the branch-protection required check.

#506 — [High] Add a merge-conflict-marker and duplicate-declaration guard to pre-commit and CI

Add a fast merge-debris guard to the repo: a new scripts/check-merge-debris.mjs that scans tracked files for conflict markers, detects duplicate keys in JSON configs (via a tokenizing parser, not JSON.parse), and detects duplicate top-level TS declarations and duplicate members within a single type literal using the TypeScript compiler API. Wire it into lint-staged, Husky pre-commit, and the CI static job, enable ESLint duplicate/redeclare rules, and document the workflow in CONTRIBUTING.md.

Addressed:

  • Changed: scripts/check-merge-debris.mjs, scripts/check-merge-debris.mjs, .lintstagedrc.js, scripts/check-merge-debris.mjs
  • Create scripts/check-merge-debris.mjs that detects <<<<<<</=======/>>>>>>> conflict markers in tracked files
  • Detect duplicate keys in package.json and JSON configs using a tokenizing parser (not JSON.parse, which silently drops duplicates)
  • Detect duplicate top-level declarations in TS files via the TypeScript AST: duplicate const/function/type/interface and duplicate members within a single type literal

#507 — [High] Upgrade PR previews with automated e2e, Lighthouse, visual diffs and a consolidated PR report comment

Extend the preview deployment pipeline so each PR preview runs a curated Playwright smoke suite against the deployed URL, a Lighthouse run on three routes with budget deltas vs main, and visual diffs of key routes vs the last main deployment, then posts a single sticky PR comment (updated in place via an HTML marker) summarizing preview URL, check statuses, bundle-size delta, Lighthouse deltas, and artifact links. Fork PRs get a safe comment explaining local verification without secret exposure, using a least-privilege pull_request vs workflow_run pattern.

Addressed:

  • Changed: .github/workflows/preview-deploy.yml, playwright.config.ts, e2e/smoke/preview-smoke.spec.ts, scripts/build-preview-report.mjs
  • After preview deploys, run a curated Playwright smoke suite with BASE_URL set to the preview URL using the mocked-wallet fixture against staging backend/mocks
  • Upload Playwright traces on failure and report pass/fail status
  • Run Lighthouse on 3 routes and compute budget deltas vs main

Changes

  • src/components/GlobalErrorCapture.tsx (modify)
  • src/lib/secureLogging.ts (modify)
  • .github/workflows/ci.yml (modify)
  • playwright.config.ts (modify)
  • package.json (modify)
  • .github/workflows/coverage-badge.yml (modify)
  • scripts/check-merge-debris.mjs (create)
  • .lintstagedrc.js (modify)
  • .github/workflows/preview-deploy.yml (modify)
  • e2e/smoke/preview-smoke.spec.ts (create)
  • scripts/build-preview-report.mjs (create)

Approach

  1. [High] Add privacy-preserving web-vitals and error telemetry with a pluggable sink and consent controls #504 — [High] Add privacy-preserving web-vitals and error telemetry with a pluggable sink and consent controls (Changed: src/components/GlobalErrorCapture.tsx, src/lib/secureLogging.ts)
  2. [High] Restructure CI into parallel, cached jobs with required checks and a fast-feedback path #505 — [High] Restructure CI into parallel, cached jobs with required checks and a fast-feedback path (Changed: .github/workflows/ci.yml, playwright.config.ts, package.json, .github/workflows/coverage-badge.yml)
  3. [High] Add a merge-conflict-marker and duplicate-declaration guard to pre-commit and CI #506 — [High] Add a merge-conflict-marker and duplicate-declaration guard to pre-commit and CI (Changed: scripts/check-merge-debris.mjs, scripts/check-merge-debris.mjs, .lintstagedrc.js, scripts/check-merge-debris.mjs)
  4. [High] Upgrade PR previews with automated e2e, Lighthouse, visual diffs and a consolidated PR report comment #507 — [High] Upgrade PR previews with automated e2e, Lighthouse, visual diffs and a consolidated PR report comment (Changed: .github/workflows/preview-deploy.yml, playwright.config.ts, e2e/smoke/preview-smoke.spec.ts, scripts/build-preview-report.mjs)

Issues

Closes #504
Closes #505
Closes #506
Closes #507

@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@sundayjob996 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	.github/workflows/ci.yml
#	.github/workflows/coverage-badge.yml
#	package.json
#	playwright.config.ts
#	src/lib/secureLogging.ts
@james2177
james2177 merged commit 00f3db3 into stellar-vortex-protocol:main Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment