Skip to content

feat: scaffold native OpenAnalytics integration for EmDash - #1

Merged
christopherjnelson merged 1 commit into
mainfrom
feat/native-openanalytics-scaffold
Sep 30, 2026
Merged

christopherjnelson merged 1 commit into
mainfrom
feat/native-openanalytics-scaffold

Conversation

@christopherjnelson

Copy link
Copy Markdown
Member

EmDash administrators need a native plugin that keeps the OpenAnalytics read credential on the server and installs the browser tracker from the site's API-provided installation metadata. This PR establishes that foundation with @blackswampai/emdash-openanalytics; embedded analytics UI is deferred.

Implementation

  • Native openAnalytics() descriptor plus the named createPlugin() runtime factory, verified against published EmDash 1.0.1.
  • Generated settings for API URL, encrypted private read key, and tracking enabled. The hosted API default is centralized; self-hosted API path prefixes and returned tracker/collector URLs are supported.
  • An authenticated, administrator-only POST validation route calls GET /v1/read/site. The client provides typed contract validation, a five-second timeout, redirect refusal, and safe errors for credentials, permissions, billing compatibility, missing sites, rate limits, and service failures.
  • Successful validation stores public installation metadata bound to the configured API/credential fingerprint. Public rendering makes no read-API requests. Configuration changes or failed validation suppress tracking until a successful validation.
  • A native page:fragments hook emits a structured async head script with the returned public key and collector URL. Missing/unsafe install data and disabled tracking suppress output; a stable fragment key prevents duplicates.
  • Publishing scaffold, MIT license, installation/security documentation, upstream contract notes, and Node 22/24 CI. No npm publication workflow is included.

Validation

All 37 tests pass on Node 22 and Node 24, along with typecheck, oxlint, oxfmt, build, package export/runtime metadata verification, artifact credential scanning, and npm package dry run. Frozen-lockfile installation succeeds.

Tests include real HTTP transport and the published EmDash runtime, SQLite adapter, encrypted settings handlers, permission/CSRF enforcement, and fragment renderer. They cover credential redaction, malformed contracts, error classes, self-hosting, configuration changes, missing installation fields, failed revalidation, disabled tracking, and deduplication. An independent GPT-6-Luna Medium reviewer found no unresolved production-code findings.

Initial scope and operating requirements

Connection validation is exposed as a documented server route; a setup button and embedded analytics remain future work. The host must configure EMDASH_ENCRYPTION_KEY and render EmDashHead in the public layout. Installation metadata requires manual revalidation after rotation or origin changes, and statically rendered pages require rebuilding.

Approximately 495 production LOC, 720 test LOC, nine source modules, no additional runtime dependencies beyond the EmDash peer, and one OpenAnalytics endpoint.

@christopherjnelson
christopherjnelson marked this pull request as ready for review September 30, 2026 00:37
@christopherjnelson
christopherjnelson merged commit 219d490 into main Sep 30, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant