Skip to content

fix(analytics): drop browser-extension exceptions in before_send - #19814

Draft
posthog[bot] wants to merge 2 commits into
posthog-self-driving/fixanalytics-filter-unactionable-client-170e4bfrom
posthog-self-driving/fixanalytics-drop-dark-reader-extension-570fe1
Draft

fix(analytics): drop browser-extension exceptions in before_send#19814
posthog[bot] wants to merge 2 commits into
posthog-self-driving/fixanalytics-filter-unactionable-client-170e4bfrom
posthog-self-driving/fixanalytics-drop-dark-reader-extension-570fe1

Conversation

@posthog

@posthog posthog Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Changes

Problem

  • A browser extension (Dark Reader) makes error tracking open a fresh issue for every page a visitor loads — pure triage cost, no site defect. The fingerprint keys off the page URL, so each new URL mints a new issue nobody can fix.
  • The extension injects an inline script. When it throws, its one frame is global code at line 1 of the document URL and is marked in_app, so the event reads as a first-party site error.
  • before_send did not catch this shape. #19599 does not cover it either: its rule drops exceptions with no in_app frame, and this frame has in_app set.

Fix — extend the single before_send hook (gatsby/onPreBootstrap.ts), stacked on #19599:

Exception shape Action Reason
only frame is global code at line 1 of the document URL drop inline script injected by an extension; the site cannot fix it
any other single or multi frame keep real product errors load from separate script files, never inline

Our own code loads from separate .js files, so a frame whose filename is the page's own document URL is always injected script.

Agent context

Checklist

  • I've read the docs and/or content style guides.
  • Words are spelled using American English
  • Use relative URLs for internal links
  • I've checked the pages added or changed in the Vercel preview build
  • If I moved a page, I added a redirect in vercel.json

Created with PostHog Desktop from this inbox report.

Extensions like Dark Reader inject an inline script into the page. When
that script throws, its one frame is "global code" at line 1 of the
document URL and is marked in_app, so error tracking reads it as a
first-party error. The fingerprint keys off the page URL, so every new
page one of these visitors loads mints a fresh issue.

Add a before_send rule that drops any exception whose only frame is
"global code" at line 1 of the document URL. Our own code loads from
separate script files, never inline in the page, so this shape is always
extension noise.

Stacked on #19599, whose no-in_app-frame rule does not catch this case
because the injected frame has in_app set.

Generated-By: PostHog Desktop
Task-Id: 30ce005e-65dd-426a-a0d1-bd1f72c56259
@posthog

posthog Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor Author

🦔 PostHog Review reviewed this pull request

Found 1 must fix, 0 should fix, 0 consider.

Published 1 finding (view the review).

Resolved comments: 1 fixed

@github-actions github-actions Bot added the website About the website (beyond just landing pages) label Aug 29, 2026
@github-actions

github-actions Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Deploy preview

Status Details Updated (UTC)
🟢 Ready View preview Aug 29, 2026 02:21AM

@posthog

posthog Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor Author

PostHog Review alpha 🦔 If you find any issues helpful - please reply "valid", "invalid", etc., for evaluation purposes 🙏

@posthog posthog Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PostHog Review

Found 1 must fix.

Comment thread gatsby/onPreBootstrap.ts Outdated
@github-actions

github-actions Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Bundle report

Total JS (gzip)

8.15 MiB (+0.7 KiB / +0.0%)

Eager graph (modules shipped in each entrypoint's initial chunks)

Entrypoint Eager size Budget Modules
app 16.91 MiB (no change) report-only 2036
Largest modules in the app closure
Module Size
./src/data/mcp-tools.json 1053.9 KiB
css ./node_modules/.pnpm/css-loader@5.2.7_webpack@5.101.3/node_modules/css-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[1]!./node_modules/.pnpm/postcss-loader@4.3.0_postcss@8.5.6_webpack@5.101.3/node_modules/postcss-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[2]!./src/styles/global.css 754.5 KiB
./src/components/Stickers/Stickers.tsx 696.4 KiB
./node_modules/.pnpm/@radix-ui+react-icons@1.3.2_react@18.3.1/node_modules/@radix-ui/react-icons/dist/react-icons.esm.js 481.4 KiB
./node_modules/.pnpm/rehype-raw@7.0.0/node_modules/rehype-raw/lib/index.js + 29 modules 395.1 KiB
./src/hooks/useCustomers.tsx + 55 modules 370.0 KiB
./node_modules/.pnpm/@posthog+icons@0.36.6_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js 354.8 KiB
./node_modules/.pnpm/react-markdown@8.0.7_@types+react@16.14.66_react@18.3.1/node_modules/react-markdown/lib/react-markdown.js + 88 modules 351.4 KiB
./src/components/ProductComparisonTable/index.tsx + 126 modules 301.7 KiB
./node_modules/.pnpm/cloudinary-core@2.14.0_lodash@4.17.21/node_modules/cloudinary-core/cloudinary-core.js 281.9 KiB
./src/components/SearchUI/index.tsx + 87 modules 273.0 KiB
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/magnifying-glass.mjs 254.7 KiB
./node_modules/.pnpm/framer-motion@10.18.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/framer-motion/dist/es/render/dom/motion.mjs + 109 modules 253.9 KiB
./node_modules/.pnpm/d3@7.9.0/node_modules/d3/src/index.js + 208 modules 247.4 KiB
./src/components/Pricing/PricingSlider/Slider.tsx + 87 modules 240.1 KiB

Eager-graph budgets are report-only until a baseline is established. Sizes are gzip of public/**/*.js; eager size is webpack module source bytes for the modules actually shipped in the entrypoint's initial chunks (post-tree-shake).

…d JS

The `before_send` document-URL guard used `.replace(/\/$/, '')` inside the
`posthogScript` template literal. Because `\/` is not a recognized escape
sequence, the template literal dropped the backslash, so the emitted
static/scripts/posthog-init.js contained `.replace(//$/, '')` — `//` starts a
line comment and the `.replace(` call never closes, making the whole file a
syntax error. The browser would discard posthog-init.js, so posthog never
initialized (analytics, error tracking, flags, session replay all broken).

Escape the backslash (`/\\/$/`) in both occurrences so the generated file
contains the intended `/\/$/` regex. Verified with node that both emitted
lines parse and that the regex still strips a single trailing slash.

Generated-By: PostHog Desktop
Task-Id: f94556e3-6d05-4e30-a26b-d83e8e61f44e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

website About the website (beyond just landing pages)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants