feat: add telemetry to web setup wizard
This commit is contained in:
@@ -38,6 +38,7 @@ interface WizardConfig {
|
||||
// Security
|
||||
sessionSecret: string;
|
||||
settingsSyncEnabled: boolean;
|
||||
telemetryEnabled: boolean;
|
||||
// Logging
|
||||
logFormat: 'text' | 'json';
|
||||
logLevel: 'error' | 'warn' | 'info' | 'debug';
|
||||
@@ -66,6 +67,7 @@ const EMPTY_CONFIG: WizardConfig = {
|
||||
oauthIssuerUrl: '',
|
||||
sessionSecret: '',
|
||||
settingsSyncEnabled: true,
|
||||
telemetryEnabled: false,
|
||||
logFormat: 'text',
|
||||
logLevel: 'info',
|
||||
faviconUrl: '',
|
||||
@@ -1002,8 +1004,11 @@ function SecurityStep({ config, setConfig, onNext, onBack }: Pick<StepProps, 'co
|
||||
e.preventDefault();
|
||||
setSubmitting(true);
|
||||
try {
|
||||
const values: Partial<WizardConfig> = {
|
||||
// telemetryConsent is persisted to the telemetry state file by the API,
|
||||
// not to admin config - see app/api/setup/step/route.ts.
|
||||
const values: Record<string, unknown> = {
|
||||
settingsSyncEnabled: config.settingsSyncEnabled,
|
||||
telemetryConsent: config.telemetryEnabled ? 'on' : 'off',
|
||||
};
|
||||
if (config.sessionSecret) values.sessionSecret = config.sessionSecret;
|
||||
await onNext('security', values);
|
||||
@@ -1068,6 +1073,15 @@ function SecurityStep({ config, setConfig, onNext, onBack }: Pick<StepProps, 'co
|
||||
hint="Stores user preferences server-side, encrypted with the session secret."
|
||||
disabled={!config.sessionSecret}
|
||||
/>
|
||||
|
||||
<div className="rounded-md border border-border bg-muted/20 p-3">
|
||||
<Toggle
|
||||
checked={config.telemetryEnabled}
|
||||
onChange={(v) => setConfig({ ...config, telemetryEnabled: v })}
|
||||
label="Send anonymous usage stats to help improve Bulwark"
|
||||
hint="Off by default. One anonymous heartbeat per day with version, platform, and which features are enabled - never email addresses, hostnames, or IPs. You can change this anytime in admin settings."
|
||||
/>
|
||||
</div>
|
||||
<Footer>
|
||||
<SecondaryButton onClick={onBack}>Back</SecondaryButton>
|
||||
<PrimaryButton type="submit" disabled={submitting}>
|
||||
@@ -1480,6 +1494,7 @@ function ReviewStep({ config, onBack, onFinish }: { config: WizardConfig; onBack
|
||||
: 'Off'
|
||||
}
|
||||
/>
|
||||
<SummaryRow label="Anonymous telemetry" value={config.telemetryEnabled ? 'On' : 'Off'} />
|
||||
</SummaryGroup>
|
||||
|
||||
<SummaryGroup icon={<FileText className="w-4 h-4" />} title="Logging">
|
||||
|
||||
@@ -4,6 +4,7 @@ import { authenticateWizardRequest } from '@/lib/setup/session';
|
||||
import { configManager } from '@/lib/admin/config-manager';
|
||||
import { CONFIG_ENV_MAP } from '@/lib/admin/types';
|
||||
import { parseJmapServers } from '@/lib/admin/jmap-servers';
|
||||
import { effectiveConsent, loadState, saveState, reschedule } from '@/lib/telemetry';
|
||||
import { logger } from '@/lib/logger';
|
||||
|
||||
export const dynamic = 'force-dynamic';
|
||||
@@ -76,8 +77,32 @@ export async function POST(request: NextRequest) {
|
||||
return NextResponse.json({ error: 'values must be an object' }, { status: 400 });
|
||||
}
|
||||
|
||||
const valuesObj = { ...(values as Record<string, unknown>) };
|
||||
|
||||
// Telemetry consent lives in the telemetry state file, not admin config, so
|
||||
// it has no CONFIG_ENV_MAP entry. Pull it out of the security step and
|
||||
// persist it directly, mirroring POST /api/admin/telemetry (set-consent).
|
||||
if (step === 'security' && 'telemetryConsent' in valuesObj) {
|
||||
const consent = valuesObj.telemetryConsent;
|
||||
delete valuesObj.telemetryConsent;
|
||||
if (consent !== 'on' && consent !== 'off') {
|
||||
return NextResponse.json({ error: 'telemetryConsent must be "on" or "off"' }, { status: 400 });
|
||||
}
|
||||
// A BULWARK_TELEMETRY env var hard-locks the choice; don't fight it.
|
||||
const { source } = await effectiveConsent();
|
||||
if (source !== 'env') {
|
||||
const tstate = await loadState();
|
||||
tstate.consent = consent;
|
||||
if (consent === 'on' && !tstate.consentedAt) {
|
||||
tstate.consentedAt = new Date().toISOString();
|
||||
}
|
||||
await saveState(tstate);
|
||||
await reschedule();
|
||||
}
|
||||
}
|
||||
|
||||
const updates: Record<string, unknown> = {};
|
||||
for (const [key, value] of Object.entries(values as Record<string, unknown>)) {
|
||||
for (const [key, value] of Object.entries(valuesObj)) {
|
||||
if (!allowedKeys.includes(key)) {
|
||||
return NextResponse.json({ error: `Key not allowed in step ${step}: ${key}` }, { status: 400 });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user