fix(plugins): stop the TypeScript telemetry losing events and misattributing accounts (#7358)

This commit is contained in:
Saket Aryan
2026-09-18 14:13:22 +05:30
committed by GitHub
parent 1a5c7ad28c
commit a8d3634312
13 changed files with 623 additions and 29 deletions
+22 -5
View File
@@ -25,7 +25,9 @@ const PLUGIN_VERSION = (() => {
let currentDistinctId = "";
const telemetry = createTelemetry({
host: "opencode",
source: "plugin",
// Shaped like the platform's EventSource values, as every other surface is.
// "plugin" said nothing about which plugin and matched no vocabulary.
source: "OPENCODE_PLUGIN",
version: PLUGIN_VERSION,
distinctId: () => currentDistinctId,
eventName: (event) => `plugin.${event}`,
@@ -40,8 +42,23 @@ function distinctId(apiKey: string): string {
return createHash("sha256").update(apiKey).digest("hex").slice(0, 32);
}
function projectHash(projectId?: string): Record<string, string> {
return projectId ? { project_hash: createHash("sha256").update(projectId).digest("hex") } : {};
/**
* Salted so the hash is not enumerable.
*
* An unsalted SHA-256 of a project id is reversible by anyone who can guess the
* id, which for a project identifier is a small space. The API key is the salt:
* it is already in play here (distinctId is a digest of it), it is high entropy,
* and using it needs no per-install file and so no write race to get wrong. The
* hash is therefore per account rather than per machine, which also keeps joins
* working for one user across machines. It resets when the key rotates, which is
* consistent, because distinctId resets with it.
*
* Both are omitted without a key. An event cannot be built without a distinctId
* anyway, so this costs nothing.
*/
function projectHash(projectId?: string, apiKey?: string): Record<string, string> {
if (!projectId || !apiKey) return {};
return { project_hash: createHash("sha256").update(`${apiKey}:${projectId}`).digest("hex") };
}
export function buildEvent(
@@ -51,7 +68,7 @@ export function buildEvent(
projectId?: string,
): Record<string, unknown> | null {
currentDistinctId = apiKey ? distinctId(apiKey) : "";
const event = telemetry.build(eventType, { ...properties, ...projectHash(projectId) });
const event = telemetry.build(eventType, { ...properties, ...projectHash(projectId, apiKey) });
return event ? { api_key: POSTHOG_API_KEY, ...event } : null;
}
@@ -62,5 +79,5 @@ export function captureEvent(
projectId?: string,
): void {
currentDistinctId = apiKey ? distinctId(apiKey) : "";
telemetry.capture(eventType, { ...properties, ...projectHash(projectId) });
telemetry.capture(eventType, { ...properties, ...projectHash(projectId, apiKey) });
}