chore(analytics): configure posthog session replay masking (#1428)

* chore(analytics): configure posthog session replay masking

Move session replay from the mask-everything default to pattern-based
masking in lib/analytics/replay-masking.ts: currency-shaped text,
person-/organisationsnummer (rendered and typed) and password inputs are
masked; other interface text and typed input is recorded for debugging.
data-ph-mask keeps force-masking tagged PII and data-ph-unmask is still
honored for chrome. Privacy policy, RoPA and decision log updated to
match.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(analytics): address review comments on replay masking PR

Bump the privacy policy's visible last-updated date to 2026-08-06 and
add the conventional vi.clearAllMocks() beforeEach to the replay-masking
tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-08-06 11:40:54 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent 902b3ee986
commit a5c10e441a
7 changed files with 268 additions and 41 deletions
+4 -4
View File
@@ -14,10 +14,10 @@ const Label = React.forwardRef<
React.ComponentPropsWithoutRef<typeof LabelPrimitive.Root> &
VariantProps<typeof labelVariants>
>(({ className, ...props }, ref) => (
// data-ph-unmask: form field labels are static i18n chrome, so session
// replays show WHICH field is being filled in while the typed value stays
// masked (see instrumentation-client.ts). A call site whose label text is
// user data must add data-ph-mask, which wins over this default.
// data-ph-unmask: form field labels are static i18n chrome, exempt from
// the pattern-based replay masking (see lib/analytics/replay-masking.ts).
// A call site whose label text is user data must add data-ph-mask, which
// wins over this default.
<LabelPrimitive.Root
ref={ref}
data-ph-unmask=""