chore(analytics): configure posthog session replay masking (#1428)
* chore(analytics): configure posthog session replay masking Move session replay from the mask-everything default to pattern-based masking in lib/analytics/replay-masking.ts: currency-shaped text, person-/organisationsnummer (rendered and typed) and password inputs are masked; other interface text and typed input is recorded for debugging. data-ph-mask keeps force-masking tagged PII and data-ph-unmask is still honored for chrome. Privacy policy, RoPA and decision log updated to match. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore(analytics): address review comments on replay masking PR Bump the privacy policy's visible last-updated date to 2026-08-06 and add the conventional vi.clearAllMocks() beforeEach to the replay-masking tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
902b3ee986
commit
a5c10e441a
@@ -14,10 +14,10 @@ const Label = React.forwardRef<
|
||||
React.ComponentPropsWithoutRef<typeof LabelPrimitive.Root> &
|
||||
VariantProps<typeof labelVariants>
|
||||
>(({ className, ...props }, ref) => (
|
||||
// data-ph-unmask: form field labels are static i18n chrome, so session
|
||||
// replays show WHICH field is being filled in while the typed value stays
|
||||
// masked (see instrumentation-client.ts). A call site whose label text is
|
||||
// user data must add data-ph-mask, which wins over this default.
|
||||
// data-ph-unmask: form field labels are static i18n chrome, exempt from
|
||||
// the pattern-based replay masking (see lib/analytics/replay-masking.ts).
|
||||
// A call site whose label text is user data must add data-ph-mask, which
|
||||
// wins over this default.
|
||||
<LabelPrimitive.Root
|
||||
ref={ref}
|
||||
data-ph-unmask=""
|
||||
|
||||
Reference in New Issue
Block a user