f8db38f989
* fix(analytics): mask session replays by default, chrome-only unmask Invert PostHog session-replay masking from visible-by-default with pattern masking to deny-by-default: every input value is masked wholesale (rrweb maskAllInputs, no maskInputFn) and every text node is masked unless it sits under data-ph-unmask chrome or a table column header (th). Chrome tags live on the shared UI primitives (PageHeader, Label, Button except combobox triggers, TabsTrigger, Badge, Card/Dialog/Sheet titles, tooltips, help popovers, empty states, settings labels), and tagged chrome is still pattern-scrubbed for amounts and person-/organisationsnummer. data-ph-mask beats data-ph-unmask, so call sites that interpolate user data into chrome stay masked; a very-thorough audit swept every unmasked primitive and each found site got a call-site mask. Confirm-dialog wrappers and toasts stay masked centrally: their copy describes user objects by design. Untagged new UI over-masks instead of leaking. Privacy policy, RoPA and decision log updated in the same change. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(analytics): tag detail-section chrome merged from main The register-detail primitives landed on main after the replay-masking audit ran: kickers and DefRow labels are static i18n chrome, values stay masked. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(analytics): close skeptic and review findings on replay masking Explicit data-ph tags now resolve before the th chrome fallback, so a th nested inside a data-ph-mask container masks correctly (regression test added). Seven missed text-leak sites get call-site masks: delete-invoice and credit-page invoice numbers, IB-correction voucher reference, TIC orgnr (served unnormalized, so the separator-based scrub cannot be relied on), articles search-term empty state, dimension segment labels, and activate-account buttons. The attribute channel is closed with rrweb's blockClass: inputs whose placeholder carries an effective user value (salary overrides, correction description, danger-zone confirms, credit confirm) get ph-no-capture, removing the element from recordings while the prefill UX stays intact; the pivot-th title attribute is dropped. Privacy-policy effective date bumped to 2026-08-17. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
135 lines
5.1 KiB
TypeScript
135 lines
5.1 KiB
TypeScript
"use client"
|
|
|
|
import * as React from "react"
|
|
import * as ToastPrimitives from "@radix-ui/react-toast"
|
|
import { cva, type VariantProps } from "class-variance-authority"
|
|
import { X } from "lucide-react"
|
|
import { cn } from "@/lib/utils"
|
|
|
|
const ToastProvider = ToastPrimitives.Provider
|
|
|
|
const ToastViewport = React.forwardRef<
|
|
React.ElementRef<typeof ToastPrimitives.Viewport>,
|
|
React.ComponentPropsWithoutRef<typeof ToastPrimitives.Viewport>
|
|
>(({ className, ...props }, ref) => (
|
|
<ToastPrimitives.Viewport
|
|
ref={ref}
|
|
className={cn(
|
|
"fixed top-0 z-[100] flex max-h-screen w-full flex-col p-4 sm:top-4 sm:right-4 sm:bottom-auto sm:flex-col md:max-w-[420px]",
|
|
className
|
|
)}
|
|
{...props}
|
|
/>
|
|
))
|
|
ToastViewport.displayName = ToastPrimitives.Viewport.displayName
|
|
|
|
const toastVariants = cva(
|
|
"group pointer-events-auto relative flex w-full items-center justify-between space-x-4 overflow-hidden rounded-lg border p-6 pr-8 shadow-lg transition-all data-[swipe=cancel]:translate-x-0 data-[swipe=end]:translate-x-[var(--radix-toast-swipe-end-x)] data-[swipe=move]:translate-x-[var(--radix-toast-swipe-move-x)] data-[swipe=move]:transition-none data-[state=open]:animate-in data-[state=closed]:animate-out data-[swipe=end]:animate-out data-[state=closed]:fade-out-0 max-sm:data-[state=open]:slide-in-from-top-full max-sm:data-[state=closed]:slide-out-to-top-full sm:data-[state=open]:slide-in-from-right-full sm:data-[state=closed]:slide-out-to-right-full",
|
|
{
|
|
variants: {
|
|
variant: {
|
|
default: "border bg-background text-foreground",
|
|
destructive:
|
|
"destructive group border-destructive bg-destructive text-destructive-foreground",
|
|
success:
|
|
"border-success bg-success text-success-foreground",
|
|
},
|
|
},
|
|
defaultVariants: {
|
|
variant: "default",
|
|
},
|
|
}
|
|
)
|
|
|
|
const Toast = React.forwardRef<
|
|
React.ElementRef<typeof ToastPrimitives.Root>,
|
|
React.ComponentPropsWithoutRef<typeof ToastPrimitives.Root> &
|
|
VariantProps<typeof toastVariants>
|
|
>(({ className, variant, ...props }, ref) => {
|
|
return (
|
|
<ToastPrimitives.Root
|
|
ref={ref}
|
|
className={cn(toastVariants({ variant }), className)}
|
|
{...props}
|
|
/>
|
|
)
|
|
})
|
|
Toast.displayName = ToastPrimitives.Root.displayName
|
|
|
|
const ToastAction = React.forwardRef<
|
|
React.ElementRef<typeof ToastPrimitives.Action>,
|
|
React.ComponentPropsWithoutRef<typeof ToastPrimitives.Action>
|
|
>(({ className, ...props }, ref) => (
|
|
<ToastPrimitives.Action
|
|
ref={ref}
|
|
className={cn(
|
|
"inline-flex h-8 shrink-0 items-center justify-center rounded-full border bg-transparent px-3 text-sm font-medium ring-offset-background transition-colors hover:bg-secondary focus:outline-none focus:ring-2 focus:ring-ring focus:ring-offset-2 disabled:pointer-events-none disabled:opacity-50 group-[.destructive]:border-muted/40 group-[.destructive]:hover:border-destructive/30 group-[.destructive]:hover:bg-destructive group-[.destructive]:hover:text-destructive-foreground group-[.destructive]:focus:ring-destructive",
|
|
className
|
|
)}
|
|
{...props}
|
|
/>
|
|
))
|
|
ToastAction.displayName = ToastPrimitives.Action.displayName
|
|
|
|
const ToastClose = React.forwardRef<
|
|
React.ElementRef<typeof ToastPrimitives.Close>,
|
|
React.ComponentPropsWithoutRef<typeof ToastPrimitives.Close>
|
|
>(({ className, ...props }, ref) => (
|
|
<ToastPrimitives.Close
|
|
ref={ref}
|
|
className={cn(
|
|
"absolute right-2 top-2 rounded-sm p-1 text-foreground/50 opacity-0 transition-opacity hover:text-foreground focus:opacity-100 focus:outline-none focus:ring-2 group-hover:opacity-100 group-[.destructive]:text-red-300 group-[.destructive]:hover:text-red-50 group-[.destructive]:focus:ring-red-400 group-[.destructive]:focus:ring-offset-red-600",
|
|
className
|
|
)}
|
|
toast-close=""
|
|
{...props}
|
|
>
|
|
<X className="h-4 w-4" />
|
|
</ToastPrimitives.Close>
|
|
))
|
|
ToastClose.displayName = ToastPrimitives.Close.displayName
|
|
|
|
const ToastTitle = React.forwardRef<
|
|
React.ElementRef<typeof ToastPrimitives.Title>,
|
|
React.ComponentPropsWithoutRef<typeof ToastPrimitives.Title>
|
|
>(({ className, ...props }, ref) => (
|
|
// Deliberately NOT data-ph-unmask: toast titles and descriptions
|
|
// interpolate user data (deadline titles, account names) at too many call
|
|
// sites to audit, so toasts stay masked in session replays. The variant
|
|
// styling still shows success/failure in the replay.
|
|
<ToastPrimitives.Title
|
|
ref={ref}
|
|
className={cn("text-sm font-semibold", className)}
|
|
{...props}
|
|
/>
|
|
))
|
|
ToastTitle.displayName = ToastPrimitives.Title.displayName
|
|
|
|
const ToastDescription = React.forwardRef<
|
|
React.ElementRef<typeof ToastPrimitives.Description>,
|
|
React.ComponentPropsWithoutRef<typeof ToastPrimitives.Description>
|
|
>(({ className, ...props }, ref) => (
|
|
<ToastPrimitives.Description
|
|
ref={ref}
|
|
className={cn("text-sm opacity-90", className)}
|
|
{...props}
|
|
/>
|
|
))
|
|
ToastDescription.displayName = ToastPrimitives.Description.displayName
|
|
|
|
type ToastProps = React.ComponentPropsWithoutRef<typeof Toast>
|
|
|
|
type ToastActionElement = React.ReactElement<typeof ToastAction>
|
|
|
|
export {
|
|
type ToastProps,
|
|
type ToastActionElement,
|
|
ToastProvider,
|
|
ToastViewport,
|
|
Toast,
|
|
ToastTitle,
|
|
ToastDescription,
|
|
ToastClose,
|
|
ToastAction,
|
|
}
|