fix(analytics): stop identifying Public visitors as page creators

Public generated pages were calling umami.identify(owner_id), collapsing
every visitor into the creator session. Anonymous visits now skip identify;
logged-in viewers identify with their own distinct id.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
john
2026-08-05 13:05:18 +08:00
parent 9e50681d96
commit e2014e05e6
4 changed files with 83 additions and 10 deletions
+17 -1
View File
@@ -68,6 +68,20 @@ export function resolveAnalyticsOwnerLabel(user = {}) {
return label.replace(/[\r\n\t]+/g, ' ').slice(0, 80) || '未命名用户';
}
export function buildViewerAnalyticsIdentity(viewer, config = {}) {
if (!viewer?.id) return null;
const distinctId = resolveAnalyticsIdentity(viewer.id, config);
if (!distinctId) return null;
return {
distinctId,
username: resolveAnalyticsOwnerLabel(viewer),
ownerSegment: resolveAnalyticsOwnerSegment(viewer),
planType: resolveAnalyticsPlan(viewer),
channel: 'public',
identityMode: config.identityMode === 'raw' ? 'raw' : 'pseudonymous',
};
}
export function buildProductAnalyticsContext({ config, user = null } = {}) {
if (!config?.enabled || !config.websiteId) return { enabled: false };
const distinctId = user?.id ? resolveAnalyticsIdentity(user.id, config) : '';
@@ -152,6 +166,7 @@ export function injectMindSpaceAnalytics(html, {
planType = 'unknown',
generatedAt = '',
channel = 'h5',
viewerIdentity = null,
config = resolveMindSpaceAnalyticsConfig(),
} = {}) {
const source = String(html ?? '');
@@ -167,7 +182,8 @@ export function injectMindSpaceAnalytics(html, {
`data-host-url="${config.hostPath}"`,
];
if (config.domains) attrs.push(`data-domains="${config.domains.replaceAll('"', '&quot;')}"`);
const block = `<script ${attrs.join(' ')} defer src="${config.scriptPath}"></script><script ${ANALYTICS_MARKER}>(function(){var d=${jsonForInlineScript(metadata)},seen={};function safeTarget(h){if(!h)return'';try{var u=new URL(h,location.href);return u.origin===location.origin?u.pathname:'external:'+u.hostname;}catch{return'';}}function t(n,x){if(!window.umami||typeof window.umami.track!=='function')return;var p=Object.assign({},d,{page_url:location.href,page_route:location.pathname,page_title:document.title},x||{});window.umami.track(n,p);}function identify(){if(!window.umami||typeof window.umami.identify!=='function')return;window.umami.identify(d.owner_id,{username:d.username,memind_page_url:location.href,owner_segment:d.owner_segment,plan_type:d.plan_type,channel:d.channel,surface:d.surface,identity_mode:d.identity_mode});}function pageview(){if(!window.umami||typeof window.umami.track!=='function')return;window.umami.track();}function once(n,x){if(seen[n])return;seen[n]=1;t(n,x);}function ready(){identify();pageview();document.addEventListener('click',function(e){var el=e.target&&e.target.closest?e.target.closest('a,button,[role="button"],[data-umami-event]'):null;if(!el)return;var custom=el.getAttribute('data-umami-event');var href=el.tagName==='A'?el.getAttribute('href')||'':'';t(custom||'page_click',{element:el.tagName.toLowerCase(),element_id:el.id||'',event_label:(custom||el.getAttribute('aria-label')||'').slice(0,100),target_path:safeTarget(href)});},{passive:true});document.addEventListener('submit',function(e){var form=e.target;t('page_form_submit',{form_id:form&&form.id||'',form_action:safeTarget(form&&form.getAttribute('action')||'')});},{passive:true});var marks=[25,50,75,90];function scroll(){var h=document.documentElement.scrollHeight-window.innerHeight;if(h<=0){once('page_scroll_100');return;}var pct=Math.round(window.scrollY/h*100);marks.forEach(function(m){if(pct>=m)once('page_scroll_'+m);});}window.addEventListener('scroll',scroll,{passive:true});setTimeout(function(){once('page_engaged_10s');},10000);setTimeout(function(){once('page_engaged_30s');},30000);scroll();}if(document.readyState==='loading'){document.addEventListener('DOMContentLoaded',ready,{once:true});}else{ready();}})();</script>`;
const viewerJson = viewerIdentity ? jsonForInlineScript(viewerIdentity) : 'null';
const block = `<script ${attrs.join(' ')} defer src="${config.scriptPath}"></script><script ${ANALYTICS_MARKER}>(function(){var d=${jsonForInlineScript(metadata)},v=${viewerJson},seen={};function safeTarget(h){if(!h)return'';try{var u=new URL(h,location.href);return u.origin===location.origin?u.pathname:'external:'+u.hostname;}catch{return'';}}function t(n,x){if(!window.umami||typeof window.umami.track!=='function')return;var p=Object.assign({},d,{page_url:location.href,page_route:location.pathname,page_title:document.title},x||{});window.umami.track(n,p);}function identifyViewer(){if(!v||!v.distinctId||!window.umami||typeof window.umami.identify!=='function')return;window.umami.identify(v.distinctId,{username:v.username||'',memind_page_url:location.href,owner_segment:v.ownerSegment||'',plan_type:v.planType||'',channel:v.channel||'public',surface:'generated_page',identity_mode:v.identityMode||'pseudonymous'});}function pageview(){if(!window.umami||typeof window.umami.track!=='function')return;window.umami.track();}function once(n,x){if(seen[n])return;seen[n]=1;t(n,x);}function ready(){identifyViewer();pageview();document.addEventListener('click',function(e){var el=e.target&&e.target.closest?e.target.closest('a,button,[role="button"],[data-umami-event]'):null;if(!el)return;var custom=el.getAttribute('data-umami-event');var href=el.tagName==='A'?el.getAttribute('href')||'':'';t(custom||'page_click',{element:el.tagName.toLowerCase(),element_id:el.id||'',event_label:(custom||el.getAttribute('aria-label')||'').slice(0,100),target_path:safeTarget(href)});},{passive:true});document.addEventListener('submit',function(e){var form=e.target;t('page_form_submit',{form_id:form&&form.id||'',form_action:safeTarget(form&&form.getAttribute('action')||'')});},{passive:true});var marks=[25,50,75,90];function scroll(){var h=document.documentElement.scrollHeight-window.innerHeight;if(h<=0){once('page_scroll_100');return;}var pct=Math.round(window.scrollY/h*100);marks.forEach(function(m){if(pct>=m)once('page_scroll_'+m);});}window.addEventListener('scroll',scroll,{passive:true});setTimeout(function(){once('page_engaged_10s');},10000);setTimeout(function(){once('page_engaged_30s');},30000);scroll();}if(document.readyState==='loading'){document.addEventListener('DOMContentLoaded',ready,{once:true});}else{ready();}})();</script>`;
if (/<\/head>/i.test(source)) return source.replace(/<\/head>/i, `${block}</head>`);
return source.replace(/<body\b/i, `${block}<body`);
}
+56 -9
View File
@@ -4,6 +4,7 @@ import vm from 'node:vm';
import {
buildProductAnalyticsContext,
buildViewerAnalyticsIdentity,
injectMindSpaceAnalytics,
pseudonymizeAnalyticsId,
resolveAnalyticsIdentity,
@@ -124,9 +125,10 @@ test('injects one local same-origin tracker with page dimensions', () => {
assert.match(out, /src="\/analytics\/script\.js"/);
assert.match(out, /data-host-url="\/analytics"/);
assert.match(out, /data-auto-track="false"/);
assert.match(out, /window\.umami\.identify\(d\.owner_id,\{username:d\.username,memind_page_url:location\.href,owner_segment:d\.owner_segment,plan_type:d\.plan_type,channel:d\.channel,surface:d\.surface,identity_mode:d\.identity_mode\}\)/);
assert.doesNotMatch(out, /umami\.identify\(d\.owner_id/);
assert.match(out, /function identifyViewer\(\)/);
assert.match(out, /identifyViewer\(\);pageview\(\)/);
assert.match(out, /function pageview\(\).*window\.umami\.track\(\)/);
assert.ok(out.indexOf('identify();pageview();') > 0);
assert.doesNotMatch(out, /t\('page_view'\)/);
assert.match(out, /page_id/);
assert.match(out, /owner_segment/);
@@ -143,7 +145,7 @@ test('injects one local same-origin tracker with page dimensions', () => {
assert.equal(injectMindSpaceAnalytics(out, { ownerId: 'user-123', config: { enabled: true, websiteId: 'local-website', idSecret: 'secret' } }), out);
});
test('identifies the pseudonymous owner before sending a standard page view', () => {
test('public visitors skip creator identify and only send a standard page view', () => {
const out = injectMindSpaceAnalytics('<!doctype html><html><head></head><body></body></html>', {
ownerId: 'user-123',
ownerSegment: 'plan:pro',
@@ -177,22 +179,67 @@ test('identifies the pseudonymous owner before sending a standard page view', ()
documentElement: { scrollHeight: 1600 },
addEventListener: () => {},
},
location: { href: 'https://m.tkmind.cn/MindSpace/demo/public/page.html' },
location: { href: 'https://m.tkmind.cn/MindSpace/demo/public/page.html', pathname: '/MindSpace/demo/public/page.html' },
setTimeout: () => {},
});
assert.deepEqual(JSON.parse(JSON.stringify(calls)), [['track']]);
});
test('logged-in public visitors identify themselves without using the page creator id', () => {
const viewerId = pseudonymizeAnalyticsId('viewer-456', 'secret');
const out = injectMindSpaceAnalytics('<!doctype html><html><head></head><body></body></html>', {
ownerId: 'user-123',
ownerLabel: '张三',
viewerIdentity: buildViewerAnalyticsIdentity(
{ id: 'viewer-456', displayName: '李四', role: 'user', planType: 'free' },
{ idSecret: 'secret', identityMode: 'pseudonymous' },
),
config: {
enabled: true,
websiteId: 'local-website',
idSecret: 'secret',
scriptPath: '/analytics/script.js',
hostPath: '/analytics',
},
});
const inlineScript = out.match(/<script data-memind-analytics="1">([\s\S]*?)<\/script>/)?.[1];
assert.ok(inlineScript);
const calls = [];
vm.runInNewContext(inlineScript, {
window: {
umami: {
identify: (...args) => calls.push(['identify', ...args]),
track: (...args) => calls.push(['track', ...args]),
},
innerHeight: 800,
scrollY: 0,
addEventListener: () => {},
},
document: {
readyState: 'complete',
title: 'Demo',
documentElement: { scrollHeight: 1600 },
addEventListener: () => {},
},
location: { href: 'https://m.tkmind.cn/MindSpace/demo/public/page.html', pathname: '/MindSpace/demo/public/page.html' },
setTimeout: () => {},
});
assert.deepEqual(JSON.parse(JSON.stringify(calls)), [
['identify', pseudonymizeAnalyticsId('user-123', 'secret'), {
username: '张三',
['identify', viewerId, {
username: '李四',
memind_page_url: 'https://m.tkmind.cn/MindSpace/demo/public/page.html',
owner_segment: 'plan:pro',
channel: 'h5',
owner_segment: 'plan:free',
plan_type: 'free',
channel: 'public',
surface: 'generated_page',
plan_type: 'unknown',
identity_mode: 'pseudonymous',
}],
['track'],
]);
assert.notEqual(viewerId, 'user-123');
});
test('does not alter non-full-html or disabled pages', () => {
@@ -6,6 +6,7 @@ import {
collectInlineScriptHashes,
} from '../mindspace-public-delivery.mjs';
import {
buildViewerAnalyticsIdentity,
injectMindSpaceAnalytics,
resolveAnalyticsOwnerLabel,
resolveAnalyticsOwnerSegment,
@@ -51,6 +52,7 @@ async function decoratePublicationHtmlAnalytics(
result,
analyticsConfig,
rybbitConfig,
viewer = null,
getAuthPool = () => null,
getUserAuth = () => null,
getMindSpacePages = () => null,
@@ -112,6 +114,7 @@ async function decoratePublicationHtmlAnalytics(
generatedAt: pageDataContext?.generatedAt ?? '',
pageId,
publicationId,
viewerIdentity: buildViewerAnalyticsIdentity(viewer, analyticsConfig),
config: analyticsConfig,
});
decorated = injectMindSpaceRybbit(decorated, {
@@ -215,6 +218,7 @@ export function createPortalPublishedPageDelivery({
result,
analyticsConfig,
rybbitConfig,
viewer: req.currentUser ?? null,
getAuthPool,
getUserAuth,
getMindSpacePages,
@@ -346,6 +350,7 @@ export function createPortalPublishedPageDelivery({
result,
analyticsConfig,
rybbitConfig,
viewer: req.currentUser ?? null,
getAuthPool,
getUserAuth,
getMindSpacePages,
@@ -1,4 +1,5 @@
import {
buildViewerAnalyticsIdentity,
injectMindSpaceAnalytics,
resolveAnalyticsOwnerLabel,
resolveAnalyticsOwnerSegment,
@@ -250,6 +251,10 @@ export function createPortalWorkspacePublicationDelivery({
pageDataContext?.publicationId ??
pageDataContext?.publication_id ??
'',
viewerIdentity: buildViewerAnalyticsIdentity(
req.currentUser ?? null,
analyticsConfig,
),
config: analyticsConfig,
});
html = injectMindSpaceRybbit(html, {