Skip to content

walkerOS v4.3.0

Choose a tag to compare

@github-actions github-actions released this 15 Jul 15:02
· 138 commits to main since this release
c9a8c9c

Changes

Click and submit triggers now fire in the capture phase, reading tagged elements
at click time. This fixes lost tagging in single-page apps where a click
re-renders and unmounts the tagged element (events previously fell back to
page with no data), and means stopPropagation no longer suppresses a tagged
click. Set capture: false on the source to restore the previous bubble-phase
behavior.

The browser source now supports a data-elbobserve attribute. Mark a container
with it and any tagged content a SPA injects into that container is
auto-registered for tracking, and cleaned up when removed, without calling
walker init after each injection. Works in light DOM and open shadow roots.

The browser source now supports a data-elbuser attribute to set persistent
user identity from the DOM. Tag any element with
data-elbuser="id:u123;loggedin:true" and the source applies it as collector
user state right before the page view, so the page view and every event after it
carry the user. Multiple elements merge, and an absent attribute leaves any
existing user untouched.

The elbLayer is append-only with guaranteed ordering: walker commands apply
immediately, events process in push order once the source starts, and entries
stay inspectable in the array. walker init now works from every entry point,
including elbLayer.push. The browser source owns window.elb (name via
settings.elb) and returns a result promise; the ELBLayer and
ELBLayerConfig types were removed.

The visible and impression triggers now fire for elements inside open shadow
DOM, and scroll depth is computed correctly for shadow-nested elements.
Visibility still accounts for occlusion across open shadow roots, so a genuinely
covered element does not trigger. Closed shadow subtrees can be tracked by
passing the closed root reference to walker init.

Fix a case where a visible / impression trigger could still fire shortly
after the source or its scope was destroyed. Pending visibility timers are now
cancelled during teardown.

Bundling a flow whose step package carries an inline version (e.g.
@walkeros/web-source-browser@2.1.0) no longer fails package resolution: the
version suffix is parsed and honored instead of being treated as part of the
package name, and an explicit config.bundle.packages pin still wins. The
elbPreview loader now activates previews via a script-element swap instead of a
CORS-bound fetch probe, so previews work on any site regardless of CDN CORS
headers. The flow runtime also buffers bundle archives fully before extraction,
fixing a rare boot crash when the download stream ended while extraction had it
paused.

Web bundles no longer assign window.elb; the browser source owns that global.
The windowElb setting is deprecated: its value is forwarded to the browser
source's config.settings.elb with a warning, so custom global names keep
working.

Unknown walker commands now log a warning and return ok: false instead of
silently succeeding. The elb function is exposed as collector.elb, a new
required field on Collector.Instance, replacing the internal sources.elb
pseudo-source.

Read-only code snippets now render their highlighted content during server-side
rendering instead of waiting for the browser, so code is visible on first paint
and in no-JS and search-engine contexts. CodeSnippet no longer ships the
Monaco editor for read-only display.

Consent Mode now sets the denied consent default before config, as Google
requires. Add como_advanced to enable advanced mode (default at page load with
wait_for_update) for non-EU setups. Sites that do not use consent are
unaffected.

Flow observation records now carry per-event journey correlation: a W3C
traceparent links a web send to the server flow that receives it, plus the
originating source id and a monotonic sequence that makes dropped telemetry
visible. At trace level, destinations can opt in to recording their outgoing
vendor calls.

The preview_regrant action now works over the CLI-backed MCP client: mint a
fresh, origin-bound activation grant for an existing preview, optionally bound
to an Observe session via sessionId. preview_create with a siteUrl now
mints a real activation grant instead of returning no activation URL.

Update the runtime Docker base image to Node.js 22.23.0, which patches the
Node.js June 2026 security release. The walkeros/flow and walkeros/cli
images now pin a fixed, digest-locked Node version.

Flow observation records now assemble into per-event journeys spanning web and
server flows, each hop showing input, output, and status, with loss flagged; the
observe_journeys MCP tool exposes the same journeys to agents. Batching
destinations now emit per-event records, and live-web vendor calls are captured
when a destination reaches its callable through getEnv, though batched sends
stay uncaptured.

With loadScript: true, site and collectDomain now reach the Piano SDK
reliably. Configuration is applied after the injected script loads, instead of
being silently skipped on a cold page. If the script fails to load (ad blocker,
network, CDN), a warning is logged rather than sending unconfigured events.

Preview links are now app-signed and bound to your site's origin, verified
locally in the bundle with no server round trip. Bundles that support preview
activation import a new browserSwapActivator from @walkeros/core. The CLI
wrap step's preview option replaces previewOrigin/previewScope, and a new
previewGrantTargets option lets a preview forward its grant to server-bound
destinations too.

Observe-session activation URLs now carry a companion session-forwarding grant
(elbPreviewSession). The browser activator stores it alongside the activation
grant, and seamed preview bundles use it to forward events to the session
container — so one preview link shows web and server journeys together.

Removed the experimental TagSkeleton, TagSkeletonOverlay, TagCanvas,
TagTreeEditor and Tag components, along with their layout and tag-tree
helpers. The draft tagging-plan visualization they prototyped is no longer part
of this package.

Events now carry per-flow config provenance on event.source.release, a
flow-name to release map that accumulates as an event crosses flows (web capture
to server processing), so a delivered event shows which config handled it. The
collector no longer stamps source.version (external source emitters may still
set it). In this first version, aws and gcp crossings are not yet covered.

The impression and visible triggers now count an element as seen when at
least half of it, or half of the viewport, whichever is smaller, is on screen
along each axis for one continuous second in a foreground tab. Elements larger
than the viewport now fire, where previously they could not, and elements are
detected reliably when a framework injects them before rendering. Expect an
increase in impression volume, particularly on small viewports and on pages with
tall sections.

walker init <element> now re-initializes a scope cleanly: visible and
impression triggers on elements in the re-initialized scope fire (previously
silent), and re-initializing the same scope no longer stacks duplicate pulse,
wait, hover, or visibility triggers. One-shot load triggers still fire on
each call.

The global Window.elbLayer type is now optional, matching reality: the queue
is absent until a source initializes it (the runtime already guards for this).
Code that reads window.elbLayer directly now correctly narrows it as possibly
undefined.

Published Packages