Releases: multiplehats/trakoo
Release list
trakoo@2.0.0
Major Changes
-
Move the SDK-backed providers into their own packages so installing one provider never involves another provider's SDK (#43)
Core declared every provider SDK as an optional peer. npm checks an optional peer whenever that package is already installed, so an OpenPanel user who had
posthog-node@4for unrelated reasons could not install trakoo at all (ERESOLVE ... peerOptional posthog-node@"^5.9.0"). The PostHog config types re-exported fromtrakoo/clientandtrakoo/serveralso failed to resolve underskipLibCheck: falseunless PostHog was installed.Core now declares no provider SDK. Install the adapter for each SDK-backed provider next to its SDK:
Provider Before After PostHog trakoo/providers/client,trakoo/providers/server,trakoo/client,trakoo/server@trakoo/posthog/client,@trakoo/posthog/serverOpenPanel trakoo/providers/client,trakoo/providers/server@trakoo/openpanel/client,@trakoo/openpanel/serverBento (server) trakoo/providers/server@trakoo/bento/serverEmitKit trakoo/providers/server@trakoo/emitkit/serverThe provider config types moved with their providers:
PostHogClientConfig,PostHogConfig,PostHogOptions,OpenPanelClientConfig,OpenPanelServerConfig, the OpenPanel delivery-failure types,BentoServerConfig,BentoAnalyticsOptionsandEmitKitServerConfig. Bento's browser provider, Pirsch, Visitors and the proxy need no SDK and stay intrakoo/providers/*.BaseAnalyticsProvideris now also exported from the roottrakooentry.
Patch Changes
- Pirsch's synthetic identify and session-reset hits now send the user agent
trakooinstead ofstacksee-analytics. (#43)
@trakoo/posthog@1.0.0
Major Changes
-
First release of the PostHog providers as their own package, moved out of trakoo core. Import
PostHogClientProviderfrom@trakoo/posthog/clientandPostHogServerProviderfrom@trakoo/posthog/server. (#43)Changes from the trakoo 1.x providers:
- Server events without a user no longer share one
"anonymous"person. Each gets its own distinct ID and$process_person_profile: false, as PostHog recommends, so anonymous traffic stops accumulating on a single person and unique-user counts change. - Server events forward the visitor's IP and user agent (
context.server, falling back tocontext.device) as$ipand$raw_user_agent, the page as$current_url(page.url, falling back topage.path), and the campaign asutm_source,utm_mediumandutm_campaign. GeoIP runs on events that carry a visitor IP unlessdisableGeoipis set. The IP is no longer stored inside thedeviceproperty. - Server events carry trakoo's event time as the PostHog event timestamp instead of a
timestampproperty. - The server provider's default host is PostHog's US ingestion host,
https://us.i.posthog.com, instead of the legacyhttps://app.posthog.com. EU projects still sethost. - Browser events keep posthog-js's own full, current
$current_urlinstead of replacing it with the path from the lastpageView().
- Server events without a user no longer share one
Patch Changes
@trakoo/openpanel@1.0.0
Major Changes
-
First release of the OpenPanel providers as their own package, moved out of trakoo core. Import
OpenPanelClientProviderfrom@trakoo/openpanel/clientandOpenPanelServerProviderfrom@trakoo/openpanel/server. (#43)Changes from the trakoo 1.x providers:
- A caller IP or user agent that cannot be sent as an HTTP header, such as one containing a line break, is skipped instead of making the server event retry and then fail as a network error. The proxy passes a browser-supplied
device.userAgentthrough when the request has no user agent header, so a client could trigger this. Adevice.ipthat cannot be sent is removed from the event'sdeviceproperties, as a valid one already was, instead of being stored there. - The server provider passes only its documented options to the SDK. An untyped
waitForProfileordisabledcould previously queue events on the shared client and attribute one request's events to another user. - Both providers warn once at initialization when the installed SDK's transport is not recognized, instead of silently losing delivery-failure reporting and caller attribution.
- A caller IP or user agent that cannot be sent as an HTTP header, such as one containing a line break, is skipped instead of making the server event retry and then fail as a network error. The proxy passes a browser-supplied
Patch Changes
@trakoo/emitkit@1.0.0
Major Changes
-
First release of the EmitKit provider as its own package, moved out of trakoo core. Import
EmitKitServerProviderfrom@trakoo/emitkit/server. (#43)Changes from the trakoo 1.x provider:
- Requires
@emitkit/js3. - The visitor's IP address is removed from the
deviceandservermetadata, so it no longer appears in the EmitKit feed and its notifications. - A non-string
emailtrait is no longer sent as an alias, which EmitKit rejected. - Duplicate tags are removed.
- Requests time out after 5 seconds by default, as documented, instead of the SDK's 30 seconds, and the SDK's retries are turned off so a call never waits longer than that.
- Events are labeled
source: "trakoo"instead of"stacksee-analytics". - Failure logs include the EmitKit error code, HTTP status and request ID.
- Requires
Patch Changes
@trakoo/bento@1.0.0
Major Changes
-
First release of the Bento server provider as its own package, moved out of trakoo core. Import
BentoServerProviderfrom@trakoo/bento/server; Bento's browser provider stays intrakoo/providers/client. Supports@bentonow/bento-node-sdk0.2 and 2.x. (#43)Changes from the trakoo 1.x provider:
identify()updates the subscriber's fields with$update_fieldsinstead of sending$subscribe, which subscribed the person to marketing email and re-ran subscribe automations on every call. Call Bento'sV1.addSubscriber()directly to subscribe someone.track()sends the event time as Bento's eventdate.- An event that Bento accepts without queueing is logged as a failure instead of as tracked.
Patch Changes
trakoo@1.2.1
Patch Changes
-
Ship the OpenPanel transport declarations again (#40)
REQUEST_CONTEXTwas declared without an explicit type, whichisolatedDeclarationsrejects, so the declaration build droppedproviders/openpanel/transport.d.tsfrom 1.2.0.providers/client.d.tsandproviders/server.d.tsstill imported it, soOpenPanelDeliveryFailureHandlerresolved to an implicitanyand anonDeliveryFailurecallback failed to type-check undernoImplicitAny.vite buildexits 0 when the declaration plugin rejects a file, soverify:packagenow asserts that every relative import in the packed declarations resolves to a file that was actually emitted.
trakoo@1.2.0
Minor Changes
-
Forward the caller's IP and user agent on OpenPanel server events (#38)
A server event carries the server's own IP and user agent, so OpenPanel attributed every one of them to the datacenter rather than to the caller, and geo and device were unusable.
OpenPanelServerProvidernow promotescontext.server.ipandcontext.server.userAgent(falling back tocontext.device) to theopenpanel-client-ipanduser-agentheaders OpenPanel resolves them from.Attribution is per event rather than per client, so a single long-lived provider stays correct across concurrent requests — OpenPanel's own server integrations build a client per request and mutate its headers, which a shared provider cannot do safely. The IP is sent as a header only; a
device.ippassed in context is no longer stored as an event property.
trakoo@1.1.0
Minor Changes
-
Report the full page URL from the browser adapter so campaign parameters survive.
BrowserAnalyticsbuilt its page context fromwindow.location.pathnamealone, so the query string never left the browser and everyutm_source/utm_medium/utm_campaignvalue was dropped before delivery — campaign traffic arrived in the dashboard as direct. The adapter now also populates theurl,search,hostandprotocolfields thatEventContext["page"]already declared, from a singlegetPageContext()snapshot shared byinitialize()andpageView(). (#37)updateContext()also merges the page snapshot instead of rebuilding it frompath,titleandreferrer, which had silently discarded every other declared field. Without that, only the immediatepageView()call carried a URL —track()andpageLeave()read the stored context and still saw none. Partial page updates now merge rather than erase, and an emptysearchis kept as a real value so a URL with no query string cannot inherit the previous page's parameters.This reaches any provider that reports a URL. OpenPanel, Bento, EmitKit, Pirsch and the proxy all read
context.page.urland fall back tocontext.page.path; until now that fallback was always taken. OpenPanel'sscreenView()consequently receives the full URL, which is what its own SDK sends when it tracks screen views itself, so its__pathchanges from a bare pathname to an absolute URL and its dashboard resolves the path and domain server-side. OpenPanel'sscreenView()also dedupes on the value it is handed, so two visits to one pathname under different query strings are now distinct: an app that callspageView()when query parameters change — filters, pagination, tabs — emits onescreen_viewper change where it previously emitted one in total. Expect page-view counts on those routes to rise.Nothing new is collected — the query string was always present in the browser — but a site that puts sensitive values in query parameters now sends them to its analytics provider, so exclude those before they reach the URL.
-
Report OpenPanel delivery failures instead of dropping them. OpenPanel's SDKs answer an HTTP 401 by returning
nullwithout throwing, retrying or logging, so a wrong client ID, a rotated secret or a browser origin the project does not allow stopped analytics silently. Both OpenPanel providers now acceptonDeliveryFailureand log rejections when no handler is configured. The failure reports the reason, status, attempt count, envelope type and ingestion URL, never event properties, and delivery still resolves so a rejected event never becomes an application error. (#34)
trakoo@1.0.0
Major Changes
-
Publish provider SDKs as optional peer dependencies and load them only when (
107774a)
their provider initializes. Trakoo no longer auto-installs or bundles unused
PostHog, OpenPanel, Bento, or EmitKit SDKs. -
Replace the proxy wire format with version 2. Proxy track events now carry raw (
1fceb0b)
registry input for server-side validation, and server identity must be derived
withresolveIdentityinstead of trusting browser claims. -
Replace type-asserted event collections with runtime
defineEvents()registries based on Standard Schema. Add direct validator interoperability, validator-freetyped<T>()events, propertyless events, inferred client/server factories, normalized validation failures, and validated provider outputs. Servertrack()calls now fail closed with the newinvalid_optionscode when the options argument contains an unrecognized key, and Proxy replay no longer re-runs Standard Schema validators against already-validated client output. This removes the legacy event helper types and client singleton convenience API; see the Standard Schema migration guide. (#32)
Minor Changes
- Add bounded proxy request parsing, batch limits, authorization and admission (
8090859)
hooks, and typed HTTP errors for malformed or rejected analytics requests.
Patch Changes
-
Initialize each PostHog browser provider with its own named SDK object, (
133e341)
isolating live configuration and identify, capture, and reset method dispatch
while preserving PostHog's token- andpersistence_name-based storage
semantics. -
Attribute PostHog server page views to user identity supplied on the current (
a5b579b)
call instead of always recording them as anonymous. -
Retain proxy events until transport acceptance, serialize concurrent flushes, (
e4e4a96)
bound batch latency from the first event, and await in-flight delivery during
shutdown. -
Wait for asynchronous provider initialization before dispatching first-use (
9504d75)
client and server analytics operations, and allow initialization retry after a
transient failure. -
Treat regex metacharacters literally in provider event patterns while (
5d4af5c)
preserving*as the only routing wildcard. -
Stop provider debug logs from serializing configuration, identity, event (
b1d124a)
properties, context, and external SDK error objects. -
Snapshot browser identity, session, context, and timestamp when
track()is (19f1819)
called so asynchronous initialization or validation cannot reattribute an event. -
Prevent Bento and EmitKit server providers from retaining one request's user (
6772c8f)
identity for later events. Server events now use only identity supplied on the
current call.