v1.22.0
frontend-production-engineer v1.22.0
The domain added is 23 analytics-privacy-and-consent — Tier 4
non-functional, and it is not blocking. It is the last of the twenty-four.
What landed
Three reference files. The split is the moment at which an agent reaches for
the material, and not the sections of the research. Adding a tracking call,
building a cookie banner, and shipping an export or a deletion screen are three
moments. One file would have made a task that adds one event load the consent
categories, the Sec-GPC header, the cookie inventory, and the data subject
flows as well.
references/event-taxonomy-and-tracking-plan.md— the measurement that a
product takes of itself. One module holds the vendor, so a vendor change
edits one file and a component test emits nothing. A discriminated union is
the tracking plan, so an event outside it fails the typecheck rather than
splitting one funnel into two charts that disagree. The identity is the
stable backend id and never an email, and the logout resets it, because a
shared device otherwise joins the next reader to the previous account. One
navigation produces one page view, which means the automatic capture of the
vendor goes off; the alternative is a funnel that reports half the real
conversion rate with no code change to explain it. The scrub over a path and
a query string sits inside the module, because a rule that each caller must
remember is a rule that one caller forgets. The last part is the three
failures that a measurement tool must not cause: a revenue event that a
blocked browser can drop, a Server Action that waits on a collector, and a
handler that reads a global which an ad blocker removed.references/consent-gate-and-cookie-inventory.md— the permission that comes
before the storage. The gate is the render and not the send, because Article
5(3) of the ePrivacy Directive covers the access to the device rather than
what the script transmits afterward, so a flag aroundtrack()arrives after
the cookie is already written. The server reads the record, or the banner
appears for a moment on every visit and moves the content under it. The
record carries a policy version, a time, and a category map, and it lives in
a first-party cookie becauselocalStorageis invisible to the server. A
Sec-GPCof1sets every non-essential category tofalseas a default.
The tool choice decides the size of the question, and a cookieless
self-hosted counter removes the banner, the vendor origin, and the transfer
question together. The last part is the inventory: one file that the policy
page renders, and an audit ofdocument.cookiein both states that proves
it.references/data-rights-and-privacy-surfaces.md— the parts of the interface
that the law makes the product show. An export is a job with a state rather
than a request that a control awaits, because an account with many rows
outlives the proxy timeout and the reader then presses the control again. A
deletion names its scope in counted nouns, takes a typed confirmation, and
clears the query cache and the analytics identity in the same step. The
retention window is a sentence beside the data rather than a line in a policy
page. The policy page renders the inventory and states the version that the
consent record names, so a purpose change moves one constant and the question
returns.
Each file carries the two-layer split, and the // Wrong: and // Correct:
pairs that name the failure the wrong version produces. Each one also holds
runnable TypeScript against the pinned versions, a binary review checklist, and
a handoff list.
Router and description
Three router rows, and fourteen seam rows. The 17 seam settles the one that
matters. Domain 17 owns the script-src and connect-src entries, the review
over a tag manager, and the integrity attribute, and it holds the veto.
Domain 23 owns the consent that must arrive before the tag renders at all. The
21 seam splits the two scrubs: an error report and an analytics event take
separate paths, and each path needs its own gate. The 16 seam keeps the cost
and the moment of a script where they already were, and takes only the
condition in front of it.
The definition of done gains a report block of twenty-five conditions. Domain
23 holds no veto, so each condition is a finding on a review pass, and one of
them fails a task only where a blocking domain fails with it. The research
offered a consent-banner focus rule and a contrast rule, and neither landed,
because the accessibility-wcag gate already carries both and it holds the
veto.
description absorbs this domain as analytics, consent, and GDPR. The count
moves from 1021 to 1019 of the 1024 that the platform allows. The 1.21.0
release recorded that no structural move remained, so the room comes from five
triggers that a sibling in the same group already fires: cast, where any
and Zod fire; CVE, where XSS and CSP fire; axe, where WCAG and ARIA fire;
robots.txt, where sitemap and metadata fire; and the size of bundle size, where LCP and INP fire. tsconfig.json loses its extension, and it is
the only trigger that shortened rather than left.
The size tripwire on SKILL.md moves from 192 kB to 200 kB. This domain adds
about 11 kB. It is the last of the twenty-four, so the number now moves only
for a patch that grows a row.
Corrected
Four landed files carried a seam that named domain 23 by number and stated that
it was not integrated. Each one now names the file that owns the subject.
references/client-bundle-and-third-party-scripts.md resolves to two files,
because the condition in front of a tag and the event that the tag sends are
separate owners. references/security-headers-and-csp.md,
references/interface-copy-and-voice.md, and
references/secret-boundary-and-supply-chain.md each resolve to the consent
file. The four Not here clauses in the SKILL.md router did the same.
references/error-capture-and-reporting.md gains a seam that it never had. It
configures the session replay mask, and nothing in it stated that a replay
needs the analytics category before it starts at all.
The research contradicted nothing that already landed, and it superseded
nothing. It carries no version delta, so the pinned baseline is unchanged.
facade keeps one meaning across the seam. The repository already uses it for
the click-to-load placeholder in front of an embed, so the analytics wrapper is
"the analytics module" rather than a second sense of the same word.
Limits
- The research names each analytics vendor and each consent platform, and it
compares them on privacy posture, cookie requirement, self-hosting, bundle
weight, data ownership, and legal exposure. It states no version, no release
date, and no advisory record for any of them. Those three columns holdNot stated, and each file tells the reader to check the registry entry before an
install. - The research reports that a content blocker removes between about 20 and 40
percent of client-side events, and it names no source for that range. The
file states the range as the research reports it, and no rule rests on the
number. The instruction is to compare the browser count of one event against
the server count of the same event. - LGPD, PIPEDA, PIPL, the EU Data Act, and the AI Act appear in the research as
regimes that exist. It states nothing operational about any of them. They are
router triggers, and no rule stands on them. - IAB TCF is named as a large surface for a product that carries advertising.
No implementation material landed, and the file states that the legal owner
belongs in that review. - The research names the GDPR articles as the range 12 to 22, and it maps no
single right onto a single article. The file cites the range, and it does not
invent the per-article mapping. - Heatmap, survey, and in-app message tools appear as one cost row, because
references/client-bundle-and-third-party-scripts.mdowns the budget over a
third-party script. - The prerequisites of this domain are 15, 16, 17, and 21, and all four are
integrated. No forward seam remains anywhere in the repository: every seam
that any file writes now resolves to a file that exists.