const RULES = [ { class: "messaging-private", pattern: /^(ask|cal|chat|crm|email|mail|news|say|session|sotce-net|tell)|subscribe|push|clock/, posthog: "inventory-only", exclusion: "No message, contact, recipient, calendar, or notification data.", }, { class: "auth-account", pattern: /auth|authorized|device|login|signin|token|user|handle|profile|location|permahandle|delete-erase|update-tezos-address/, posthog: "aggregate-status-only", exclusion: "No tokens, email, account payloads, or authorization headers.", }, { class: "commerce", pattern: /billing|give|keep|mint|mug|paypal|print|shop|ticket/, posthog: "aggregate-status-only", exclusion: "No payment, wallet, address, or order payloads.", }, { class: "local-machine", pattern: /agent-memory|machine|m4l|macpal|mcp-|ac-device|ff1|local-upload|os-install|os-native/, posthog: "inventory-only", exclusion: "No host details, logs, local files, device identifiers, or credentials.", }, { class: "operational-telemetry", pattern: /boot-log|bundle-telemetry|kidlisp-log|piece-hit|piece-log|metrics|reports|status|track-|menuband-logs|paper-hit/, posthog: "existing-lith-silo-only", exclusion: "Keep raw logs, errors, stacks, IP and performance samples in Lith/Silo.", }, { class: "admin-internal", pattern: /admin|backfill|fix-|migrate|oven|patch|presigned|redirect-proxy|register-|reload|update-build|verify-|warm-|whistlegraph|jas-tags/, posthog: "inventory-only", exclusion: "No admin actions, internal payloads, secrets, or infrastructure details.", }, { class: "content-media", pattern: /painting|piece|kidlisp|media|playlist|tape|sfx|stor|pixel|screenshot|art|flux|juke|manifestation|mockup|tv/, posthog: "minimized-browser-or-aggregate", exclusion: "No source, prompts, media, filenames, handles, or artifact contents.", }, ]; const PUBLIC_PRODUCT_NAMES = new Set([ "apple-developer-merchantid-domain-association", "api-docs", "bdf-glyph", "blank", "bundle-html", "cancelok", "commits", "docs", "firebase-config", "get-builds", "get-plugins", "index", "logo", "menuband-downloads", "mood", "og-image", "og-preview", "pop", "run", "vary", "version", ]); // Reviewed against toolchain/analytics/posthog-inventory.mjs. Unknown names // fail closed even if they happen to match one of the category patterns. const REVIEWED_FUNCTION_NAMES = new Set([ "ac-device", "admin-rebake", "agent-memory-ingest", "api-docs", "apple-developer-merchantid-domain-association", "ask", "atproto-user-stats", "auth-cli-callback", "auth0-events", "authorized", "backfill-painting-codes", "bdf-glyph", "billing", "blank", "boot-log", "bundle-html", "bundle-telemetry", "bundle-telemetry-query", "cal", "cancelok", "chat-heart", "chat-messages", "claude-token", "client-media", "clock", "commits", "crm", "delete-erase-and-forget-me", "delete-tape", "device-auth", "device-login", "device-pair", "device-pair-login", "device-token", "docs", "email", "export-piece", "ff1-devices", "ff1-pair", "ff1-proxy", "firebase-config", "fix-tezos-network-prod", "flux", "get-builds", "get-painting", "get-plugins", "get-tape", "get-tape-status", "give", "give-image", "give-portal", "gives", "handle", "handle-colors", "handles", "index", "jas-tags", "juke-cloud", "keep-confirm", "keep-mint", "keep-prepare", "keep-prepare-background", "keep-status", "keep-update", "keep-update-confirm", "keeps-config", "kidlisp-count", "kidlisp-keep", "kidlisp-list", "kidlisp-log", "local-upload", "location", "logo", "m4l-plugins", "machine-logs", "machines", "macpal-art", "macpal-art-lib", "macpal-status", "mail-status", "manifestations", "mcp-remote", "media-collection", "menuband-downloads", "menuband-logs", "metrics", "migrate-piece-paths", "mockup-webp", "mood", "mug", "mugs", "nela-signin", "news", "news-api", "news-guidelines", "news-toll", "og-image", "og-preview", "os-install-report", "os-native", "oven-complete", "painting-code", "painting-metadata", "paper-hit", "patch", "paypal", "permahandle", "piece-commits", "piece-dates", "piece-fans", "piece-hit", "piece-log", "piece-metadata", "pieces-search", "pixel", "playlist", "pop", "presigned-url", "print", "profile", "push", "push-devices", "redirect-proxy", "register-build", "register-plugin", "register-push-token", "reload", "reports", "run", "say", "screenshot", "session", "sfx", "shop", "sotce-net", "store-clock", "store-kidlisp", "store-kidlisp-datomic", "store-piece", "stories", "stretched-paintings", "subscribe-to-topic", "tape-draft", "tell", "test-tv-hits", "ticket", "track-media", "track-media-stream", "tv", "tv-tapes", "unsubscribe", "update-build", "update-painting-slug", "update-tezos-address", "user", "user-tapes", "vary", "verify-builds-password", "version", "warm-gateways", "whistlegraph-admin", "whistlegraph-admin-lib", "whistlegraph-og", "whistlegraph-query", ]); export function classifyPostHogFunction(name) { if (!REVIEWED_FUNCTION_NAMES.has(name)) { return { class: "review-required", posthog: "disabled", exclusion: "Classify this source before enabling any PostHog capture.", }; } if (PUBLIC_PRODUCT_NAMES.has(name)) { return { class: "public-product", posthog: "minimized-browser-or-aggregate", exclusion: "No request/response bodies, query strings, raw errors, or identifiers.", }; } return ( RULES.find((rule) => rule.pattern.test(name)) || { class: "review-required", posthog: "disabled", exclusion: "Classify this source before enabling any PostHog capture.", } ); } export function permitsPostHogEndpointAggregate(policy) { return ["aggregate-status-only", "minimized-browser-or-aggregate"].includes( policy?.posthog, ); }