Skip to content

feat(report): opt-in tool error reporting (MVP / Sub-project A) - #401

Merged
slaveofcode merged 21 commits into
developfrom
feat/tool-error-reporting
Sep 27, 2026
Merged

slaveofcode merged 21 commits into
developfrom
feat/tool-error-reporting

Conversation

@slaveofcode

Copy link
Copy Markdown
Owner

What

An opt-in, consent-gated "Report a problem" reporter on every tool page. When a tool fails, a willing user can send a rich diagnostics + logs payload (and optionally the failing file) so we can reproduce and fix — closing the "works on my machine" gap.

  • Client services (pure, unit-tested): fileMeta (magic-byte sniff → claimed-vs-actual format + decode), breadcrumbs (ring buffer + global capture), diagnostics (env fingerprint + capabilities + logs), reporter bus, submit.
  • UI: ReportDialog island (consent, "see exactly what will be sent", separate pre-unchecked file attach with a sensitivity warning, invisible Turnstile, warm thank-you) + ReportButton, wired into ToolHost on every tool page; "Report this crash" on the error boundary.
  • Worker POST /api/report → private R2 bucket, gated by Turnstile + a 10 MB cap; hardened (server-generated R2 key, form-field type guards, body-size precheck, no byte logging).
  • Wired first: image-compress (the tool that prompted this).
  • useReportable hook for one-line tool wiring.

Privacy

Nothing is sent without an explicit Submit and a ticked consent box. The file is a separate, pre-unchecked, warned opt-in. Diagnostics exclude the filename and file bytes. Reports land in a private R2 bucket.

⛔ Deploy gate — do NOT merge until these are done

Merging to develop deploys straight to production. First:

  1. wrangler r2 bucket create goodwebtools-reports and goodwebtools-reports-staging
  2. wrangler secret put TURNSTILE_SECRET (and --env staging)
  3. Set PUBLIC_TURNSTILE_SITE_KEY to the matching real Turnstile site key
    Until (1) the bucket exists /api/report 500s on submit; until (2) the secret is set the endpoint accepts unverified submissions (default is Cloudflare's always-pass test key).

Scope

This is Sub-project A (MVP). Deferred to Sub-project B: admin viewer (/admin/reports + /api/admin/reports), per-IP rate limiting, webhook enrichment, R2 30-day retention lifecycle, wiring the remaining hot tools, Privacy-page copy. Spec + plan under docs/superpowers/.

Verify

npx vitest run 2311 pass · lint 0 errors · build OK (441 pages) · npm run test:e2e 229 passed / 1 skipped (real-model agent) — includes the all-tools render smoke + report happy/failure specs.

Promote to production: pdf-redact zoom control
Cross-cutting problem reporter on every tool page: consent-gated report
with comprehensive diagnostics + logs (closes 'works on my machine'),
optional failing-file attachment, Worker /api/report → private R2 with
Turnstile + size/rate caps, token-gated admin viewer, warm thank-you.
Staged rollout (MVP first, admin/webhook/retention follow).
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
goodwebtools 9364f84 Sep 27 2026, 12:58 AM

@slaveofcode
slaveofcode merged commit 6df58bc into develop Sep 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant