Skip to content

[CI] (3f39e0e) swift/hackers-ios - #4187

Closed
wizard-ci-bot[bot] wants to merge 1 commit into
mainfrom
wizard-ci-3f39e0e-swift-hackers-ios
Closed

wizard-ci-bot[bot] wants to merge 1 commit into
mainfrom
wizard-ci-3f39e0e-swift-hackers-ios

Conversation

@wizard-ci-bot

@wizard-ci-bot wizard-ci-bot Bot commented Sep 23, 2026

Copy link
Copy Markdown

Automated wizard CI run

Source: wizard-pr
Trigger ID: 3f39e0e
App: swift/hackers-ios
App directory: apps/swift/hackers-ios
Workbench branch: wizard-ci-3f39e0e-swift-hackers-ios
Wizard branch: release-please--branches--main--components--wizard
Context Mill branch: main
PostHog (MCP) branch: master
Timestamp: 2026-09-23T22:29:10.757Z
Duration: 818.3s

YARA Scanner

✓ 194 tool calls scanned, 0 violations detected

No violations: ✓ 194 clean scans

@wizard-ci-bot

wizard-ci-bot Bot commented Sep 23, 2026

Copy link
Copy Markdown
Author

PR Evaluation Report

Summary

This PR integrates the PostHog iOS SDK (v3.81.0) into the Hackers iOS app via Swift Package Manager. It adds initialization in AppDelegate, captures five custom events across navigation and authentication flows, enables error auto-capture, and configures the API key/host through Xcode build settings baked into the Info.plist.

Files changed Lines added Lines removed
7 +92 -13

Confidence score: 5/5 🧙

  • Missing identify() call: After a successful login in authenticate(), the code captures login_succeeded but never calls PostHogSDK.shared.identify() with the user's distinct ID. This means all events remain anonymous and cannot be linked to specific users. [CRITICAL]
  • Missing reset() on logout: The logout() function calls sessionService.unauthenticate() and captures an event, but never calls PostHogSDK.shared.reset(). If another user logs in on the same device, their events will be attributed to the previous user. [MEDIUM]
  • Events lack properties: All five capture() calls are bare — post_opened doesn't include a post ID, login_succeeded has no method/plan info, deep_link_opened has no URL path. This significantly limits analytics utility. [MEDIUM]

File changes

Filename Score Description
App/AppDelegate.swift 4/5 PostHog initialization with build-setting-sourced API key, error tracking, and structured logging
App/ContentView.swift 3/5 Extracts auth/logout into functions with PostHog capture, but missing identify/reset
App/NavigationStore.swift 3/5 Adds capture calls for post, settings, and deep link opens — all without properties
App/Supporting Files/Hackers-Info.plist 5/5 Adds Info.plist keys for build setting substitution
Hackers.xcodeproj/project.pbxproj 5/5 Correct SPM integration with all three required objects (PBXBuildFile, XCSwiftPackageProductDependency, XCRemoteSwiftPackageReference)
.env.example 4/5 Documents required env vars
Package.resolved 5/5 Locks posthog-ios at 3.81.0

App sanity check ✅

Criteria Result Description
App builds and runs Yes SPM dependency properly declared with three required pbxproj objects; imports resolve
Preserves existing env vars & configs Yes Existing app logic preserved; auth/logout refactored to wrapper functions maintaining original behavior
No syntax or type errors Yes Valid Swift syntax throughout
Correct imports/exports Yes import PostHog is correct for the posthog-ios SPM package
Minimal, focused changes Yes All changes directly relate to PostHog integration
Pre-existing issues None —

Other completed criteria

  • Environment variables documented in .env.example
  • Build configuration valid — project.pbxproj properly structured with PBXBuildFile, product dependency, and package reference
  • Build settings bake POSTHOG_PROJECT_TOKEN and POSTHOG_HOST into the binary via Info.plist substitution, which is the recommended iOS approach

PostHog implementation ⚠️

Criteria Result Description
PostHog SDKs installed Yes posthog-ios v3.81.0 added via Swift Package Manager
PostHog client initialized Yes PostHogConfig(apiKey:host:) + PostHogSDK.shared.setup(config) in AppDelegate.didFinishLaunchingWithOptions
capture() Yes Five custom events: login_succeeded, logout_completed, post_opened, settings_opened, deep_link_opened
identify() No No PostHogSDK.shared.identify() call anywhere — user sessions remain anonymous
Error tracking Yes config.errorTrackingConfig.autoCapture = true properly configured
Reverse proxy N/A iOS app — reverse proxy only benefits posthog-js in browsers

Issues

  • No user identification after login: The authenticate() function captures login_succeeded but never calls PostHogSDK.shared.identify("distinct_id"). Per the docs, identify should be called "as soon as you're able to… directly after your users log in." Without this, all events are anonymous and cannot be attributed to users, defeating much of PostHog's value. Fix: Add PostHogSDK.shared.identify(username, userProperties: [...]) after successful authentication. [CRITICAL]
  • No reset() on logout: The logout() function never calls PostHogSDK.shared.reset(). The docs explicitly state: "If a user logs out on your frontend, you should call reset() to unlink any future events." Fix: Add PostHogSDK.shared.reset() in the logout() function before or after sessionService.unauthenticate(). [MEDIUM]

Other completed criteria

  • API key and host correctly sourced from build settings baked into Info.plist — hardcoding is the recommended approach for iOS per the framework rules
  • Host correctly set to https://us.i.posthog.com
  • Screen views autocaptured via captureScreenViews (defaults to true)
  • Structured logging configured with config.logs.serviceName = "hackers-ios"

PostHog insights and events ⚠️

Filename PostHog events Description
AppDelegate.swift Error auto-capture, structured logging Initialization with error tracking and application launch log
ContentView.swift login_succeeded, logout_completed Captures auth events but without properties or identify/reset
NavigationStore.swift post_opened, settings_opened, deep_link_opened Navigation events for core user flows, all without properties

Issues

  • Events lack enriched properties: All five capture() calls pass no properties. post_opened should include the post ID/title, deep_link_opened should include the URL path/view type, login_succeeded could include the auth method. Bare events severely limit filtering, breakdown, and funnel analysis. Fix: Add relevant properties, e.g. PostHogSDK.shared.capture("post_opened", properties: ["post_id": post.id, "post_title": post.title]). [MEDIUM]

Other completed criteria

  • Events represent real user actions (login, logout, opening posts, settings, deep links)
  • Events enable product insights — can build login → post_opened funnels and track feature adoption
  • No PII placed in event properties
  • Event naming follows descriptive snake_case convention consistently

Reviewed by wizard workbench PR evaluator

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants