Skip to content

Fix: Drop opaque cross-origin "Script error." events - #369

Draft
posthog-eu[bot] wants to merge 1 commit into
mainfrom
posthog-self-driving/fixobservability-drop-opaque-cross-7c5d55
Draft

posthog-eu[bot] wants to merge 1 commit into
mainfrom
posthog-self-driving/fixobservability-drop-opaque-cross-7c5d55

Conversation

@posthog-eu

@posthog-eu posthog-eu Bot commented Sep 12, 2026

Copy link
Copy Markdown

Problem

  • Who is hurt: the team, not users. A cross-origin "Script error." reaches error tracking as a high-severity issue that no one can debug, so it costs triage time on an otherwise quiet project.
  • The browser reports "Script error." with no stack, no source file, and a synthetic mechanism when a script from another origin throws without CORS headers. The likely source is a browser extension or an injected third-party script, not app code.
  • The before_send hook in packages/observability/src/initAnalytics.ts only adds properties and never drops anything, so the event lands as an issue.
  • Cloudflare Turnstile loads from a third-party origin without crossorigin, so a genuine Turnstile load failure on the register and forgot pages would also report the same opaque message.

Changes

  • Drop the noise: before_send now returns null for an $exception event whose exception list is only stackless "Script error." entries.
  • Keep future failures debuggable: the Turnstile script tag now sets crossorigin="anonymous", so a real load failure reports a usable stack instead of an opaque message.

Notes

  • Scoped to stackless "Script error." exceptions, so real errors that carry a stack are untouched.
  • No test runner exists in the observability package, so the change ships without a unit test. The package builds cleanly (ESM/CJS). The experimental-dts step fails only on the pre-existing @repo/lib declaration resolution, present on main and unrelated to this change.
  • Related to the localhost filter in Fix: Drop analytics events from local development #364, which also edits this hook.

Created with PostHog Desktop from this inbox report.

Drop stackless "Script error." exceptions in the observability before_send
hook so cross-origin script failures from extensions or third-party scripts
stop reaching error tracking as high-severity, unactionable noise.

Add crossorigin="anonymous" to the Cloudflare Turnstile script tag so a real
Turnstile load failure reports a usable stack instead of the same opaque
message.

Generated-By: PostHog Desktop
Task-Id: 87554b1b-8413-4f2c-8818-969ae09248db
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Staging Environment Deployed

Your staging environment is ready!

URL: https://theopenpresenter-staging-pr-369-server.qzteeq.uncld.dev

Note: This environment will be automatically destroyed:

  • When this PR is closed or merged
  • After 7 days of inactivity
  • When new commits are pushed (a new environment will be created)

To manually recreate the environment, re-run the "Build and Deploy Staging" workflow.


Deployed at: 2026-09-12T03:12:35.604Z
Commit: 429a3ea

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants