Repository navigation
Require analytics limiter configuration in production - #8009
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
📝 WalkthroughWalkthrough
ChangesAnalytics rate-limit validation
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (24 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR requires analytics limiter configuration for Vercel production deployments. The main changes are:
Confidence Score: 5/5This looks safe to merge.
Important Files Changed
Reviews (2): Last reviewed commit: "Keep analytics limiter optional in Verce..." | Re-trigger Greptile |
| CMUX_FEEDBACK_RATE_LIMIT_ID: z.string().min(1), | ||
| CMUX_CLIENT_CONFIG_RATE_LIMIT_ID: requireVercelNonPreviewValue("CMUX_CLIENT_CONFIG_RATE_LIMIT_ID"), | ||
| CMUX_ANALYTICS_RATE_LIMIT_ID: z.string().min(1).optional(), | ||
| CMUX_ANALYTICS_RATE_LIMIT_ID: requireVercelNonPreviewValue("CMUX_ANALYTICS_RATE_LIMIT_ID"), |
There was a problem hiding this comment.
Development Deployments Require Production Rule
When VERCEL="1" and VERCEL_ENV="development", this helper requires CMUX_ANALYTICS_RATE_LIMIT_ID even though the intended contract is production-only. The local environment loader does not provide this analytics rule ID, so Vercel development processes that load app/env.ts can fail validation and prevent unrelated routes from initializing.
| CMUX_ANALYTICS_RATE_LIMIT_ID: requireVercelNonPreviewValue("CMUX_ANALYTICS_RATE_LIMIT_ID"), | |
| CMUX_ANALYTICS_RATE_LIMIT_ID: z.string().min(1).optional().superRefine((value, context) => { | |
| if (process.env.VERCEL === "1" && process.env.VERCEL_ENV === "production" && !value) { | |
| context.addIssue({ | |
| code: z.ZodIssueCode.custom, | |
| message: "CMUX_ANALYTICS_RATE_LIMIT_ID is required for Vercel production runtimes", | |
| }); | |
| } | |
| }), |
There was a problem hiding this comment.
Fixed in 8eb9f64. The analytics env validator now targets Vercel production only, while the existing client-config validator keeps its non-preview contract. A subprocess test covers VERCEL_ENV=development without the analytics rule ID.
— Claude Code
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@web/app/env.ts`:
- Line 40: Update the environment-validation message in the relevant
`web/app/env.ts` diagnostic to use product-neutral wording without exposing the
environment-variable name or deployment provider, while retaining exact
configuration details only in internal diagnostics. Update the corresponding
stderr assertion to match the sanitized message.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: bdf732db-4849-4efb-b5f6-da7b8bb17487
📒 Files selected for processing (2)
web/app/env.tsweb/tests/client-config-env.test.ts
Summary
Testing
cd web && bun test tests/client-config-env.test.ts tests/analytics-events-route.test.tscd web && bun run typecheckPOST /api/analytics/eventswith an empty batch returns 200 after enabling thecmux-analyticsFirewall rule and environment variable/,/handler/sign-in, redirected/handler/after-sign-in, and an empty analytics batchIssues
/api/analytics/eventsstarting July 13, 2026Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Summary by cubic
Require
CMUX_ANALYTICS_RATE_LIMIT_IDfor Vercel production only; keep it optional for development and preview. Adds tests to enforce this and prevent 5xxs on POST/api/analytics/events.CMUX_ANALYTICS_RATE_LIMIT_IDin Vercel production to the analytics Firewall rule ID and ensure the rule is enabled.Written for commit 8eb9f64. Summary will update on new commits.
Summary by CodeRabbit