feat(frontend): post collected samples to /api/v1/reports (closes #53)
check / check (push) Failing after 1s

A Reporter beside AppState POSTs a JSON delta report to the same-origin
/api/v1/reports every reportInterval (default 60s). buildReport is an
exported pure function of host state, emitting each host's unreported,
non-paused samples plus a per-browser clientId, geo null, and a UTC
timestamp; a per-host high-water mark advances only on a delivered POST,
so a failed send re-sends next interval within the history window.
Failure is quiet and never blocks probing.

The client id feature-detects crypto.randomUUID and otherwise builds a v4
id from crypto.getRandomValues, so insecure-context loads (plain HTTP to a
non-localhost host) work; reporter setup is isolated so it can never stop
probing. init() runs only when the #app page is present, so a test can
import buildReport.

vite.config.js proxies /api to 127.0.0.1:8080 for yarn dev.

Model: opus-4-8
This commit is contained in:
2026-09-21 13:10:55 +00:00
parent f3895789d2
commit 6c6081b455
4 changed files with 192 additions and 4 deletions
+5
View File
@@ -22,6 +22,11 @@ files, so merging it also closes most compliance gaps.
# Completed Steps
- 2026-09-21: frontend reporting client — a `Reporter` class posts collected
samples to `/api/v1/reports` every `reportInterval` (default 60s) as a
per-host delta, with the report-building step a pure exported function of host
state; the per-browser client id works in insecure (plain-HTTP) contexts;
`vite.config.js` proxies `/api` to the local backend for `yarn dev`
- 2026-09-21: backend HTTP hardening (issue #19): added `ReadHeaderTimeout` and
`IdleTimeout` to the server, a `SecurityHeaders` middleware (HSTS, tight CSP,
frame/sniff/referrer/permissions headers) registered before CORS, and