Files
DeskcommCRM/sentry.edge.config.ts
T
Rafael MelgaçoandClaude Opus 4.7 5d0cdb5c48 feat(EPIC-12): hardening + e2e + polish [10 waves, partial]
Error handling:
- app/error.tsx + app/app/error.tsx + app/(public)/error.tsx via shared
  components/feedback/SegmentError.tsx — captures to Sentry, displays eventId,
  copy-to-clipboard, reset button.
- app/global-error.tsx upgraded with Sentry capture + eventId UI.
- app/not-found.tsx (PT-BR copy B1).
- app/403/page.tsx polished (copy B2).
- app/500/page.tsx + app/503/page.tsx new (copy B3, B4).

Empty states:
- components/empty/EmptyState.tsx (base) + 10 specialized variants
  (Inbox, Kanban, Contacts, Audit, Pipeline, Team, ApiTokens, Timeline,
  MergeQueue, FilterResults).
- Wired into kanban picker, contacts list, inbox conversation list (3 sites).

Loading skeletons:
- app/app/loading.tsx + 4 route-specific loading.tsx
  (inbox, kanban, contacts, audit) using shadcn Skeleton.

Sentry:
- beforeSend in sentry.server.config.ts, sentry.edge.config.ts,
  instrumentation-client.ts scrubs Authorization/Cookie/x-api-key/
  x-waha-api-key/x-nuvemshop-token/x-deskcomm-token headers + CPF/email/phone
  patterns from message + exception values. sendDefaultPii: false.
- lib/logger.ts: structured JSON logger (zero deps).

Web Vitals:
- next.config.ts: experimental.optimizePackageImports for phosphor/lucide/
  date-fns. Performance budget block documented inline.
- .github/workflows/perf.yml reports build output sizes to Step Summary.

E2E:
- tests/e2e/auth.spec.ts: anon redirect, invalid creds, keyboard tab order,
  axe-core a11y audit on /login (fails on serious/critical).
- tests/e2e/error-pages.spec.ts: 404/403/500/503 routes.
- @axe-core/playwright integrated.

Public paths:
- lib/auth/public-paths.ts allows /500 and /503 (must not require auth).

Docs:
- README.md quickstart 5min reescrito.
- ARCHITECTURE.md (1-page overview + spec refs).
- CONTRIBUTING.md (PR + epic-executor workflow).
- docs/DEPLOY-CHECKLIST.md preflight.

Migrations:
- supabase/migrations/ reconciled against remote schema_migrations
  (verified via Supabase MCP list_migrations); 9 stub files created with
  pointers to the corresponding spec; MANIFEST.md updated for 0008/0009.

Deferred to follow-up (documented in EPIC-12 Wave Completion Log):
- Lighthouse CI + bundle-analyzer thresholds in GitHub Actions.
- E2E specs covering /app/* routes (require MFA bypass strategy via
  test-only env var or storageState fixture).
- Full 5-jornada E2E suite — depends on EPIC-06 (AI) and EPIC-08 (LGPD)
  which remain pending.

Implements S-12.01..S-12.10 contracts. Closes EPIC-12 (10/10 waves with
documented stubs).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 23:32:27 -03:00

49 lines
1.3 KiB
TypeScript

// This file configures the initialization of Sentry for edge features (middleware, edge routes, and so on).
// https://docs.sentry.io/platforms/javascript/guides/nextjs/
import * as Sentry from "@sentry/nextjs";
const SENSITIVE_HEADERS = [
"authorization",
"cookie",
"x-api-key",
"x-waha-api-key",
"x-nuvemshop-token",
"x-deskcomm-token",
];
function scrubMessage(input: string): string {
return input
.replace(/\d{3}\.?\d{3}\.?\d{3}-?\d{2}/g, "[CPF]")
.replace(/\+?\d{2}\s?\d{4,5}-?\d{4}/g, "[PHONE]")
.replace(/[\w.+-]+@[\w-]+\.[\w.-]+/g, "[EMAIL]");
}
Sentry.init({
dsn: "https://58fabf8ad54504863d404a3647ef3714@o4509908078559232.ingest.us.sentry.io/4509908083212288",
tracesSampleRate: 1,
enableLogs: true,
sendDefaultPii: false,
beforeSend(event) {
if (event.request?.headers) {
const headers = event.request.headers as Record<string, string>;
for (const k of Object.keys(headers)) {
if (SENSITIVE_HEADERS.includes(k.toLowerCase())) {
delete headers[k];
}
}
}
if (typeof event.message === "string") {
event.message = scrubMessage(event.message);
}
if (event.exception?.values) {
for (const ex of event.exception.values) {
if (ex.value) ex.value = scrubMessage(ex.value);
}
}
return event;
},
});