4 Commits
Author SHA1 Message Date
Pradeep Elankumaran bfea648ac5 chore: bump crash reporter MIN_VERSION to 1.10.0
Reports from older versions are now rejected — all the issues they
were filing (memory leak false positives, likely-sleep stalls) are
fixed in 1.10.0.
2026-05-10 10:36:00 -07:00
Pradeep Elankumaran e453c6c06d chore: rename crash-relay to telemetry, add version gate >=1.8.10
- Renamed CF worker from camofox-crash-relay to camofox-telemetry
- Updated all references: README, AGENTS.md, openclaw.plugin.json,
  lib/reporter.js default URL, wrangler.toml, workflow file
- Replaced 'relay' language with 'endpoint' throughout
- Replaced 'crash reporter/reporting' with 'telemetry' in user-facing text
- Added MIN_VERSION gate (1.8.10) to the CF worker — rejects reports
  from old versions or missing version field
- Deployed and verified: old versions blocked, 1.8.14 passes
2026-04-29 00:42:09 -07:00
Pradeep Elankumaran c4b35b3d9a fix: strip all non-ASCII from shipped files (scanner unicode-control-chars)
Replace all Unicode characters (em-dash, arrows, bullets, box-drawing,
curly quotes, checkmarks, emoji) with ASCII equivalents across all
49 files that ship in the npm package.

The ClawHub scanner generates SKILL.md from package contents and
flagged unicode control characters as a potential prompt-injection
pattern. All shipped files are now pure ASCII.

Note: path-depth markers in reporter.js JSDoc comments changed from
the original bullet (U+2022) to [path] -- using * would create
nested block comment syntax errors.
2026-04-28 16:37:51 -07:00
Pradeep Elankumaran d1b78e17c3 security: move crash reporter credentials to Cloudflare Worker relay
Remove embedded GitHub App private key from lib/reporter.js and
camofox.config.json. Crash reports now POST to a Cloudflare Worker
relay that holds credentials as env secrets — no secrets shipped
in the npm package.

Verifiable by design:
- Relay source is in-repo: workers/crash-reporter/index.ts
- GET /source returns the deployed commit hash + sha256 of the source
- Compare against: sha256sum workers/crash-reporter/index.ts
- CI deploys are auditable: .github/workflows/crash-relay-deploy.yml
  injects the commit and source hash at deploy time, visible at
  https://github.com/jo-inc/camofox-browser/actions/workflows/crash-relay-deploy.yml

Changes:
- workers/crash-reporter/index.ts: CF Worker with payload validation,
  IP rate limiting, signature dedup, GitHub App JWT auth, issue
  creation. GET /source for hash verification.
- lib/reporter.js: replaced direct GitHub API calls with sendToRelay(),
  added inline relay source documentation block
- CAMOFOX_CRASH_REPORT_URL env var for self-hosted relay override
- Telemetry declaration in plugin manifest (data collected/never
  collected, opt-out, self-host override, verification endpoint)
- 61 new tests (client relay + worker contract + payload compat)
- CI workflow for auto-deploy on push to main

Relay live at https://camofox-crash-relay.askjo.workers.dev
2026-04-28 15:17:43 -07:00