Skip to content

fix(runtime-browser): isolate beforeSend failures - #22

Open
rajeshaipython-stack wants to merge 1 commit into
Autter-dev:mainfrom
rajeshaipython-stack:codex/fix-browser-before-send
Open

rajeshaipython-stack wants to merge 1 commit into
Autter-dev:mainfrom
rajeshaipython-stack:codex/fix-browser-before-send

Conversation

@rajeshaipython-stack

@rajeshaipython-stack rajeshaipython-stack commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

A throwing beforeSend callback currently escapes the browser SDK. When network capture observes an HTTP 503 response, that exception changes the application's resolved fetch into a rejection. On a network failure, it also replaces the original error.

Catch callback exceptions and drop the affected telemetry event, preserving the original request result. Document this behavior and add regression coverage for response identity, original network errors, manual capture, intentional drops, and subsequent event mapping/delivery.

Validation:

  • Regression fails against unchanged main and passes with this fix.
  • Full Linux CI passes: workspace build, Node/browser/ingester tests, and browser size gate.
  • Local browser tests: 9/9 pass.
  • Local ingester tests: 62/62 pass.
  • Browser size: 3.43 kB, below 5 kB.
  • Local Node tests on Windows: 33/37 pass; four unchanged SIGTERM/shutdown fixtures exit with status 1. The complete Node suite passes in Linux CI.
  • git diff --check passes.

View code changes stack in Autter

Summary

Summary generated by Autter.

Why this change

User-supplied beforeSend runs inside the browser SDK enqueue path, so a throwing callback risks breaking event capture and leaking errors into the host app. This change isolates those failures to preserve the SDK's fail-open behavior.

What changes for users

Browser consumers keep using beforeSend to mutate or drop (return null) events before send, but hook failures are now contained to the affected event. No wire-format or relay/ingester changes; @autter/runtime-next/client re-exports pick up the fix automatically.

Implementation and review notes

  • Review enqueue isolation in packages/runtime-browser/src/index.ts (~L311–L324) — confirm beforeSend errors cannot throw or stall queue/flush.
  • Check AutterBrowserOptions.beforeSend doc touch-up (~L32) matches implemented throw-drops-event semantics.
  • See new packages/runtime-browser/test/before-send.test.mjs for throwing / drop / mutate coverage.
  • Verify browser bundle still meets <5 KB brotlied size gate and zero-dependency constraint.

Changes

  • Isolated opts.beforeSend invocation inside enqueue() in packages/runtime-browser/src/index.ts with try/catch so a throwing hook drops only the affected BrowserEvent and never propagates into the host app, queue, or flush timer.
  • Preserved existing beforeSend contract: return mutated event to send, return null to drop; throwing is now explicitly defined as drop-event fail-open path.
  • Updated AutterBrowserOptions.beforeSend doc comment to document throw-drops-event semantics.
  • Added packages/runtime-browser/test/before-send.test.mjs covering throwing hook, null drop, and mutate passthrough.
  • Breaking changes: None. No change to /v1/browser v1 payload, BrowserEvent shape, relay validation, or ingester normalization; additive fail-open fix only.

Acceptance Criteria

  • Throwing beforeSend does not throw from enqueue/capture* and drops that event while subsequent events still flush.
  • Returning null drops the event; returning a mutated event sends the mutation.

Test Plan

  • Run npm run build -w @autter/runtime-browser and confirm clean build with no new dependencies.
  • Run npm run test -w @autter/runtime-browser and confirm new before-send.test.mjs passes.
  • Run npm run size -w @autter/runtime-browser and confirm <5 KB brotlied budget holds.
  • Manually verify with throwing beforeSend that page does not error and follow-on events still send via relay.

Rollback Plan

  • Revert commit dc1513a and rebuild @autter/runtime-browser; no migration or ingester change to undo.

Related Issues

No linked issue was identified in branch, commits, or diff context.

Written for commit dc1513a. Summary will update on new commits.

@autter-dev

autter-dev Bot commented Oct 5, 2026

Copy link
Copy Markdown

🚦 Pre-merge checks · ✅ 168 passed

✅ Passed checks (168)
Check Status Explanation
Too many files changed ✅ Passed Changed 2 file(s), within the limit of 50.
Too many lines changed ✅ Passed Changed 72 line(s), within the limit of 1000.
Too many unrelated chapters ✅ Passed 1 chapter(s) detected, within the limit of 6.
Generated files hiding real changes ✅ Passed Generated-file volume (0 lines) does not obscure the 72 hand-written line(s).
Missing PR context ✅ Passed PR context looks sufficient.
Mixed concerns (refactor + behavior change) ✅ Passed Single fail-open behavior fix with matching doc update and regression test; no rename/move/cleanup refactor.
Migration + app logic + UI combined in one PR ✅ Passed No database migration files; only browser SDK logic change plus test.
Sensitive data in logs ✅ Passed No sensitive data in logs issues detected.
Log injection ✅ Passed No log injection issues detected.
Missing audit logging ✅ Passed No missing audit logging issues detected.
Removed observability ✅ Passed No removed observability issues detected.
Silent exception swallowing ✅ Passed No silent exception swallowing issues detected.
Unhandled promise rejection ✅ Passed No unhandled promise rejection issues detected.
Circuit breaker not detected ✅ Passed No circuit breaker not detected issues detected.
Stack trace leakage ✅ Passed No stack trace leakage issues detected.
Multi-write without detected transaction ✅ Passed No multi-write without detected transaction issues detected.
Possible TOCTOU in critical path ✅ Passed No possible toctou in critical path issues detected.
Idempotency key not detected ✅ Passed No idempotency key not detected issues detected.
Possible non-atomic read-modify-write ✅ Passed No possible non-atomic read-modify-write issues detected.
Optimistic locking not detected ✅ Passed No optimistic locking not detected issues detected.
Rate limiting not detected ✅ Passed No rate limiting not detected issues detected.
Rate limiting removed ✅ Passed No rate limiting removed issues detected.
Batch size limit not detected ✅ Passed No batch size limit not detected issues detected.
Pagination not detected ✅ Passed No pagination not detected issues detected.
Prompt injection risk ✅ Passed No LLM/AI-integration code touched by this diff.
LLM output used in a dangerous sink ✅ Passed No LLM/AI-integration code touched by this diff.
Sensitive data in prompt or system-prompt leakage ✅ Passed No LLM/AI-integration code touched by this diff.
Over-privileged LLM tool / excessive agency ✅ Passed No LLM/AI-integration code touched by this diff.
Missing validation on an LLM-driven decision ✅ Passed No LLM/AI-integration code touched by this diff.
Unbounded LLM usage (denial-of-wallet) ✅ Passed No LLM/AI-integration code touched by this diff.
Table exposed without row-level security ✅ Passed No row-level-security-related code touched by this diff.
Over-broad row-level security policy ✅ Passed No row-level-security-related code touched by this diff.
Code path that bypasses row-level security ✅ Passed No row-level-security-related code touched by this diff.
Privileged database credential reachable from the client ✅ Passed No row-level-security-related code touched by this diff.
Privileged query without row-level scoping ✅ Passed No row-level-security-related code touched by this diff.
Row-level security enabled with no policy ✅ Passed No row-level-security-related code touched by this diff.
Template-default gradient styling ✅ Passed No added frontend pages or design-slop markers in this diff.
Interchangeable AI marketing copy ✅ Passed No added frontend pages or design-slop markers in this diff.
Placeholder content shipped to users ✅ Passed No added frontend pages or design-slop markers in this diff.
Emoji standing in for an icon system ✅ Passed No added frontend pages or design-slop markers in this diff.
Call-to-action that goes nowhere ✅ Passed No added frontend pages or design-slop markers in this diff.
Templated page composition ✅ Passed No added frontend pages or design-slop markers in this diff.
Color outside the brand palette ✅ Passed No added frontend markup or brand-relevant style changes in this diff.
Hardcoded style bypassing design tokens ✅ Passed No added frontend markup or brand-relevant style changes in this diff.
Typography outside the brand type system ✅ Passed No added frontend markup or brand-relevant style changes in this diff.
One-off UI instead of the shared component ✅ Passed No added frontend markup or brand-relevant style changes in this diff.
Copy that does not match brand voice ✅ Passed No added frontend markup or brand-relevant style changes in this diff.
Screen does not match the rest of the product ✅ Passed No added frontend markup or brand-relevant style changes in this diff.
Merge-blocking marker left in the change ✅ Passed No pending-work markers added by this diff.
Known-defect marker shipped in code ✅ Passed No pending-work markers added by this diff.
Untracked TODO without an issue reference ✅ Passed No pending-work markers added by this diff.
Test disabled or left pending ✅ Passed No pending-work markers added by this diff.
PII in logs ✅ Passed No pii in logs issues detected.
PII or internals leaked in error response ✅ Passed No pii or internals leaked in error response issues detected.
PII stored without application-level encryption ✅ Passed No pii stored without application-level encryption issues detected.
User data stored without retention controls ✅ Passed No user data stored without retention controls issues detected.
PII sent to external / cross-border destination ✅ Passed No pii sent to external / cross-border destination issues detected.
Lockfile resolution / integrity tampered ✅ Passed No lockfile resolution / integrity tampered issues detected.
Dependency runs install-time lifecycle script ✅ Passed No dependency runs install-time lifecycle script issues detected.
Possible dependency-confusion attack ✅ Passed No possible dependency-confusion attack issues detected.
Lockfile resolves a dependency the manifest does not declare ✅ Passed No lockfile resolves a dependency the manifest does not declare issues detected.
Checked-in build artefact modified without source change ✅ Passed No checked-in build artefact modified without source change issues detected.
Dockerfile build-step is insecure ✅ Passed No dockerfile build-step is insecure issues detected.
External artefact pulled in without integrity pinning ✅ Passed No external artefact pulled in without integrity pinning issues detected.
Changed export, importer not updated ✅ Passed No changed export with an un-updated importer detected.
Missing linked tracker issue ✅ Passed No missing linked tracker issue issues remaining after verification.
Missing CODEOWNERS reviewer approval ✅ Passed No missing codeowners reviewer approval issues detected.
Missing security-team review on sensitive path ✅ Passed No missing security-team review on sensitive path issues detected.
Source changes without matching tests ✅ Passed No source changes without matching tests issues detected.
Migration missing rollback / down step ✅ Passed No migration missing rollback / down step issues detected.
Frontend importing database client directly ✅ Passed No frontend importing database client directly issues detected.
Route handler bypassing service layer ✅ Passed No route handler bypassing service layer issues detected.
Backend service importing UI module ✅ Passed No backend service importing ui module issues detected.
Cross-context internals import ✅ Passed No cross-context internals import issues detected.
Workspace package rule violation ✅ Passed No workspace package rule violation issues detected.
Inconsistent logging pattern ✅ Passed No inconsistent logging pattern issues detected.
Inconsistent error handling ✅ Passed No inconsistent error handling issues detected.
Endpoint missing input validation ✅ Passed No endpoint missing input validation issues detected.
Multi-write without transaction wrapper ✅ Passed No multi-write without transaction wrapper issues detected.
New feature shipped without feature flag ✅ Passed No new feature shipped without feature flag issues detected.
Module placed in the wrong workspace package ✅ Passed No module placed in the wrong workspace package issues detected.
Hallucinated import (package not installed) ✅ Passed No hallucinated import (package not installed) issues remaining after verification.
Nonexistent package (not found in registry) ✅ Passed No nonexistent package (not found in registry) issues detected.
Call to function that does not exist ✅ Passed No call to function that does not exist issues detected.
Generic placeholder identifier in production logic ✅ Passed No generic placeholder identifier in production logic issues detected.
Repetitive boilerplate (duplicated block) ✅ Passed No repetitive boilerplate (duplicated block) issues detected.
Overbroad try/catch swallowing all exceptions ✅ Passed No overbroad try/catch swallowing all exceptions issues detected.
TODO / FIXME on critical path ✅ Passed No todo / fixme on critical path issues detected.
Comment contradicts or fabricates code behaviour ✅ Passed No comment contradicts or fabricates code behaviour issues detected.
Abstraction defined but never used ✅ Passed No abstraction defined but never used issues detected.
Code style differs from rest of codebase ✅ Passed No code style differs from rest of codebase issues detected.
Established pattern ignored ✅ Passed No established pattern ignored issues detected.
Unhandled edge case (null / empty / zero / boundary) ✅ Passed No unhandled edge case (null / empty / zero / boundary) issues detected.
Insecure training-data / doc-example pattern ✅ Passed No insecure training-data / doc-example pattern issues detected.
Dead code (defined but never referenced) ✅ Passed No dead code (defined but never referenced) issues detected.
Deprecated API call ✅ Passed No deprecated api call issues detected.
API pattern from wrong library version ✅ Passed No api pattern from wrong library version issues detected.
API endpoint removed ✅ Passed No api endpoint removed issues detected.
HTTP method changed (GET ↔ POST etc.) ✅ Passed No http method changed (get ↔ post etc.) issues detected.
New required field added to request ✅ Passed No new required field added to request issues detected.
Field removed from response schema ✅ Passed No field removed from response schema issues detected.
Response field type changed ✅ Passed No response field type changed issues detected.
HTTP status code changed ✅ Passed No http status code changed issues detected.
Auth requirement added / removed / changed ✅ Passed No auth requirement added / removed / changed issues detected.
Error response shape changed ✅ Passed No error response shape changed issues detected.
Pagination behaviour changed ✅ Passed No pagination behaviour changed issues detected.
Outbound webhook payload schema changed ✅ Passed No outbound webhook payload schema changed issues detected.
GraphQL field removed without deprecation ✅ Passed No graphql field removed without deprecation issues detected.
GraphQL enum value removed ✅ Passed No graphql enum value removed issues detected.
Vendor API consumer ✅ Passed This PR does not touch call sites of an open vendor API change.
SQL injection ✅ Passed No sql injection issues detected.
Cross-site scripting (XSS) ✅ Passed No cross-site scripting (xss) issues detected.
Path traversal ✅ Passed No path traversal issues detected.
Command injection ✅ Passed No command injection issues detected.
Insecure deserialization ✅ Passed No insecure deserialization issues detected.
Weak cryptography ✅ Passed No weak cryptography issues detected.
Hardcoded secret ✅ Passed No hardcoded secret issues detected.
Insecure randomness for security material ✅ Passed No insecure randomness for security material issues detected.
Unsafe file upload ✅ Passed No unsafe file upload issues detected.
Missing input validation ✅ Passed No missing input validation issues detected.
Unsafe CORS configuration ✅ Passed No unsafe cors configuration issues detected.
Unsafe / open redirect ✅ Passed No unsafe / open redirect issues detected.
Missing CSRF protection ✅ Passed No missing csrf protection issues detected.
Unsafe cookie / session settings ✅ Passed No unsafe cookie / session settings issues detected.
Sensitive data exposure ✅ Passed No sensitive data exposure issues detected.
Invisible Unicode / Trojan Source characters ✅ Passed No invisible unicode / trojan source characters issues detected.
API key in source ✅ Passed No api key in source detected.
Access token in source ✅ Passed No access token in source detected.
Private key in source ✅ Passed No private key in source detected.
Database connection URL with embedded credentials ✅ Passed No database connection url with embedded credentials detected.
Cloud credential in source ✅ Passed No cloud credential in source detected.
Webhook signing secret in source ✅ Passed No webhook signing secret in source detected.
OAuth client secret in source ✅ Passed No oauth client secret in source detected.
JWT signing secret in source ✅ Passed No jwt signing secret in source detected.
Hardcoded password ✅ Passed No hardcoded password detected.
Auth middleware removed from route ✅ Passed No auth middleware removed from route issues detected.
Route protection changed (protected → public) ✅ Passed No route protection changed (protected → public) issues detected.
Permission / RBAC check removed ✅ Passed No permission / rbac check removed issues detected.
Required role weakened ✅ Passed No required role weakened issues detected.
Admin-only route exposed to lower privilege ✅ Passed No admin-only route exposed to lower privilege issues detected.
Token validation skipped in middleware chain ✅ Passed No token validation skipped in middleware chain issues detected.
JWT verification weakened or changed ✅ Passed No jwt verification weakened or changed issues detected.
Session expiration / TTL changed ✅ Passed No session expiration / ttl changed issues detected.
Password reset flow changed ✅ Passed No password reset flow changed issues detected.
OAuth callback / redirect handling changed ✅ Passed No oauth callback / redirect handling changed issues detected.
Webhook endpoint missing signature verification ✅ Passed No webhook endpoint missing signature verification issues detected.
Public route touches private/PII data ✅ Passed No public route touches private/pii data issues detected.
Frontend performance issue ✅ Passed No additional explanation was reported.
Frontend security issue ✅ Passed No additional explanation was reported.
Frontend correctness issue ✅ Passed No additional explanation was reported.
Accessibility issue ✅ Passed No additional explanation was reported.
Frontend maintainability issue ✅ Passed No additional explanation was reported.
Code correctness issue ✅ Passed No additional explanation was reported.
Runtime error risk ✅ Passed No runtime error risk issues remaining after verification.
Resource leak risk ✅ Passed No additional explanation was reported.
Data integrity risk ✅ Passed No additional explanation was reported.
Maintainability issue ✅ Passed No additional explanation was reported.
Co-change coupling ✅ Passed No additional explanation was reported.
Redundant alias / duplicate import ✅ Passed No additional explanation was reported.
Redundant type construct ✅ Passed No additional explanation was reported.
Unnecessary type assertion ✅ Passed No additional explanation was reported.
Module smell ✅ Passed No additional explanation was reported.
Dead export (no callers) ✅ Passed No additional explanation was reported.
Code duplication / DRY violation ✅ Passed No additional explanation was reported.
Intent vs. implementation ✅ Passed Yes — throwing beforeSend is now isolated, original requests are preserved, and documented regression coverage was added. Requirements: 4 implemented. (Intent from PR description.)
Complexity Guard ✅ Passed No additional explanation was reported.
Bundle Size Monitor ✅ Passed No additional explanation was reported.
Release Notes Curator ✅ Passed No additional explanation was reported.

This comment is updated automatically whenever Autter reviews a new PR revision.

@autter-dev

autter-dev Bot commented Oct 5, 2026

Copy link
Copy Markdown
💡 1 suggestion(s) — conventions, hardening and hygiene, not defects

Inline comments are reserved for concrete defects. These are things worth knowing that the diff does not prove wrong — a missing hardening layer, a convention the repo usually follows, a file that historically changes alongside one you touched. Skim, adopt what fits, ignore the rest.

  • 🟠 Hook-produced non-serializable data can throw from telemetry capture (risk 69/100) — packages/runtime-browser/src/index.ts:317

@autter-dev

autter-dev Bot commented Oct 5, 2026

Copy link
Copy Markdown

🤖 Release Notes Curator

Impact: patch — Isolates throwing beforeSend hooks so they only drop the event without affecting app requests.

Changelog entry (ready to paste):

Fixed an issue where an error thrown from beforeSend could interrupt app behavior — throwing now safely drops just that event while later telemetry continues to send normally.

Custom agent · runs after review · configured in Autter

@autter-dev autter-dev Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Autter posted 1 finding(s) as review threads below (🟠 1). Each carries a copy-paste AI fix prompt.

try {
const mapped = opts.beforeSend(event);
if (!mapped) return;
event = mapped;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 [deterministic] Biome: lint/style/noParameterAssign — Risk: 55/100

Reassigning a function parameter is confusing.

🛠 AI fix prompt (copy & paste into your coding agent)
Fix the Biome `lint/style/noParameterAssign` issue at packages/runtime-browser/src/index.ts:317: Reassigning a function parameter is confusing.

Flagged by Autter security & observability checks.

@autter-dev

autter-dev Bot commented Oct 5, 2026

Copy link
Copy Markdown

🧪 Autter test run

Autter checked dc1513ad.

This PR changes 2 source files. No project test command ran for the touched workspace. It also executed 4 checks from the PR's test plan.

Targeted agent checks: Autter ran targeted checks against the files this PR changed — it executed uncovered test-plan items and, where a changed file had no matching test, wrote a temporary test to verify the new behavior.

Execution summary: 8 checks executed · 8 passed.

Project test commands

No project test commands were detected in this repository.

Autter targeted verification

5 tests executed · 5 passed.

Code-level simulations

Revision dc1513ad931f · 436.7s · up to 2 scenarios in parallel

  • Throwing hook preserves an HTTP 503 response — execution incomplete (code_diff, code_diff, spec)
    Source: packages/runtime-browser/src/index.ts — return response;
    Source: packages/runtime-browser/src/index.ts — } catch {
    // A telemetry hook must not change application request outcomes.
    return;
    Source: PR description — When network capture observes an HTTP 503 response, that exception changes the application's resolved fetch into a rejection.
    Ran: node '.autter/scratch/before-send-503.mjs'
    Could not complete: Error: Simulation did not execute every planned assertion exactly once; verdict discarded.
  • Throwing hook preserves the original network rejection — passed (code_diff, code_diff, spec)
    Source: packages/runtime-browser/src/index.ts — throw error;
    Source: packages/runtime-browser/src/index.ts — } catch {
    // A telemetry hook must not change application request outcomes.
    return;
    Source: PR description — On a network failure, it also replaces the original error.
    Ran: node '.autter/scratch/throwing-hook-network-rejection.mjs'
    ✅ The fetch promise rejects with the exact original network Error object, not the hook error.: expected fetch rejection is the original network Error object; observed fetch rejection is the original network Error object (integration)
    ✅ The hook error does not escape and the affected request_failure event is not delivered.: expected hook error does not escape; no request_failure event is delivered; observed hook error escaped: false; request_failure delivered: false; sendBeacon calls: 0 (integration)
  • Manual capture APIs contain beforeSend exceptions — passed (code_diff, code_diff, spec)
    Source: packages/runtime-browser/src/index.ts — export function captureException(
    Source: packages/runtime-browser/src/index.ts — export function captureMessage(
    Source: PR description — Catch callback exceptions and drop the affected telemetry event, preserving the original request result.
    Ran: node '.autter/scratch/before-send-exceptions.mjs'
    ✅ Both void capture APIs return without throwing the beforeSend error.: expected Neither capture call throws; observed captureMessage threw: no; captureException threw: no (code)
    ✅ Neither affected event is present in any delivered payload.: expected Delivered event count for each captured message: 0; delivered payload count may be 0; observed payloads: 0; matching message events: 0; matching exception events: 0 (code)
  • XHR 5xx telemetry hook failure stays contained — passed (code_diff, code_diff, spec)
    Source: packages/runtime-browser/src/index.ts — enqueue(event, true);
    Source: packages/runtime-browser/test/before-send.test.mjs — beforeSend(event) {
    if (hookMode === "throw") throw hookError;
    Source: PR description — A throwing beforeSend callback currently escapes the browser SDK.
    Ran: node '.autter/scratch/xhr-5xx-before-send.mjs'
    ✅ The loadend capture path does not expose the beforeSend sentinel error as an uncaught hook failure.: expected loadend completes without throwing the beforeSend sentinel error; observed loadend completed without throwing (integration)
    ✅ The request_failure event is dropped and no telemetry payload contains it.: expected zero request_failure events in all flushed telemetry payloads; observed 0 request_failure event(s); observed event types: [] (integration)
    Source unavailable: Production route aggregates are unavailable: Runtime queries are not configured. No retained production error patterns were available for this repository.
    Coverage limitation: No production runtime IDs or production-pattern evidence were supplied, so scenarios use only the changed browser SDK code and PR description.
    Coverage limitation: The fake XHR scenario exercises SDK listener wiring and enqueue behavior locally; it does not emulate browser-level uncaught-exception reporting or a real browser network stack.
    Coverage limitation: No scenario requires a database; event persistence and relay/ingester integration are outside this browser-only diff.
    Coverage limitation: Scenario omitted because its source evidence could not be verified: Intentional drop and later mapped event delivery

Declared tests: 16 test file(s) found — 1 ran, 0 not observed in suite output, 15 did not run.

The project's command reported 0 of them. Autter ran the other 1 file one by one so every declared test has a verdict (1 passed, 0 failed).

"Did not run" means no test command that Autter executed covers the file, so nothing in it was checked.

⚠️ Test cases that did not run
  • ⛔ packages/otlp-ingester/src/continuous-detection.test.ts (6 cases) — no test suite covers this file
  • ⛔ packages/otlp-ingester/src/fingerprint.test.ts (10 cases) — no test suite covers this file
  • ⛔ packages/otlp-ingester/src/latency.test.ts (5 cases) — no test suite covers this file
  • ⛔ packages/otlp-ingester/src/normalize-browser.test.ts (5 cases) — no test suite covers this file
  • ⛔ packages/otlp-ingester/src/normalize.test.ts (5 cases) — no test suite covers this file
  • ⛔ packages/otlp-ingester/src/server.sink.test.ts (2 cases) — no test suite covers this file
  • ⛔ packages/otlp-ingester/src/sink.test.ts (9 cases) — no test suite covers this file
  • ⛔ packages/runtime-browser/test/client-context.test.mjs (1 case) — no test suite covers this file
  • ⛔ packages/runtime-browser/test/csp-actions.test.mjs (1 case) — no test suite covers this file
  • ⛔ packages/runtime-browser/test/network.test.mjs (1 case) — no test suite covers this file
  • ⛔ packages/runtime-browser/test/redact.test.mjs (5 cases) — no test suite covers this file
  • ⛔ packages/runtime-node/test/autoflush.test.mjs (7 cases) — no test suite covers this file
  • ⛔ packages/runtime-node/test/lifecycle.test.mjs (4 cases) — no test suite covers this file
  • ⛔ packages/runtime-node/test/redact.test.mjs (24 cases) — no test suite covers this file
  • ⛔ packages/runtime-node/test/relay.test.mjs (2 cases) — no test suite covers this file

Tests for this change

Autter ran the existing test for 1 changed file.

Change coverage (is each changed file's behavior verified by a test?)

Changed file Related test Result
packages/runtime-browser/src/index.ts packages/runtime-browser/test/before-send.test.mjs ✅ existing test passes
🤖 Coverage-check evidence

packages/runtime-browser/src/index.ts

Temporary tests are written under .autter/scratch/ for verification only — they are never committed to the repository.

Test plan (from the PR description)

  • ✅ Run npm run build -w @autter/runtime-browser and confirm clean build with no new dependencies. — verified by agent execution
  • ✅ Run npm run test -w @autter/runtime-browser and confirm new before-send.test.mjs passes. — verified by agent execution
  • ✅ Run npm run size -w @autter/runtime-browser and confirm <5 KB brotlied budget holds. — verified by agent execution
  • ✅ Manually verify with throwing beforeSend that page does not error and follow-on events still send via relay. — verified by agent execution
🤖 Agent-executed checks

✅ Run npm run build -w @autter/runtime-browser and confirm clean build with no new dependencies.
tsup ESM build success; dist/index.js 17.03 KB; DTS build success; no package manifest or lockfile changes.

✅ Run npm run test -w @autter/runtime-browser and confirm new before-send.test.mjs passes.
9 tests passed, 0 failed; beforeSend failures preserve application requests and later delivery passed.

✅ Run npm run size -w @autter/runtime-browser and confirm <5 KB brotlied budget holds.
Size limit 5 kB; measured 3.43 kB minified and brotlied.

✅ Manually verify with throwing beforeSend that page does not error and follow-on events still send via relay.
Focused scenario passed: throwing beforeSend does not throw from captureMessage, sends no dropped event, preserves fetch response/network error, and a later mapped event is delivered through mocked n…

⬜ items could not be verified automatically and still need a manual check.

@autter-dev

autter-dev Bot commented Oct 5, 2026

Copy link
Copy Markdown

Autter product walk

Autter did not drive this change in a browser.

This PR changes a backend/API, but Autter could not find a start, dev, or run command for it, so it could not boot the service and exercise its endpoints. Autter ran targeted checks only. Add a start command (a start/dev script, or make it discoverable on the repo's "How to run this" tab), and Autter exercises the endpoints on the next push.

@autter-dev autter-dev Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Autter approved #22 with notes: the merge gate is clear, and 2 non-blocking finding(s) remain as review detail. (Also detected: 4 finding(s) dismissed as likely false positives by verification.)

@autter-dev

autter-dev Bot commented Oct 5, 2026

Copy link
Copy Markdown

Autter task list

No concrete follow-up tasks were generated for this PR.

Generated from PR diff, blast radius, and context.

Issues found

No unresolved code findings remain for this revision — 4 finding(s) dismissed as likely false positives by verification. Dismissed findings stay listed with their verdicts in the Autter review dashboard.

2 additional non-blocking finding(s) are available in the Autter review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant