The editor reported nothing when a session died. Evidence lived only in-tab —
an 800-line React array behind a "Show console" button — so diagnosis meant
asking a user to paste a screenshot.
Better Stack's Error Tracking ingests the Sentry wire protocol, so this runs
the stock @sentry/browser against a Better Stack DSN. Sentry.init installs its
own window error/unhandledrejection handlers, so uncaught main-thread errors
and the wasm traps that escape emscripten's DOM event handlers are captured
with no instrumentation at the throw sites. Not their JS tag: it has no
beforeSend or fingerprint hooks, its runtime spawns workers from cross-origin
CDN hosts (this page is COEP: require-corp), and it ships session replay on by
default — which on a CAD canvas records customers' board geometry.
@sentry/browser is imported in exactly one file so the vendor stays swappable,
mirroring how lib/analytics.ts isolates Plausible.
Also replaces the terminal-signature regex with a shared, unit-tested predicate
(wasm/terminal-error.ts) used by BOTH the fatal overlay and the reporter, so
they cannot disagree. The regex was a type check written as a string match and
had three live holes: `RuntimeError` was listed but never appears IN
`.message`; Chrome's bare "unreachable" and "null function" matched nothing
(the v0.1.20 prod log is exactly those); and narrowing "table index is out of
bounds" to `\bindex out of bounds` for Firefox in 197f317 silently stopped
matching Chrome's spelling. Checking the TYPE — every trap in this family is a
WebAssembly.RuntimeError — covers all engines and ends the spelling chase; the
message patterns remain as a fallback for paths that lose the Error object,
such as a worker ErrorEvent crossing the realm boundary with error: null.
197f317's pthread-worker tap, promote() and Firefox findings are kept as-is.
Notes:
- Off unless VITE_ERRORS_DSN is set AND VITE_ALLOW_USER_OVERRIDE !== "1" (dev
servers and every Playwright harness set the latter, and production builds
never do), so a production DSN in a local .env still cannot report. With no
DSN the whole SDK is const-folded out: 1,193,080 vs 1,282,463 bytes of JS.
- browserApiErrors integration removed. It wraps setTimeout/rAF/addEventListener
in try/catch, which is exactly how KiCad-on-Emscripten drives its main loop.
- Console breadcrumbs off (collab/debug.ts's clog fires per Yjs update and would
evict the ring before any crash); dom/fetch/navigation breadcrumbs kept.
- beforeSend redacts token/apiKey/Bearer — collab/provider.ts puts the collab
token in the y-partyserver URL, so a connection-failure string carries a live
credential — and guards the cascade: one wedge produced 8 errors in prod, and
after the first terminal event the rest are dropped into cascade_count.
Verified end to end against the real EU host from a cross-origin-isolated page:
POST /api/<id>/envelope/ -> 200, and 4 terminal throws produce 1 event
(control: 1 throw, same count).
Privacy policy 9, cookie policy 6 and the licenses page are updated: Better
Stack is disclosed as an EU processor, and the licenses page now describes the
browser app's own JS dependencies, which it never did.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
125 lines
5.8 KiB
YAML
125 lines
5.8 KiB
YAML
name: deploy-demo (manual re-deploy)
|
|
|
|
# MANUAL re-deploy of demo.pcbjam.com WITHOUT rebuilding/publishing WASM — it
|
|
# snapshots the WASM already in the registry into manifest-<tag>.json, publishes
|
|
# the gallery, builds the standalone, and deploys. Use it to re-ship the demo for
|
|
# an existing tag (e.g. a Pages config fix) when the WASM is already published.
|
|
#
|
|
# The tag-triggered release pipeline lives in release.yml (build -O2 → publish
|
|
# WASM → deploy), so a tag NO LONGER triggers this — this is the manual escape
|
|
# hatch only. If the registry has no WASM for the tag, the snapshot step fails
|
|
# (run release.yml, which builds + publishes). See docs/features/demo-deploy/.
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
tag:
|
|
description: "Release tag to re-deploy, e.g. v1.2.3 (WASM must already be published)"
|
|
required: true
|
|
|
|
# Serialize demo deploys so two tags don't race the live site (don't cancel a
|
|
# half-finished deploy — let it complete).
|
|
concurrency:
|
|
group: deploy-demo
|
|
cancel-in-progress: false
|
|
|
|
env:
|
|
CDN: https://cdn.pcbjam.com
|
|
BUCKET: pcbjam-cdn
|
|
# KiCad library snapshot the demo points at (published once by publish-libs.yml
|
|
# to libs/kicad/<LIB_TAG>/). Bump when moving to a newer KiCad library release.
|
|
LIB_TAG: "10.0.3"
|
|
# kicad-packages3D snapshot the demo's lazy 3D models point at (published once
|
|
# to libs/kicad-models/<MODELS_TAG>/ — see scripts/deploy/publish-models.ts +
|
|
# upload-models-r2.sh; docs/features/3d-models). Empty ⇒ 3D models off.
|
|
MODELS_TAG: "10.0.3"
|
|
PAGES_PROJECT: pcbjam-demo
|
|
# MUST be the Pages project's PRODUCTION branch — any other value makes
|
|
# `wrangler pages deploy` a PREVIEW deploy and demo.pcbjam.com won't update.
|
|
# Direct-Upload projects default to "production".
|
|
PAGES_PROD_BRANCH: production
|
|
# Better Stack error-tracking DSN. Unset ⇒ this build reports nothing.
|
|
# Keep in sync with release.yml — the demo is built from BOTH workflows, and
|
|
# setting it in only one silently ships a demo with no error reporting.
|
|
ERRORS_DSN: ${{ secrets.ERRORS_DSN }}
|
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
|
# The publish scripts shell wrangler; no repo dep — fetch it on demand.
|
|
WRANGLER_CMD: npx --yes wrangler@4
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# The standalone needs the MIT pcbjam-shared submodule, but NOT the huge
|
|
# kicad/wxwidgets ones (WASM is prebuilt on the CDN, not built here).
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
submodules: false
|
|
- name: Init pcbjam-shared submodule
|
|
run: git submodule update --init --depth 1 web/pcbjam-shared
|
|
|
|
# Pin pnpm explicitly: the repo root has no package.json, so action-setup
|
|
# can't infer the version from a packageManager field (it lives in
|
|
# web/package.json). Keep in sync with web/package.json's packageManager.
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 10.33.0
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 20
|
|
cache: pnpm
|
|
cache-dependency-path: web/pnpm-lock.yaml
|
|
|
|
- name: Install standalone workspace
|
|
run: pnpm --dir web install --frozen-lockfile
|
|
|
|
- name: Resolve tag
|
|
id: tag
|
|
# On workflow_dispatch GITHUB_REF_NAME is the branch (e.g. main), so prefer
|
|
# the explicit input; on a tag push the input is empty and ref_name is the tag.
|
|
run: echo "tag=${{ github.event.inputs.tag || github.ref_name }}" >> "$GITHUB_OUTPUT"
|
|
|
|
# 1) Reuse prebuilt WASM: snapshot the current registry into manifest-<tag>
|
|
# (no build, no upload). Fails if the WASM was never published — run
|
|
# publish-wasm.yml (or a local seed) first.
|
|
- name: Snapshot WASM manifest
|
|
run: >
|
|
node scripts/deploy/publish-wasm.mjs --tag "${{ steps.tag.outputs.tag }}"
|
|
--driver r2 --bucket "$BUCKET" --remote --from-registry
|
|
|
|
# 2) Publish the read-only example gallery (tiny; content/<tag>/).
|
|
- name: Publish content gallery
|
|
run: >
|
|
node scripts/deploy/publish-content.mjs --tag "${{ steps.tag.outputs.tag }}"
|
|
--gallery deploy/demo/gallery.json --driver r2 --bucket "$BUCKET" --remote
|
|
|
|
# 3) Build the standalone pinned to the CDN + this tag's manifests. The
|
|
# full KiCad library set is served read-only from libs/kicad/$LIB_TAG
|
|
# (published once by publish-libs.yml — run it first for a new lib tag).
|
|
- name: Build demo
|
|
# Plausible: the shared pa- script covering all pcbjam properties
|
|
# (one dashboard, segment by hostname).
|
|
run: >
|
|
node scripts/deploy/build-demo.mjs --tag "${{ steps.tag.outputs.tag }}"
|
|
--cdn "$CDN" --lib-tag "$LIB_TAG"
|
|
${MODELS_TAG:+--models-tag "$MODELS_TAG"}
|
|
--plausible "https://plausible.io/js/pa-KjNS9YmidydULZTstsjRg.js"
|
|
${ERRORS_DSN:+--errors-dsn "$ERRORS_DSN" --errors-env demo}
|
|
|
|
# 4) Ensure the Pages project exists (first deploy creates it; no-op after).
|
|
# Its production branch must equal PAGES_PROD_BRANCH or deploys land as
|
|
# previews and demo.pcbjam.com won't update.
|
|
- name: Ensure Pages project exists
|
|
run: >
|
|
npx --yes wrangler@4 pages project create "$PAGES_PROJECT"
|
|
--production-branch "$PAGES_PROD_BRANCH"
|
|
|| echo "pages project create skipped (already exists)"
|
|
|
|
# 5) Deploy to Cloudflare Pages. Attach demo.pcbjam.com to this project
|
|
# (Pages → $PAGES_PROJECT → Custom domains) for the custom domain to serve it.
|
|
- name: Deploy to Cloudflare Pages
|
|
run: >
|
|
npx --yes wrangler@4 pages deploy web/standalone/dist
|
|
--project-name "$PAGES_PROJECT"
|
|
--branch "$PAGES_PROD_BRANCH"
|
|
--commit-dirty=true
|