Repository navigation
usertest: per-tester log lines, token redaction, findings to a private triage repo - #190
Merged
Merged
Conversation
…e repo - The collector tags each line with a salted hash of the sender's address and redacts credentials in URLs (plugin stack traces carried the host's view token). The moderator keeps its tester's hashes and only hears those lines (plus atomic-server's), so sessions can run concurrently. - When a session ends, analyze.mjs turns the transcript, log lines and up to 12 screenshots into anonymized findings (claude-opus-5, effort high), written as findings.json/findings.md in the session folder. With /etc/github-findings.env (a fine-grained token, Issues on ontola/usertest-findings only) they are filed there as issues for Michiel's triage. Nothing goes to a public repo without his `approved`. Checked on the droplet: session 1 gave 6 findings in 34 s (about 2,000 tokens in, 2,400 out), without the tester's name; a test log line got a client hash and its token redacted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Makes moderated user-testing sessions (#185) produce findings without anyone copying files around, and keeps publication gated.
Per-tester log lines
client, a salted hash (/etc/usertest-salt.env, created bycollector/run.sh) of the sender's address. No addresses are stored.token=,code=,key=and a few more) with[redacted]. Plugin stack traces carried the host's view token.Findings
moderator/analyze.mjsruns when a session ends (the page ends it, or the moderator's[END]). It sends the transcript, the log lines and up to 12 screenshots toclaude-opus-5(efforthigh).findings.jsonandfindings.mdinto the session folder. The prompt forbids names, email addresses and calendar content, andscrub()removes the tester's name, email addresses and URL queries./etc/github-findings.env(a fine-grained token, Issues read/write on the privateontola/usertest-findingsonly, to be created and saved by Michiel), each finding becomes an issue there, labeledtooling,atomic-pluginsoratomic-server. Without the file, findings stay on the droplet.approvedin that private repo.docker exec usertest-moderator node analyze.mjs <id> [--file]analyzes a session that ended without the page saying so.Checked on the droplet
/logline got aclienthash, and itstoken=became[redacted].Not verified yet: filing into the private repo, which needs the token, and two concurrent sessions.
🤖 Generated with Claude Code