Skip to content

usertest: per-tester log lines, token redaction, findings to a private triage repo - #190

Merged
michielbdejong merged 1 commit into
mainfrom
claude/usertest-findings
Sep 28, 2026
Merged

michielbdejong merged 1 commit into
mainfrom
claude/usertest-findings

Conversation

@michielbdejong

Copy link
Copy Markdown
Contributor

Makes moderated user-testing sessions (#185) produce findings without anyone copying files around, and keeps publication gated.

Per-tester log lines

  • The collector tags each line with client, a salted hash (/etc/usertest-salt.env, created by collector/run.sh) of the sender's address. No addresses are stored.
  • It also replaces credentials in URLs (token=, code=, key= and a few more) with [redacted]. Plugin stack traces carried the host's view token.
  • The moderator remembers the hashes its tester's page came from and only passes those lines to Claude (atomic-server's own lines are always included). Two testers at the same time no longer hear about each other's errors.

Findings

  • moderator/analyze.mjs runs when a session ends (the page ends it, or the moderator's [END]). It sends the transcript, the log lines and up to 12 screenshots to claude-opus-5 (effort high).
  • It writes anonymized findings.json and findings.md into the session folder. The prompt forbids names, email addresses and calendar content, and scrub() removes the tester's name, email addresses and URL queries.
  • With /etc/github-findings.env (a fine-grained token, Issues read/write on the private ontola/usertest-findings only, to be created and saved by Michiel), each finding becomes an issue there, labeled tooling, atomic-plugins or atomic-server. Without the file, findings stay on the droplet.
  • Nothing reaches a public repository until Michiel labels a finding approved in that private repo.
  • docker exec usertest-moderator node analyze.mjs <id> [--file] analyzes a session that ended without the page saying so.

Checked on the droplet

Not verified yet: filing into the private repo, which needs the token, and two concurrent sessions.

🤖 Generated with Claude Code

…e repo

- The collector tags each line with a salted hash of the sender's address
  and redacts credentials in URLs (plugin stack traces carried the host's
  view token). The moderator keeps its tester's hashes and only hears
  those lines (plus atomic-server's), so sessions can run concurrently.
- When a session ends, analyze.mjs turns the transcript, log lines and up
  to 12 screenshots into anonymized findings (claude-opus-5, effort high),
  written as findings.json/findings.md in the session folder. With
  /etc/github-findings.env (a fine-grained token, Issues on
  ontola/usertest-findings only) they are filed there as issues for
  Michiel's triage. Nothing goes to a public repo without his `approved`.

Checked on the droplet: session 1 gave 6 findings in 34 s (about 2,000
tokens in, 2,400 out), without the tester's name; a test log line got a
client hash and its token redacted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@michielbdejong
michielbdejong merged commit c10bee7 into main Sep 28, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant