Skip to content

[High] Integrate error monitoring with source maps, release tagging and PII scrubbing behind a pluggable reporter #511

Description

@james2177

Category: DevOps, CI/CD & Observability

Description: GlobalErrorCapture and useGlobalErrorCapture capture errors, but reporting is not tied to releases or source maps. Add a reporter interface (Sentry-compatible implementation included, optional) with source map upload, release tagging, breadcrumbs and strict scrubbing.

Problem Statement & Context: Minified stack traces are unactionable; without release tags regressions cannot be attributed to deploys; wallet-integrated apps must never send addresses or XDR to third parties.

Scope & Acceptance Criteria:

  • ErrorReporter interface with capture(error, context), addBreadcrumb(), setRelease(); default no-op; Sentry adapter enabled only when DSN configured and telemetry consent granted.
  • beforeSend scrubber reuses secureLogger redaction (addresses, XDR, tokens, query strings) and drops request bodies; breadcrumbs limited to route changes, API call paths/status (no bodies), wallet state transitions (no addresses) and toasts (message keys only).
  • Source maps generated in production builds (productionBrowserSourceMaps or upload-only) and uploaded in the deploy workflow keyed by the release id; maps are not publicly served.
  • Error boundaries (error.tsx, global-error.tsx) show a support code (event id) users can copy; documented triage playbook.
  • Out of scope: alert routing/on-call setup.

Implementation Guidelines (Suggested Execution):

  1. Key Files/Modules: src/components/GlobalErrorCapture.tsx, src/hooks/useGlobalErrorCapture.ts, src/app/**/error.tsx, new src/app/global-error.tsx, .github/workflows/deploy.yml, next.config.mjs.
  2. Design/Architecture: Reporter selected by config; adapters lazy-loaded to avoid bundle cost when disabled.
  3. Edge Cases/Constraints: error storms (rate limiting/deduplication), cross-origin script errors, ad-blockers, CSP connect-src for the DSN host only when enabled.
  4. Testing: Scrubber tests with hostile fixtures; reporter selection tests; e2e verifying an induced error yields a support code and (with a mock sink) a scrubbed payload.

Definition of "Done": Baseline DoD, plus documented setup steps and a sample scrubbed event.

Resources: Sentry Next.js docs (source maps/beforeSend), src/hooks/useGlobalErrorCapture.test.ts.

Complexity: High (200 points)

Baseline Definition of Done (applies to every Wave issue)

Each issue's own "Definition of Done" is in addition to this baseline:

  • Code, tests and documentation are included in one PR that references the issue.
  • npm run lint, npm run typecheck, npm test, npm run check:i18n and npm run check:editorconfig pass locally and in CI. (If a command is broken by pre-existing repo debris, see the Repository Health & Build Integrity issues — do not silence the check; note the blocker in the PR.)
  • No new any, no // @ts-ignore / eslint-disable without a justification comment, and no new console.* (use secureLogger from src/lib/secureLogging.ts).
  • All new user-facing strings go through the i18n catalog (src/lib/i18n/messages/en.ts and es.ts).
  • New interactive UI is keyboard-operable, has visible focus, correct ARIA semantics, and works in both the dark and light palettes defined in src/app/globals.css.
  • UI changes include before/after screenshots (desktop and ~400px mobile). Behaviour changes include a short screen recording or test output.
  • Relevant docs under docs/ (and README.md if routes/scripts/env vars change) are updated.
  • The PR is reviewed and approved by a maintainer listed in .github/CODEOWNERS.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    complexity: highHigh complexity Drips Wave issue (200 points)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions