aidenybai / aidenybai/react-scan

Unconditional version-check fetch to react-grab.com on start() with no opt-out

Offen
#472 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
TypeScript
Sterne
21.8k
Forks
390
Ø Merge
23 Min.
Gemergte PRs (30 T.)
1

Beschreibung

## Summary

`packages/scan/src/web/utils/check-react-grab-version.ts:14-37` (called from `packages/scan/src/core/index.ts:470`) fetches:

```
https://www.react-grab.com/api/version?source=react-scan&v=&t=
```

on every `start()`. This is a non-consented phone-home that leaks visitor IP/UA to a third-party domain, and there is **no opt-out flag**.

## Mitigating factors

- `start()` early-returns in production builds (`core/index.ts:462-468`) unless `dangerouslyForceRunInProduction`, so this mainly fires in dev.
- Payload is minimal (version + timestamp), but IP/UA are inherent to any HTTP request.

## Suggested fix

1. Gate behind the same telemetry/DO_NOT_TRACK conventions used elsewhere in the ecosystem (react-grab CLI honors `DO_NOT_TRACK`; react-doctor has `--no-telemetry`).
2. Document the ping in the README regardless.

Note: `react-scan/lite` already does this exactly right — event POSTing is strictly opt-in, and `lite.test.ts:83-84` asserts lite never touches `fetch`/`XHR`. Applying the same philosophy to the version check would make the package consistent.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.