aidenybai / aidenybai/react-scan
Unconditional version-check fetch to react-grab.com on start() with no opt-out
- Lingua principale
- TypeScript
- Stelle
- 21.8k
- Fork
- 390
- Merge medio
- 23m
- PR unite (30g)
- 1
Descrizione
## Summary
`packages/scan/src/web/utils/check-react-grab-version.ts:14-37` (called from `packages/scan/src/core/index.ts:470`) fetches:
```
https://www.react-grab.com/api/version?source=react-scan&v=&t=
```
on every `start()`. This is a non-consented phone-home that leaks visitor IP/UA to a third-party domain, and there is **no opt-out flag**.
## Mitigating factors
- `start()` early-returns in production builds (`core/index.ts:462-468`) unless `dangerouslyForceRunInProduction`, so this mainly fires in dev.
- Payload is minimal (version + timestamp), but IP/UA are inherent to any HTTP request.
## Suggested fix
1. Gate behind the same telemetry/DO_NOT_TRACK conventions used elsewhere in the ecosystem (react-grab CLI honors `DO_NOT_TRACK`; react-doctor has `--no-telemetry`).
2. Document the ping in the README regardless.
Note: `react-scan/lite` already does this exactly right — event POSTing is strictly opt-in, and `lite.test.ts:83-84` asserts lite never touches `fetch`/`XHR`. Applying the same philosophy to the version check would make the package consistent.
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.