aidenybai / aidenybai/react-scan

Unconditional version-check fetch to react-grab.com on start() with no opt-out

オープン
#472 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
TypeScript
スター
21.8k
フォーク
390
平均マージ
23分
マージ済み PR(30日)
1

説明

## Summary

`packages/scan/src/web/utils/check-react-grab-version.ts:14-37` (called from `packages/scan/src/core/index.ts:470`) fetches:

```
https://www.react-grab.com/api/version?source=react-scan&v=&t=
```

on every `start()`. This is a non-consented phone-home that leaks visitor IP/UA to a third-party domain, and there is **no opt-out flag**.

## Mitigating factors

- `start()` early-returns in production builds (`core/index.ts:462-468`) unless `dangerouslyForceRunInProduction`, so this mainly fires in dev.
- Payload is minimal (version + timestamp), but IP/UA are inherent to any HTTP request.

## Suggested fix

1. Gate behind the same telemetry/DO_NOT_TRACK conventions used elsewhere in the ecosystem (react-grab CLI honors `DO_NOT_TRACK`; react-doctor has `--no-telemetry`).
2. Document the ping in the README regardless.

Note: `react-scan/lite` already does this exactly right — event POSTing is strictly opt-in, and `lite.test.ts:83-84` asserts lite never touches `fetch`/`XHR`. Applying the same philosophy to the version check would make the package consistent.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。