mirror of
https://github.com/screentinker/screentinker.git
synced 2026-08-14 14:23:14 -06:00
The number exists — every install that opts into sharing reports its screen count, and the collector has been keeping them since it went live. Nothing read them back out. GET /api/public/stats returns the aggregate: total screens and how many installs they came from. The landing page shows it under the hero and stays silent otherwise — hidden until a number arrives, so a self-hosted instance (where the route does not exist) and a brand-new one (where the count is zero) show nothing rather than an empty frame or a "0". Gated on TELEMETRY_COLLECTOR, the same flag as the collector, and the gate is doing real work here: without it, any anonymous visitor could read a private instance's screen count off its own landing page. Only the deployment that gathers the numbers may state them, and there the figure is a sum across every reporting install, so it discloses nothing about any one of them. Verified with the flag unset: both routes 404. Cached for five minutes. This sits on a public page and the number moves in hours, so a scraper in a loop costs one query per interval rather than one per request. Both endpoints moved out of server.js into routes/telemetry-collector.js as an injectable factory. They were inline and therefore untestable — an unauthenticated endpoint anyone on the internet can POST to, and the one that decides what a public page claims, with no test between them. Now covered: the upsert really updates (an install reporting daily must not become 365 rows and get counted 365 times), malformed and hostile bodies are refused without reaching the table, the aggregate carries no per-install detail, and the cache holds. 1676/1676 pass. |
||
|---|---|---|
| .. | ||
| config | ||
| db | ||
| lib | ||
| middleware | ||
| player | ||
| routes | ||
| scripts | ||
| services | ||
| test | ||
| ws | ||
| .gitignore | ||
| config.js | ||
| package-lock.json | ||
| package.json | ||
| server.js | ||
| smoke-ui.js | ||
| version.js | ||