Skip to content

fix: backport recent v2 beta fixes to 1.x - #932

Merged
harlan-zw merged 3 commits into
1.xfrom
fix/1x-recent-beta-backports
Sep 28, 2026
Merged

harlan-zw merged 3 commits into
1.xfrom
fix/1x-recent-beta-backports

Conversation

@harlan-zw

Copy link
Copy Markdown
Collaborator

🔗 Linked issue

Related to #925.

📚 Description

1.x still queues Meta Pixel consent changes behind the default consent state.
It also forces an initial PageView and guesses some registry keys during bundling.
Google Maps overlays render different nodes on the server and client.
This backports #930, #931, #926, and the Google Maps part of #914.

The three affected paths: registry lookup, Meta Pixel commands, and Google Maps hydration

🤖 AI disclosure: Harlan Agent Kit modified this description. My AI open-source policy.

Keep consent changes effective before Meta Pixel loads, let callers own PageView tracking, and use canonical registry keys during bundling. Render Google Maps overlays consistently during hydration.
@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
scripts-playground Ready Ready Preview Sep 28, 2026 2:29pm UTC

Request Review

@pkg-pr-new

pkg-pr-new Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@nuxt/scripts@932

commit: ba0a6e7

@harlan-zw harlan-zw added harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. labels Sep 28, 2026
@harlan-zw

harlan-zw commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator Author

🤖 MERGED

Harlan Agent Kit posted this automated review. It is not Harlan's personal review or approval. AI open source policy. Last updated: 2026-09-28 15:07 UTC.

GitHub merged this pull request.

  • ScriptGoogleMapsHeatmapLayer still SSR/client hydration-mismatches; the fix skipped it. View code Next: Replace the empty template with defineOptions({ render: () => null }) exactly like the other overlay components, and add the layer to the map-hydration fixture page.

No Repair remains on the default branch: Finding is false at this head. The worktree starts at the current default branch (origin/main, v2) at b4f097c, where ScriptGoogleMapsHeatmapLayer.vue does not exist: it was removed by 2db3380 'refa

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 73ef7148-38a2-4a5e-b249-39c2b28127a4

📥 Commits

Reviewing files that changed from the base of the PR and between 380c375 and ba0a6e7.

📒 Files selected for processing (3)
  • package.json
  • test/fixtures/tiktok-pixel/nuxt.config.ts
  • test/unit/tiktok-pixel-bundle-proxy.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

The changes add a trackPageView option and adjust Meta Pixel consent-call ordering. Registry integration composables now prefer a configured registry key. Google Maps child components use null render functions, with an end-to-end test for hydration messages.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to ba0a6

The supplied evidence identifies no issue that needs resolution before merge. Normal checks can proceed.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to ba0a6

A consent grant made before Meta Pixel finishes loading can move ahead of tracking events recorded while consent was denied. Whether those earlier events are subsequently sent depends on the pixel SDK, so this is a meaningful privacy risk rather than a verified disclosure.

Retained concerns

  • Medium · security · inferred: With default consent denied, a grant before SDK load replaces the queued denial and moves ahead of PageView and other events queued while consent was denied. Those earlier events may therefore be replayed under granted consent rather than their event-time consent state.
Security review details

Security Blast Radius

  • inferred — The plausible exposure is browser-side tracking for sites using this Meta Pixel integration, specifically events queued before SDK load followed by a consent grant. The source shows no new server credential, tenant-wide state, or remotely callable entrypoint.

Security Findings and Attack Paths

  • inferred — A visitor's grant, conveyed through the application's consent API before SDK load, can become the first queued command even when PageView or a caller-issued event was queued under default denial. Whether Meta then transmits those earlier events was not established by the queue-only test.

Trust Boundaries and Controls

  • observed — Application consent calls cross into the browser's Meta command queue, whose eventual consumer is the external pixel SDK. The new proxy tests, by contrast, use hardcoded inputs and mocked upstream responses; they do not expose that production boundary to a new caller.

Resilience and Maintainability Implications

  • inferred — Repeated pre-load consent changes converge on the last command, while post-load calls take the direct callMethod path. The available test verifies only the pre-load queue, not interrupted loading, SDK replay, or resulting network requests.

Hardening Proposals

  • proposed — For deployments requiring consent at event time, verify SDK replay and network behavior for denial followed by pre-load grant; avoid replaying events recorded during denial, or defer their creation until consent. The documented load gate addresses the separate requirement not to request the SDK before opt-in.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 9 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly states that the pull request backports recent v2 beta fixes to the 1.x branch. It is concise and directly matches the changeset.
Description check ✅ Passed The description accurately identifies the affected areas: Meta Pixel consent ordering and PageView behavior, registry key resolution, and Google Maps hydration. It also references the related backport…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 9 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The canonical registry key now activates bundling for TikTok Pixel. Keep the protocol fixture on the direct SDK path and cover proxy rewriting separately.
@harlan-zw harlan-zw added harlan-agent-blocked The automated Review found a material defect in this head commit. harlan-agent-running An Agent holds a Task on this issue or pull request right now. and removed harlan-agent-running An Agent holds a Task on this issue or pull request right now. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. harlan-agent-blocked The automated Review found a material defect in this head commit. labels Sep 28, 2026
@harlan-zw harlan-zw removed the harlan-agent-running An Agent holds a Task on this issue or pull request right now. label Sep 28, 2026
@harlan-zw harlan-zw added the harlan-agent-running An Agent holds a Task on this issue or pull request right now. label Sep 28, 2026
@harlan-zw
harlan-zw merged commit bdd333d into 1.x Sep 28, 2026
17 checks passed
@harlan-zw
harlan-zw deleted the fix/1x-recent-beta-backports branch September 28, 2026 14:38
@harlan-zw harlan-zw added harlan-agent-running An Agent holds a Task on this issue or pull request right now. and removed harlan-agent-running An Agent holds a Task on this issue or pull request right now. labels Sep 28, 2026

This branch was successfully deployed

1 active deployment
Preview — ba0a6e74 Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant