Skip to content

Commit 6805b09

Browse files
Tsvetan StoychevTsvetan Stoychev
authored andcommitted
Add query string privacy setting
1 parent 784b2bf commit 6805b09

19 files changed

Lines changed: 446 additions & 115 deletions

‎README.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -51,6 +51,12 @@ so HTTP beacon URLs are automatically upgraded to HTTPS.
5151

5252
### Visitor Privacy
5353

54+
**Strip Query Strings** is disabled by default. When enabled, it replaces
55+
complete query strings in page, navigation, referrer, and resource URLs with
56+
`?qs-redacted` before beacons are sent. URL paths remain visible. With this
57+
setting disabled, beacons can include complete query strings, so review whether
58+
site URLs contain personal or sensitive information.
59+
5460
Basicrum supports two observable loading policies under **Basicrum > Visitor
5561
Privacy**:
5662

‎docs/audits/checklist.md‎

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -9,19 +9,19 @@ operator-journey defect, P3 = minor/polish.
99

1010
## A. Plugin engineering
1111

12-
- [ ] P0 Regenerate translation catalogs and commit (`make translations`).
13-
The stale POT is COMMITTED at `0ec392e`: the CI translations job fails on
14-
main and blocks the `package` job (`needs: translations`). Everything else
15-
in this backlog that touches strings should regenerate catalogs in the
16-
same change. (privacy 5 / DISC-10, lab-elevated)
17-
- [ ] P1 Set `strip_query_string: true` in `Assets::build_config_js()`.
18-
Lab-verified: this single flag redacts `u`, `nu`, `r`, AND `restiming`
12+
- [x] P0 Regenerate translation catalogs and commit (`make translations`).
13+
Completed in `784b2bf`. Two consecutive generations produced identical
14+
catalogs, and the translation CI gate passed after push. (privacy 5 /
15+
DISC-10, lab-elevated)
16+
- [ ] P1 Make `strip_query_string` a first-class Visitor Privacy setting,
17+
disabled by default by product decision and emitted as a Boomerang boolean.
18+
When enabled, this flag redacts `u`, `nu`, `r`, and `restiming`
1919
(`?qs-redacted`) - no separate ResourceTiming measure is needed for query
20-
strings. Optionally expose `ResourceTiming.trimUrls` for PATH-level
21-
redaction (order IDs in `/checkout/order-received/11/` survive
22-
query-stripping). Add a negative beacon test with a planted token
23-
(`?s=SECRET`) asserting the token appears in no beacon field. (privacy 1 /
24-
DF-07)
20+
strings. URL paths remain and may need a future `ResourceTiming.trimUrls`
21+
policy. Add a real-bundle negative beacon test with planted document and
22+
resource tokens, asserting the token appears in no beacon field.
23+
Implementation and verification are complete in the working tree; keep this
24+
item open until the change is committed. (privacy 1 / DF-07)
2525
- [ ] P1 Apply the opt-out race fix. Port the deterministic test from the
2626
temporary worktree before cleaning it up. The minimum fix should null
2727
`basicRumBoomerangConfig`; do not add the proposed `optedOut` marker or any

‎plugins/basicrum/languages/basicrum-bg_BG.po‎

Lines changed: 61 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ msgstr ""
1717

1818
#. Plugin Name of the plugin
1919
#: basicrum.php
20-
#: src/Admin/Privacy.php:71
20+
#: src/Admin/Privacy.php:78
2121
msgid "Basicrum - Real User Monitoring"
2222
msgstr ""
2323

@@ -37,7 +37,7 @@ msgid "https://www.basicrum.com/contact/"
3737
msgstr "https://www.basicrum.com/contact/"
3838

3939
#: src/Admin/Settings/Page.php:93
40-
#: src/Admin/Settings/Page.php:468
40+
#: src/Admin/Settings/Page.php:480
4141
msgid "Basicrum Settings"
4242
msgstr ""
4343

@@ -77,83 +77,83 @@ msgstr ""
7777
msgid "Boomerang Version"
7878
msgstr ""
7979

80-
#: src/Admin/Settings/Page.php:321
80+
#: src/Admin/Settings/Page.php:333
8181
msgid "Performance"
8282
msgstr ""
8383

84-
#: src/Admin/Settings/Page.php:328
84+
#: src/Admin/Settings/Page.php:340
8585
msgid "Wait After Onload"
8686
msgstr ""
8787

88-
#: src/Admin/Settings/Page.php:334
88+
#: src/Admin/Settings/Page.php:346
8989
msgid "Delay beacon sending until after page load completes."
9090
msgstr ""
9191

92-
#: src/Admin/Settings/Page.php:340
92+
#: src/Admin/Settings/Page.php:352
9393
msgid "Delay (milliseconds)"
9494
msgstr ""
9595

96-
#: src/Admin/Settings/Page.php:346
96+
#: src/Admin/Settings/Page.php:358
9797
msgid "Milliseconds to delay the beacon after onload. Leave 0 to disable the delay."
9898
msgstr ""
9999

100-
#: src/Admin/Settings/Page.php:377
100+
#: src/Admin/Settings/Page.php:389
101101
msgid "Developer Settings"
102102
msgstr ""
103103

104-
#: src/Admin/Settings/Page.php:354
104+
#: src/Admin/Settings/Page.php:366
105105
msgid "Script Position"
106106
msgstr ""
107107

108-
#: src/Admin/Settings/Page.php:360
108+
#: src/Admin/Settings/Page.php:372
109109
msgid "Where to insert the monitoring script."
110110
msgstr ""
111111

112-
#: src/Admin/Settings/Page.php:362
112+
#: src/Admin/Settings/Page.php:374
113113
msgid "Header (wp_head)"
114114
msgstr ""
115115

116-
#: src/Admin/Settings/Page.php:363
116+
#: src/Admin/Settings/Page.php:375
117117
msgid "Footer (wp_footer)"
118118
msgstr ""
119119

120-
#: src/Admin/Settings/Page.php:396
120+
#: src/Admin/Settings/Page.php:408
121121
msgid "Use Unminified Loaders"
122122
msgstr ""
123123

124-
#: src/Admin/Settings/Page.php:402
124+
#: src/Admin/Settings/Page.php:414
125125
msgid "Load unminified JavaScript loaders for debugging."
126126
msgstr ""
127127

128-
#: src/Admin/Settings/Page.php:690
128+
#: src/Admin/Settings/Page.php:702
129129
msgid "~30 KB gzipped"
130130
msgstr ""
131131

132-
#: src/Admin/Settings/Page.php:722
132+
#: src/Admin/Settings/Page.php:734
133133
msgid "Example:"
134134
msgstr ""
135135

136-
#: src/Admin/Settings/Validate.php:116
136+
#: src/Admin/Settings/Validate.php:119
137137
msgid "Beacon URL was automatically upgraded to HTTPS."
138138
msgstr ""
139139

140-
#: src/Admin/Settings/Validate.php:125
140+
#: src/Admin/Settings/Validate.php:128
141141
msgid "Invalid Beacon URL. The default URL has been restored."
142142
msgstr ""
143143

144-
#: src/Admin/Settings/Validate.php:151
144+
#: src/Admin/Settings/Validate.php:154
145145
msgid "Invalid Brum Site ID. Copy it from the Basicrum backoffice and try again."
146146
msgstr "Невалиден Brum Site ID. Копирайте го от административния панел на Basicrum и опитайте отново."
147147

148-
#: src/Admin/Settings/Validate.php:178
148+
#: src/Admin/Settings/Validate.php:181
149149
msgid "Delay cannot exceed 30000 milliseconds. It has been capped at 30000."
150150
msgstr ""
151151

152-
#: src/Admin/Settings/Page.php:390
152+
#: src/Admin/Settings/Page.php:402
153153
msgid "Allow HTTP beacon URLs for local testing. Do not enable this on production sites."
154154
msgstr ""
155155

156-
#: src/Admin/Settings/Page.php:384
156+
#: src/Admin/Settings/Page.php:396
157157
msgid "HTTP Strictness"
158158
msgstr ""
159159

@@ -162,19 +162,19 @@ msgid "Basicrum could not start because its Composer dependencies are missing. R
162162
msgstr ""
163163

164164
#. translators: %s: Link to the Basicrum settings page.
165-
#: src/Admin/Settings/Page.php:473
165+
#: src/Admin/Settings/Page.php:485
166166
#, php-format
167167
msgid "Basicrum monitoring is enabled but inactive because the Beacon URL and Brum Site ID are missing. Configure them in %s."
168168
msgstr ""
169169

170170
#. translators: %s: Link to the Basicrum settings page.
171-
#: src/Admin/Settings/Page.php:476
171+
#: src/Admin/Settings/Page.php:488
172172
#, php-format
173173
msgid "Basicrum monitoring is enabled but inactive because the Beacon URL is missing. Configure it in %s."
174174
msgstr ""
175175

176176
#. translators: %s: Link to the Basicrum settings page.
177-
#: src/Admin/Settings/Page.php:479
177+
#: src/Admin/Settings/Page.php:491
178178
#, php-format
179179
msgid "Basicrum monitoring is enabled but inactive because the Brum Site ID is missing. Configure it in %s."
180180
msgstr ""
@@ -203,27 +203,23 @@ msgstr ""
203203
msgid "Suggested text:"
204204
msgstr ""
205205

206-
#: src/Admin/Privacy.php:64
206+
#: src/Admin/Privacy.php:71
207207
msgid "Monitoring is configured to start immediately on eligible pages without waiting for a consent signal."
208208
msgstr ""
209209

210210
#: src/Admin/Settings/Page.php:265
211211
msgid "Visitor Privacy"
212212
msgstr ""
213213

214-
#: src/Admin/Settings/Page.php:272
214+
#: src/Admin/Settings/Page.php:284
215215
msgid "Monitoring Start"
216216
msgstr ""
217217

218-
#: src/Admin/Settings/Page.php:285
218+
#: src/Admin/Settings/Page.php:297
219219
msgid "Load immediately"
220220
msgstr ""
221221

222-
#: src/Admin/Settings/Page.php:309
223-
msgid "Choose when monitoring starts. Basicrum does not display a consent popup, determine your legal basis, or make a site compliant by itself."
224-
msgstr ""
225-
226-
#: src/Admin/Settings/Page.php:716
222+
#: src/Admin/Settings/Page.php:728
227223
msgid "Consent Tool Integration"
228224
msgstr ""
229225

@@ -236,56 +232,76 @@ msgid "This site uses Basicrum to measure real-user performance. When monitoring
236232
msgstr ""
237233

238234
#. translators: %s: Configured Basicrum beacon URL.
239-
#: src/Admin/Privacy.php:54
235+
#: src/Admin/Privacy.php:61
240236
#, php-format
241237
msgid "When monitoring runs, performance data is sent to the collector configured at %s."
242238
msgstr ""
243239

244-
#: src/Admin/Settings/Page.php:278
240+
#: src/Admin/Settings/Page.php:290
245241
msgid "Select when Boomerang may load on an eligible page."
246242
msgstr ""
247243

248-
#: src/Admin/Settings/Page.php:286
244+
#: src/Admin/Settings/Page.php:298
249245
msgid "Boomerang loads on eligible pages without waiting for a consent signal. This may set cookies and send performance data. Use this only when your site is permitted to monitor without prior consent."
250246
msgstr ""
251247

252-
#: src/Admin/Settings/Page.php:720
248+
#: src/Admin/Settings/Page.php:732
253249
msgid "The callbacks are registered at the configured Script Position. Load the consent integration after that point; calls made before registration are not replayed."
254250
msgstr ""
255251

256-
#: src/Admin/Settings/Page.php:281
252+
#: src/Admin/Settings/Page.php:293
257253
msgid "Follow external consent tool"
258254
msgstr ""
259255

260-
#: src/Admin/Settings/Page.php:282
256+
#: src/Admin/Settings/Page.php:294
261257
msgid "Boomerang follows the current allow or deny decision reported by your consent or cookie tool on each page."
262258
msgstr ""
263259

264-
#: src/Admin/Settings/Page.php:717
260+
#: src/Admin/Settings/Page.php:729
265261
msgid "When \"Follow external consent tool\" is selected, connect the example below to your consent or cookie tool. Call one of the two callbacks on every page after the Basicrum consent loader is available."
266262
msgstr ""
267263

268-
#: src/Admin/Settings/Page.php:718
264+
#: src/Admin/Settings/Page.php:730
269265
msgid "Call when the external tool reports that performance monitoring is allowed. This executes the standard Boomerang loader."
270266
msgstr ""
271267

272-
#: src/Admin/Settings/Page.php:721
268+
#: src/Admin/Settings/Page.php:733
273269
msgid "Basicrum does not persist consent across page loads or in its own cookie or server-side record, and it does not display a consent popup. Your consent tool remains the source of truth. A region-aware tool may report allowed before visitor interaction in an opt-out region. If consent is withdrawn after Boomerang loading starts, reload the page before granting it again."
274270
msgstr ""
275271

276-
#: src/Admin/Privacy.php:62
272+
#: src/Admin/Privacy.php:69
277273
msgid "Monitoring is configured to follow the site's consent tool on every page. Basicrum does not persist consent across page loads or in its own cookie or server-side record. The consent tool may report monitoring as allowed before visitor interaction where an opt-out policy applies. Signaling denial, expiry, or withdrawal stops future browser collection but does not retract data already sent."
278274
msgstr ""
279275

280-
#: src/Admin/Settings/Validate.php:204
276+
#: src/Admin/Settings/Validate.php:207
281277
msgid "Invalid monitoring start value. Basicrum will follow the external consent tool."
282278
msgstr ""
283279

284-
#: src/Admin/Settings/Page.php:719
280+
#: src/Admin/Settings/Page.php:731
285281
msgid "Call when the external tool reports that monitoring is denied or that permission has expired or been withdrawn. Basicrum disables loaded collection and attempts to remove the Boomerang RT and BA cookies, but it cannot retract data already sent."
286282
msgstr ""
287283

288284
#. Description of the plugin
289285
#: basicrum.php
290286
msgid "Privacy-first Real User Monitoring with consent-controlled loading, page types, and Web Vitals."
291287
msgstr ""
288+
289+
#: src/Admin/Privacy.php:54
290+
msgid "Query-string stripping is disabled, so page, navigation, referrer, and resource URLs may include complete query strings. Review whether your URLs can contain personal or sensitive information before using this configuration."
291+
msgstr ""
292+
293+
#: src/Admin/Settings/Page.php:272
294+
msgid "Strip Query Strings"
295+
msgstr ""
296+
297+
#: src/Admin/Settings/Page.php:321
298+
msgid "Control URL query-string handling and choose when monitoring starts. Basicrum does not display a consent popup, determine your legal basis, or make a site compliant by itself."
299+
msgstr ""
300+
301+
#: src/Admin/Privacy.php:52
302+
msgid "Basicrum is configured to replace complete query strings in page, navigation, referrer, and resource URLs with the marker ?qs-redacted before sending beacons. URL paths are still collected."
303+
msgstr ""
304+
305+
#: src/Admin/Settings/Page.php:278
306+
msgid "When enabled, replace complete query strings in page, navigation, referrer, and resource URLs with ?qs-redacted before sending beacons. URL paths are still collected."
307+
msgstr ""

0 commit comments

Comments
 (0)