Stop CI counting as plugin downloads, and see who abandons sign-in #191
No reviewers
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda!191
Loading…
Reference in a new issue
No description provided.
Delete branch "worktree-downloads-truth"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Task: NEC-133
The KPI dashboard showed 212 plugin downloads against five accounts, all ours. This fixes why, and adds the one measurement that would show whether outsiders reach the sign-in page and give up.
Where the downloads came from
The e2e job's compat step ("The previous plugin release against this server") downloaded
main.js,manifest.jsonandstyles.cssfrom the latest public GitHub release on every run. GitHub counts each fetch as a download, and the community store shows GitHub'smanifest.jsoncount. From the step's own logs (testing this server against plugin X):No outside address has ever requested a sign-in code, so nothing suggests sign-up is broken; there has been almost no outside traffic.
Changes
git ls-remote, and the three files are cached per tag withactions/cache. A release is fetched once, not once per run.wire-structure.test.tsasserts all three properties.downloads_citable with CI's count per release, and a viewv_downloads_excluding_ci./api/kpion identitystarted→page_opened→provider/email_code→completed.email_codecomes frommail_log, not the plugin's pre-filled address.page_openedis a lower bound: the page asks for passkey options on load for autofill, so an unfinished passkey attempt can't be told apart from a page that was only seen.docs/security-model.mdnow says unfinished sign-ins are counted.Verified locally
pnpm test,pnpm -r typecheck,pnpm lintandbuild-dashboard --checkall pass.main's schema:ls-remotelookup returns0.2.1for the real repo, and fails with no output for a missing one.auth_flows.email, ranking autofill above a provider choice, and dropping the forward-only guard (in both the unit test and the database).Changelog
NONE
🤖 Generated with Claude Code
https://claude.ai/code/session_01MY63BZ4UVtMHFcADNr1jFg