import type { CapturedNetworkRequest, SessionRecordingOptions } from 'common' /** * Enables session replay in Studio. Recording also requires "Record user * sessions" in PostHog, which www and docs share. */ export const IS_SESSION_REPLAY_ENABLED = process.env.NEXT_PUBLIC_POSTHOG_SESSION_REPLAY === 'true' /** * Setting `data-ph-capture="true"` on an element opts its text in to session * recording. All text is opted out by default. */ const CAPTURE_DATASET_KEY = 'phCapture' /** * Returns asterisks for all text except text inside elements marked * `data-ph-capture="true"`. */ export function maskReplayText(text: string, element?: HTMLElement): string { if (element?.dataset[CAPTURE_DATASET_KEY] === 'true') return text return '*'.repeat(text.trim().length) } const SVG_NAMESPACE = 'http://www.w3.org/2000/svg' const HTML_NAMESPACE = 'http://www.w3.org/1999/xhtml' /** * Masked attributes collapse to one asterisk rather than one per character. Attribute * length has no effect on how replay lays the page out, so preserving it would publish * the length of every bucket name, title and URL for nothing. Text nodes still mask * per-character, where the width does affect layout. */ function mask(_value: string): string { return '*' } /** * Attributes whose value is CSS, so `url()` has to be masked inside them. * * `_cssText` is deliberately absent. rrweb puts inlined stylesheet text there, which in * Studio is our own build output: `fonts.css` points at font files and `grid.css` draws * the data grid's checkbox marks from `data:` URIs, so masking those targets costs the * replay its fonts and its checkboxes. The customer content this function exists for * rides in inline `style` attributes, which stay masked. * * Allowing `_cssText` through does not widen what gets recorded. rrweb only sets it for a * ``, or for a `