remove umami

Signed-off-by: Hadi <[email protected]>
This commit is contained in:
Hadi
2026-08-27 10:13:51 +02:00
parent 55c03bebfe
commit f376048495
5 changed files with 9 additions and 129 deletions
-12
View File
@@ -75,18 +75,6 @@
results = data.results; results = data.results;
totalPages = data.pagination.totalPages; totalPages = data.pagination.totalPages;
totalResults = data.pagination.totalResults; totalResults = data.pagination.totalResults;
if (typeof window !== "undefined" && (window as any).umami) {
(window as any).umami.track("search", {
query: lastQuery,
results: totalResults,
hasResults: totalResults > 0,
});
if (totalResults === 0) {
(window as any).umami.track("search_no_results", {
query: lastQuery,
});
}
}
} catch (e) { } catch (e) {
console.error("Search error:", e); console.error("Search error:", e);
results = []; results = [];
-12
View File
@@ -14,9 +14,6 @@ const {
description = "Open-source database of default credentials for pentesters and researchers. Find factory-set passwords for any device or software.", description = "Open-source database of default credentials for pentesters and researchers. Find factory-set passwords for any device or software.",
ogImage = `${Astro.site ?? "https://default-creds.hadi.icu"}/og.png` ogImage = `${Astro.site ?? "https://default-creds.hadi.icu"}/og.png`
} = Astro.props; } = Astro.props;
const umamiUrl = process.env.PUBLIC_UMAMI_URL;
const umamiId = process.env.PUBLIC_UMAMI_WEBSITE_ID;
--- ---
<html lang="en"> <html lang="en">
@@ -59,13 +56,4 @@ const umamiId = process.env.PUBLIC_UMAMI_WEBSITE_ID;
<slot /> <slot />
</div> </div>
</body> </body>
{umamiUrl && umamiId && (
<script
defer
src={`${umamiUrl}/script.js`}
data-website-id={umamiId}
is:inline
/>
)}
</html> </html>
+2 -2
View File
@@ -54,8 +54,8 @@ const SECURITY_HEADERS: Record<string, string> = {
"default-src 'self'", "default-src 'self'",
"img-src 'self' cdn.jsdelivr.net data:", "img-src 'self' cdn.jsdelivr.net data:",
"style-src 'self' 'unsafe-inline'", "style-src 'self' 'unsafe-inline'",
"script-src 'self' 'unsafe-inline' static.cloudflareinsights.com umami.hadi.icu", "script-src 'self' 'unsafe-inline' static.cloudflareinsights.com",
"connect-src 'self' cloudflareinsights.com umami.hadi.icu", "connect-src 'self' cloudflareinsights.com",
"frame-ancestors 'none'", "frame-ancestors 'none'",
].join("; "), ].join("; "),
}; };
+1 -69
View File
@@ -91,7 +91,7 @@ export function getAllData(): CredentialEntry[] {
return allResults; return allResults;
} }
export const GET: APIRoute = async ({ url, request }) => { export const GET: APIRoute = async ({ url }) => {
const query = url.searchParams.get("q")?.trim().toLowerCase() || ""; const query = url.searchParams.get("q")?.trim().toLowerCase() || "";
const page = Math.max(1, parseInt(url.searchParams.get("page") || "1")); const page = Math.max(1, parseInt(url.searchParams.get("page") || "1"));
const size = Math.min( const size = Math.min(
@@ -99,9 +99,6 @@ export const GET: APIRoute = async ({ url, request }) => {
Math.max(1, parseInt(url.searchParams.get("size") || "10")), Math.max(1, parseInt(url.searchParams.get("size") || "10")),
); );
const dnt = request.headers.get("DNT") === "1"
|| request.headers.get("Sec-GPC") === "1";
const allEntries = getAllData(); const allEntries = getAllData();
let filtered = allEntries; let filtered = allEntries;
@@ -112,15 +109,6 @@ export const GET: APIRoute = async ({ url, request }) => {
); );
} }
// NOTE: Server-side tracking is intentionally only triggered when DNT/GPC is active.
// When DNT is off, the client handles tracking via Umami's JS snippet.
// When DNT is on, the JS snippet is suppressed, so we fall back to server-side tracking
// to log search queries (query string + result count only, no user data) in order to
// identify missing manufacturers/products and improve the dataset.
if (query && dnt) {
await trackSearchServerSide(query, filtered.length);
}
const totalResults = filtered.length; const totalResults = filtered.length;
const totalPages = Math.ceil(totalResults / size); const totalPages = Math.ceil(totalResults / size);
const start = (page - 1) * size; const start = (page - 1) * size;
@@ -146,59 +134,3 @@ export const GET: APIRoute = async ({ url, request }) => {
}, },
); );
}; };
async function trackSearchServerSide(query: string, results: number) {
const umamiUrl = process.env.UMAMI_URL;
const umamiId = process.env.UMAMI_WEBSITE_ID;
if (!umamiUrl || !umamiId) return;
try {
await fetch(`${umamiUrl}/api/send`, {
method: "POST",
headers: {
"Content-Type": "application/json",
"User-Agent": "Mozilla/5.0 (compatible; default-creds-server/1.0)",
},
body: JSON.stringify({
type: "event",
payload: {
website: umamiId,
hostname: "default-creds.hadi.icu",
url: "/api/search",
name: "search",
data: {
query,
results,
hasResults: results > 0,
source: "server",
},
},
}),
});
if (results === 0) {
await fetch(`${umamiUrl}/api/send`, {
method: "POST",
headers: {
"Content-Type": "application/json",
"User-Agent": "Mozilla/5.0 (compatible; default-creds-server/1.0)",
},
body: JSON.stringify({
type: "event",
payload: {
website: umamiId,
hostname: "default-creds.hadi.icu",
url: "/api/search",
name: "search_no_results",
data: {
query,
source: "server",
},
},
}),
});
}
} catch (e) {
console.error("Umami server-side tracking failed:", e);
}
}
+6 -34
View File
@@ -5,7 +5,7 @@ import Layout from "../layouts/Layout.astro";
<Layout title="Privacy Policy"> <Layout title="Privacy Policy">
<main class="prose prose-invert max-w-3xl mx-auto"> <main class="prose prose-invert max-w-3xl mx-auto">
<h1 class="text-4xl font-black uppercase tracking-tighter text-primary">Privacy Policy</h1> <h1 class="text-4xl font-black uppercase tracking-tighter text-primary">Privacy Policy</h1>
<p class="text-base-content/50 text-sm">Last updated: March 2026</p> <p class="text-base-content/50 text-sm">Last updated: August 2026</p>
<p> <p>
Default Creds is a free, open-source tool for security researchers and pentesters. This page explains Default Creds is a free, open-source tool for security researchers and pentesters. This page explains
@@ -14,18 +14,8 @@ import Layout from "../layouts/Layout.astro";
<h2>What we collect</h2> <h2>What we collect</h2>
<p> <p>
This site uses <a href="https://umami.is" target="_blank" class="link link-primary">Umami</a>, We don't run any analytics or tracking on this site.
a privacy-focused analytics tool. Umami collects the following anonymized data:
</p> </p>
<ul>
<li>Pages visited</li>
<li>Referrer URL (where you came from)</li>
<li>Browser and operating system (aggregated)</li>
<li>Country (derived from IP, not stored)</li>
<li>Search queries submitted through the search interface</li>
</ul>
<h2>What we do NOT collect</h2>
<ul> <ul>
<li>No cookies are set — ever</li> <li>No cookies are set — ever</li>
<li>No IP addresses are stored</li> <li>No IP addresses are stored</li>
@@ -34,17 +24,11 @@ import Layout from "../layouts/Layout.astro";
<li>No data is sold or shared with third parties</li> <li>No data is sold or shared with third parties</li>
</ul> </ul>
<h2>How anonymization works</h2> <h2>Server logs</h2>
<p> <p>
Umami does not store IP addresses. Instead, it generates a daily rotating hash from your IP, Like any web server, ours may retain standard access logs (e.g. request timestamps, IP addresses,
browser, and a server-side secret. This hash is used solely to distinguish unique visits within user agents) for a short period for security and abuse-prevention purposes. These logs are not used
a single day and cannot be reversed or linked back to you. for analytics and are not retained long-term.
</p>
<h2>Data storage</h2>
<p>
All analytics data is stored on our own self-hosted server. No data is sent to third-party
analytics providers. The Umami instance is hosted at <code>umami.hadi.icu</code>.
</p> </p>
<h2>Your rights</h2> <h2>Your rights</h2>
@@ -54,18 +38,6 @@ import Layout from "../layouts/Layout.astro";
<a href="/.well-known/security.txt" class="link link-primary">security.txt</a>. <a href="/.well-known/security.txt" class="link link-primary">security.txt</a>.
</p> </p>
<h2>Do Not Track</h2>
<p>
Umami respects the <code>DNT</code> (Do Not Track) header. If your browser has DNT enabled,
no client-side analytics will be collected for your session.
</p>
<p>
However, when a search is performed, the query and whether it returned results are logged
server-side, with no user information attached (no IP, no browser, no session identifier).
This is used solely to identify missing manufacturers or products in the database and improve
the dataset.
</p>
<h2>Changes to this policy</h2> <h2>Changes to this policy</h2>
<p> <p>
If anything changes, this page will be updated with a new date at the top. If anything changes, this page will be updated with a new date at the top.