[privacy] remove Community Chatwoot Hub egress

Remove Community Chatwoot Hub URL/push relay/sync/registration/event/changelog
egress. changelog.js becomes a local empty-feed adapter (no axios/fetch/network)
exporting the default ChangelogApi; links.js drops the Hub changelog URL.
lib/chatwoot_hub.rb removes base_url/push_notification_url/billing_base_url/
instance_config/send_push/send_push_with_response; billing_url reads only an
explicit CHATWOOT_BILLING_URL env, HTTPS-only with host and no userinfo, and
never falls back to a Hub URL. Enterprise proprietary base_url override is
preserved (spec uses singleton_class.instance_methods(false) for edition-safety).
privacy_audit uses a narrow per-file/per-rule Enterprise exception (hub-url
only) and privacy_audit_test.sh proves forbidden Enterprise runtime lines are
still detected; deployment privacy guard unchanged. Approved by independent
five-key review deleg_49d6ee2e (passed=true, blocking arrays empty).
This commit is contained in:
Kunthawat Greethong
2026-08-16 07:37:52 +07:00
parent 2ef6fa554b
commit 8101395608
10 changed files with 146 additions and 73 deletions

View File

@@ -0,0 +1,24 @@
import axios from 'axios';
import changelogAPI from '../changelog';
vi.mock('axios');
describe('#changelogAPI', () => {
beforeEach(() => {
vi.clearAllMocks();
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({}));
axios.get.mockResolvedValue({ data: { posts: [] } });
});
afterEach(() => {
vi.unstubAllGlobals();
});
it('returns an empty local feed without making a request', async () => {
const response = await changelogAPI.fetchFromHub();
expect(response).toEqual({ data: { posts: [] } });
expect(global.fetch).not.toHaveBeenCalled();
expect(axios.get).not.toHaveBeenCalled();
});
});