Description
When GTM detection evidence is a script URL containing a container ID, ts audit copies the entire URL into [integrations.google_tag_manager].container_id. Runtime validation requires a bare ID, so the generated configuration is rejected.
Reproduction
- Audit a page whose GTM script URL is recorded as the first evidence for
google_tag_manager, with id=GTM-ABC123 in its query string.
- Generate the draft configuration.
- Observe that
container_id contains the complete script URL rather than GTM-ABC123.
- Validate the generated configuration. The GTM container ID validator rejects the URL.
Expected behavior
Write container_id = "GTM-ABC123" whether detection evidence is a bare ID or a URL containing it.
Cause
In crates/trusted-server-cli/src/commands/audit/generate/analyzer.rs, extract_gtm_container_id uses GTM_REGEX.is_match on integration evidence but returns integration.evidence.clone(). Its asset fallback already returns only the regex match.
crates/trusted-server-cli/src/commands/audit/generate/mod.rs writes the returned value directly into the draft. The runtime validator in crates/trusted-server-core/src/integrations/google_tag_manager.rs requires ^GTM-[A-Z0-9]{4,20}$.
Existing tests cover bare-ID evidence and URL extraction from assets with no integration evidence. They miss URL evidence taking precedence over the asset fallback.
Affected area
CI / Tooling, specifically the operator CLI audit command.
Version and evidence
Confirmed at 666953a0 with two failing Rust regression tests: extraction from URL evidence and the generated configuration field both return the full URL instead of GTM-ABC123. Reproduction command: cargo test --package trusted-server-cli --target x86_64-unknown-linux-gnu gtm_container_id.
Done when
- URL evidence produces only the matched container ID.
- Bare-ID evidence and asset fallback remain supported.
- Regression tests cover URL evidence and the generated configuration field.
Separate from #1110, which concerns collecting gtag tag IDs.
Description
When GTM detection evidence is a script URL containing a container ID,
ts auditcopies the entire URL into[integrations.google_tag_manager].container_id. Runtime validation requires a bare ID, so the generated configuration is rejected.Reproduction
google_tag_manager, withid=GTM-ABC123in its query string.container_idcontains the complete script URL rather thanGTM-ABC123.Expected behavior
Write
container_id = "GTM-ABC123"whether detection evidence is a bare ID or a URL containing it.Cause
In
crates/trusted-server-cli/src/commands/audit/generate/analyzer.rs,extract_gtm_container_idusesGTM_REGEX.is_matchon integration evidence but returnsintegration.evidence.clone(). Its asset fallback already returns only the regex match.crates/trusted-server-cli/src/commands/audit/generate/mod.rswrites the returned value directly into the draft. The runtime validator incrates/trusted-server-core/src/integrations/google_tag_manager.rsrequires^GTM-[A-Z0-9]{4,20}$.Existing tests cover bare-ID evidence and URL extraction from assets with no integration evidence. They miss URL evidence taking precedence over the asset fallback.
Affected area
CI / Tooling, specifically the operator CLI audit command.
Version and evidence
Confirmed at
666953a0with two failing Rust regression tests: extraction from URL evidence and the generated configuration field both return the full URL instead ofGTM-ABC123. Reproduction command:cargo test --package trusted-server-cli --target x86_64-unknown-linux-gnu gtm_container_id.Done when
Separate from #1110, which concerns collecting gtag tag IDs.