Skip to content

ts audit writes the full GTM script URL into container_id #1219

Description

@ChristianPavilonis

Description

When GTM detection evidence is a script URL containing a container ID, ts audit copies the entire URL into [integrations.google_tag_manager].container_id. Runtime validation requires a bare ID, so the generated configuration is rejected.

Reproduction

  1. Audit a page whose GTM script URL is recorded as the first evidence for google_tag_manager, with id=GTM-ABC123 in its query string.
  2. Generate the draft configuration.
  3. Observe that container_id contains the complete script URL rather than GTM-ABC123.
  4. Validate the generated configuration. The GTM container ID validator rejects the URL.

Expected behavior

Write container_id = "GTM-ABC123" whether detection evidence is a bare ID or a URL containing it.

Cause

In crates/trusted-server-cli/src/commands/audit/generate/analyzer.rs, extract_gtm_container_id uses GTM_REGEX.is_match on integration evidence but returns integration.evidence.clone(). Its asset fallback already returns only the regex match.

crates/trusted-server-cli/src/commands/audit/generate/mod.rs writes the returned value directly into the draft. The runtime validator in crates/trusted-server-core/src/integrations/google_tag_manager.rs requires ^GTM-[A-Z0-9]{4,20}$.

Existing tests cover bare-ID evidence and URL extraction from assets with no integration evidence. They miss URL evidence taking precedence over the asset fallback.

Affected area

CI / Tooling, specifically the operator CLI audit command.

Version and evidence

Confirmed at 666953a0 with two failing Rust regression tests: extraction from URL evidence and the generated configuration field both return the full URL instead of GTM-ABC123. Reproduction command: cargo test --package trusted-server-cli --target x86_64-unknown-linux-gnu gtm_container_id.

Done when

  • URL evidence produces only the matched container ID.
  • Bare-ID evidence and asset fallback remain supported.
  • Regression tests cover URL evidence and the generated configuration field.

Separate from #1110, which concerns collecting gtag tag IDs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions