Conversation
There was a problem hiding this comment.
Pull request overview
Adds Umami web analytics and documents the associated privacy handling.
Changes:
- Injects the Umami analytics script site-wide.
- Adds and links a new privacy policy.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
eleventy.config.mjs |
Adds footer link and analytics transform. |
app/privacy-policy.md |
Documents analytics data processing. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Lovely 🙌 I've deleted previous comments that are now outdated following our offline discussion. Two minor things:
|
|
Looks good in principle! It's not clear from the Umami docs whether different versions of the tracking script work with different versions of Umami, or if there's a risk of issues if they diverge. Either way it's probably worth us versioning the script files on the bucket like
We can set up an appropriate nhs.uk subdomain when the time comes (I believe
Can we do that in this PR? This will need a |
Thanks @csutter. I have added a CSP to this PR and tested it. I'll work on the version tracking in parallel. We're still waiting on an outcome of the DPIA screen for this. Please can you provide details off this PR of how to make the request to the DNS team for the subdomain, or should this wait for the outcome of the DPIA screen first? |
<head>to stream web analytics data to Umami (NHSE-hosted in AWS)<meta>tag in the<head>- tested by running locally and checking logs for CSP violations, as well as LLM pixel-by-pixel comparison of screenshots before/after to check for missing fonts, style sheets etc.