Re: [RFC] PHP.net analytics
| From: | Derick Rethans | Date: | Thu, 07 Nov 2024 16:18:28 +0000 |
| Subject: | Re: [RFC] PHP.net analytics | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-125924@lists.php.net to get a copy of this message | ||
On Tue, 5 Nov 2024, Larry Garfield wrote:
> On Fri, Nov 1, 2024, at 6:10 PM, Bob Weinand wrote:
> > On 1.11.2024 22:41:29, Larry Garfield wrote:
> >> In a similar vein to approving the use of software, Roman Pronskiy
> >> asked for my help putting together an RFC on collecting analytics
> >> for PHP.net.
> >>
> >> https://wiki.php.net/rfc/phpnet-analytics
> >>
> >> Of particular note:
> >>
> >> * This is self-hosted, first-party only. No third parties get data, so no third
> >> parties can do evil things with it.
> >> * There is no plan to collect any PII.
> >> * The goal is to figure how how to most efficiently spend Foundation money improving
> >> php.net, something that is sorely needed.
> >>
> >> Ideally we'd have this in place by the 8.4 release or shortly
> >> thereafter, though I realize that's a little tight on the timeline.
> >
> > Hey Larry,
> >
> > I have a couple concerns and questions:
> >
> > Is there a way to track analytics with only transient data? As in, data
> > actually stored is always already anonymized enough that it would be
> > unproblematic to share it with everyone?
> > Or possibly, is there a retention period for the raw data after which
> > only anonymized data remains?
>
> The plan is to configure Matomo to not collect anything non-anonymous
> to begin with, to the extent possible. We're absolutely not talking
> about user-stalking like ad companies do, or anything even remotely
> close to that.
>
> I'm not convinced that publishing raw, even anonymized data, is
> valuable or responsible. I don't know of any other sites off hand
> that publish their raw analytics, and I don't know what purpose that
> would serve other than just a principled "radical transparency"
> stance, which I generally don't agree with.
>
> However, having an automated aggregate dashboard similar to
> https://analytics.bookstackapp.com/bookstackapp.com (made by a
> different tool, but same idea) that we could make public is the goal,
> but we don't want to do that until it's been running a while and we're
> sure that nothing personally identifiable could leak through that way.
I would have no issues publishing this HTML File once a week, created by
parsing the log files with:
sudo zcat access.log.*.gz | sudo goaccess access.log access.log.1 --anonymize-ip --ignore-crawlers
--real-os --max-items=500 --log-format=combined --enable-panel=REQUESTS --output=/tmp/access.html
https://derickrethans.nl/files/dump/access.html
(for my own site as
example).
> * How many people are accessing the site from a desktop vs mobile?
> * What speed connection do people have?
> * How many people are using the in-browser Wasm code runner that is currently being worked on?
> cf: https://github.com/php/web-php/pull/1097
Server logs contain the browser handle at least. I am not sure whether
the Matomo JS tracker actually distinguishes between desktop and mobile,
or the other two points you mention here.
The connection speed can be stored in server logs (we don't at the
moment):
https://onecompiler.com/questions/3src8rjkd/how-to-log-application-response-time-with-nginx
cheers,
Derick
--
https://derickrethans.nl | https://xdebug.org | https://dram.io
Author of Xdebug. Like it? Consider supporting me: https://xdebug.org/support
mastodon: @derickr@phpc.social @xdebug@phpc.social