Show HN: Mirrorshades – Simple web analytics
getmirrorshades.com
getmirrorshades.com
Goaccess is interesting in that it has both a live, terminal, curses interface as well as HTML output. https://goaccess.io
someone sniffing the network traffic can see the SECRET_SITE_KEY .. isn't it a security concern? or am i missing anything?
one of the comments of the question here: http://stackoverflow.com/questions/499591/are-https-urls-enc...
says: "It's probably a bad idea to put confidential data in the URL anyway. It will be displayed in the browser's address bad too, remember? People don't like it if their password is visible to anyone who happens to glance at the screen"
you can just display a form with an input field for the secret key, which will be HTTP POSTed and only THEN you should display the account's data (while the url doesn't disclose the secret key)
Also, what stack are you using? I'm interested as I've been slowly designing my own mini project (with SaaS aspirations, SaaSpirations?) that does very similar metrics.
I just recently switch from GA to Gauges, because the referral spam and bloat was annoying me.
I'm definitely going to use this on my next project. Simple and beautiful.
Thanks for sharing!
What if the analytics server actually parsed the referring page to see if there's a real link there and only confirm the referrer after that? Isn't there a third party service that checks these things?
It seems like someone could just scan for sites with a site ID matching your format, then a quick burst of 100 PATCH requests and you're now experiencing the same stuff that makes Google Analytics so painful to use.
Do you have any plans to combat stuff like this? This is typically my biggest gripe with analytics platforms, the spam can make them unusable and is hard to protect against.
Does look nice and clean - but I would love to see a license, not just a copyright notice. I am unsure if such a short snippet really is copyrightable? It is tempting to just change the post url and whip up something simple for self-hosting... but tricky to do and redistribute as long as there is no license on the file. For such short snippets I would recommend cc0 - or perhaps bsd.
It seems to be small enough to not even link it but paste in the HTML (836 bytes uglified, supposedly golfable even further).
Quick question, why did you choose to use a PATCH request and get involved with CORS issues, instead of injecting an image element with a tracking pixel (web beacon)?
var siteId = scriptElements[scriptElements.length - 1].getAttribute('data-siteId');
Maybe that could be better documented?Alternatively a change in the way that the script element (and the siteId) is detected could be helpful (instead of lines 13, 14):
var siteId = document.querySelector('script[data-siteId]').getAttribute('data-siteId');I've already started using it and I'll send feedbacks along the way.
Good luck!
Some kind of top pages or top bounce rate stats would also be good. Usually I'm using analytics to figure out either a) what's working or b) what's broken.
The only benefit I see is that Google doesn't have the data.