Commit a104d82e by Renzo Lucioni

Secure templates used to inject Segment and Optimizely

parent 88aa4a90
<%page expression_filter="h"/>
<%! from openedx.core.djangolib.js_utils import js_escaped_string %>
% if settings.CMS_SEGMENT_KEY: % if settings.CMS_SEGMENT_KEY:
<!-- begin segment footer --> <!-- begin segment footer -->
<script type="text/javascript"> <script type="text/javascript">
...@@ -6,10 +9,10 @@ ...@@ -6,10 +9,10 @@
// screws up RequireJS' JQuery initialization. // screws up RequireJS' JQuery initialization.
var onLoadCallback = function() { var onLoadCallback = function() {
analytics.identify( analytics.identify(
"${user.id}", "${ user.id | n, js_escaped_string }",
{ {
email: "${user.email}", email: "${ user.email | n, js_escaped_string }",
username: "${user.username}" username: "${ ser.username | n, js_escaped_string }"
}, },
{ {
integrations: { integrations: {
......
<%! from django.template.defaultfilters import escapejs %> <%page expression_filter="h"/>
<%! from openedx.core.djangolib.js_utils import js_escaped_string %>
% if context_course: % if context_course:
<% <%
...@@ -11,12 +12,12 @@ ...@@ -11,12 +12,12 @@
<script type="text/javascript"> <script type="text/javascript">
// if inside course, inject the course location into the JS namespace // if inside course, inject the course location into the JS namespace
%if context_course: %if context_course:
var course_location_analytics = "${locator | escapejs}"; var course_location_analytics = "${ locator | n, js_escaped_string }";
%endif %endif
// Asynchronously load Segment's analytics.js library // Asynchronously load Segment's analytics.js library
!function(){var analytics=window.analytics=window.analytics||[];if(!analytics.initialize)if(analytics.invoked)window.console&&console.error&&console.error("Segment snippet included twice.");else{analytics.invoked=!0;analytics.methods=["trackSubmit","trackClick","trackLink","trackForm","pageview","identify","reset","group","track","ready","alias","page","once","off","on"];analytics.factory=function(t){return function(){var e=Array.prototype.slice.call(arguments);e.unshift(t);analytics.push(e);return analytics}};for(var t=0;t<analytics.methods.length;t++){var e=analytics.methods[t];analytics[e]=analytics.factory(e)}analytics.load=function(t){var e=document.createElement("script");e.type="text/javascript";e.async=!0;e.src=("https:"===document.location.protocol?"https://":"http://")+"cdn.segment.com/analytics.js/v1/"+t+"/analytics.min.js";var n=document.getElementsByTagName("script")[0];n.parentNode.insertBefore(e,n)};analytics.SNIPPET_VERSION="3.1.0"; !function(){var analytics=window.analytics=window.analytics||[];if(!analytics.initialize)if(analytics.invoked)window.console&&console.error&&console.error("Segment snippet included twice.");else{analytics.invoked=!0;analytics.methods=["trackSubmit","trackClick","trackLink","trackForm","pageview","identify","reset","group","track","ready","alias","page","once","off","on"];analytics.factory=function(t){return function(){var e=Array.prototype.slice.call(arguments);e.unshift(t);analytics.push(e);return analytics}};for(var t=0;t<analytics.methods.length;t++){var e=analytics.methods[t];analytics[e]=analytics.factory(e)}analytics.load=function(t){var e=document.createElement("script");e.type="text/javascript";e.async=!0;e.src=("https:"===document.location.protocol?"https://":"http://")+"cdn.segment.com/analytics.js/v1/"+t+"/analytics.min.js";var n=document.getElementsByTagName("script")[0];n.parentNode.insertBefore(e,n)};analytics.SNIPPET_VERSION="3.1.0";
analytics.load("${ settings.CMS_SEGMENT_KEY }"); analytics.load("${ settings.CMS_SEGMENT_KEY | n, js_escaped_string }");
analytics.page(); analytics.page();
}}(); }}();
// Note: user tracking moved to segment-io-footer.html // Note: user tracking moved to segment-io-footer.html
...@@ -26,7 +27,7 @@ ...@@ -26,7 +27,7 @@
<!-- dummy Segment --> <!-- dummy Segment -->
<script type="text/javascript"> <script type="text/javascript">
%if context_course: %if context_course:
var course_location_analytics = "${locator | escapejs}"; var course_location_analytics = "${ locator | n, js_escaped_string }";
%endif %endif
var analytics = { var analytics = {
"track": function() {} "track": function() {}
......
<%page expression_filter="h"/>
% if settings.OPTIMIZELY_PROJECT_ID and not disable_optimizely: % if settings.OPTIMIZELY_PROJECT_ID and not disable_optimizely:
<script src=${'//cdn.optimizely.com/js/{}.js'.format(settings.OPTIMIZELY_PROJECT_ID)}></script> <script src=${ '//cdn.optimizely.com/js/{}.js'.format(settings.OPTIMIZELY_PROJECT_ID) }></script>
% endif % endif
<%page expression_filter="h"/>
<%! from openedx.core.djangolib.js_utils import js_escaped_string %>
% if settings.LMS_SEGMENT_KEY: % if settings.LMS_SEGMENT_KEY:
<!-- begin segment footer --> <!-- begin segment footer -->
<script type="text/javascript"> <script type="text/javascript">
% if user.is_authenticated(): % if user.is_authenticated():
$(window).load(function() { $(window).load(function() {
analytics.identify( analytics.identify(
"${user.id}", "${ user.id | n, js_escaped_string }",
{ {
email: "${user.email}", email: "${ user.email | n, js_escaped_string }",
username: "${user.username}" username: "${ user.username | n, js_escaped_string }"
}, },
{ {
integrations: { integrations: {
......
<%page expression_filter="h"/>
<%! from openedx.core.djangolib.js_utils import js_escaped_string %>
% if settings.LMS_SEGMENT_KEY: % if settings.LMS_SEGMENT_KEY:
<!-- begin Segment --> <!-- begin Segment -->
<script type="text/javascript"> <script type="text/javascript">
// Asynchronously load Segment's analytics.js library // Asynchronously load Segment's analytics.js library
!function(){var analytics=window.analytics=window.analytics||[];if(!analytics.initialize)if(analytics.invoked)window.console&&console.error&&console.error("Segment snippet included twice.");else{analytics.invoked=!0;analytics.methods=["trackSubmit","trackClick","trackLink","trackForm","pageview","identify","reset","group","track","ready","alias","page","once","off","on"];analytics.factory=function(t){return function(){var e=Array.prototype.slice.call(arguments);e.unshift(t);analytics.push(e);return analytics}};for(var t=0;t<analytics.methods.length;t++){var e=analytics.methods[t];analytics[e]=analytics.factory(e)}analytics.load=function(t){var e=document.createElement("script");e.type="text/javascript";e.async=!0;e.src=("https:"===document.location.protocol?"https://":"http://")+"cdn.segment.com/analytics.js/v1/"+t+"/analytics.min.js";var n=document.getElementsByTagName("script")[0];n.parentNode.insertBefore(e,n)};analytics.SNIPPET_VERSION="3.1.0"; !function(){var analytics=window.analytics=window.analytics||[];if(!analytics.initialize)if(analytics.invoked)window.console&&console.error&&console.error("Segment snippet included twice.");else{analytics.invoked=!0;analytics.methods=["trackSubmit","trackClick","trackLink","trackForm","pageview","identify","reset","group","track","ready","alias","page","once","off","on"];analytics.factory=function(t){return function(){var e=Array.prototype.slice.call(arguments);e.unshift(t);analytics.push(e);return analytics}};for(var t=0;t<analytics.methods.length;t++){var e=analytics.methods[t];analytics[e]=analytics.factory(e)}analytics.load=function(t){var e=document.createElement("script");e.type="text/javascript";e.async=!0;e.src=("https:"===document.location.protocol?"https://":"http://")+"cdn.segment.com/analytics.js/v1/"+t+"/analytics.min.js";var n=document.getElementsByTagName("script")[0];n.parentNode.insertBefore(e,n)};analytics.SNIPPET_VERSION="3.1.0";
analytics.load("${ settings.LMS_SEGMENT_KEY }"); analytics.load("${ settings.LMS_SEGMENT_KEY | n, js_escaped_string }");
analytics.page(); analytics.page();
}}(); }}();
// Note: user tracking moved to segment-io-footer.html // Note: user tracking moved to segment-io-footer.html
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment