Add first-party verdict and guards to tracker mapping
The tracker-pattern catalog was binary (linked to a vendor or not), so generic and first-party artifacts (loglevel keys, wallet-extension keys, an org's own trackers) were retried forever and, once one row was wrongly attributed, re-propagated to every organization with no re-check. Give catalog rows a terminal attribution verdict (UNDETERMINED, THIRD_PARTY, FIRST_PARTY): FIRST_PARTY short-circuits the whole mapping pipeline so the artifact is never attributed again. Gate deterministic vendor adoption behind a trust bar so only curated/operator rows auto-propagate; lower-confidence agent/heuristic rows are reused as hints and re-resolved, and an independent agent re-confirmation corroborates and promotes them. Make the mapping agent emit an evidence source and reject any attribution that lacks concrete evidence, and let it declare a first-party verdict. Skip the speculative agent for PRE_EXISTING-source patterns, whose low signal invites invented vendors. Add proboctl "ctp mark-first-party" and an --attribution list filter to audit and remediate existing wrong links, and a cursor rule documenting migration naming so the timestamp is taken from date -u, not invented. Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
38
pkg/coredata/migrations/20260616T114832Z.sql
Normal file
38
pkg/coredata/migrations/20260616T114832Z.sql
Normal file
@@ -0,0 +1,38 @@
|
||||
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
|
||||
--
|
||||
-- Permission to use, copy, modify, and/or distribute this software for any
|
||||
-- purpose with or without fee is hereby granted, provided that the above
|
||||
-- copyright notice and this permission notice appear in all copies.
|
||||
--
|
||||
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
-- PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-- Give the global tracker-pattern catalog a terminal attribution verdict so a
|
||||
-- row can record that it has no third party (a first-party or generic
|
||||
-- artifact) rather than only "linked" vs "not yet linked". UNDETERMINED rows
|
||||
-- are still probed by the mapping pipeline; THIRD_PARTY rows carry a vendor;
|
||||
-- FIRST_PARTY rows are terminal and the pipeline never attributes them again.
|
||||
CREATE TYPE common_tracker_pattern_attribution AS ENUM (
|
||||
'UNDETERMINED',
|
||||
'THIRD_PARTY',
|
||||
'FIRST_PARTY'
|
||||
);
|
||||
|
||||
ALTER TABLE common_tracker_patterns
|
||||
ADD COLUMN attribution common_tracker_pattern_attribution NOT NULL DEFAULT 'UNDETERMINED';
|
||||
|
||||
-- Backfill: any row already carrying a vendor is, by definition, attributed to
|
||||
-- a third party. The DEFAULT covers the rest (UNDETERMINED).
|
||||
UPDATE common_tracker_patterns
|
||||
SET attribution = 'THIRD_PARTY'
|
||||
WHERE common_third_party_id IS NOT NULL;
|
||||
|
||||
-- The DEFAULT only backfills existing rows; drop it so inserts must supply the
|
||||
-- value explicitly, matching the cookie_source convention.
|
||||
ALTER TABLE common_tracker_patterns
|
||||
ALTER COLUMN attribution DROP DEFAULT;
|
||||
Reference in New Issue
Block a user