Skip to content

Current implementation does not eliminate Affinity analytics upload #11

Description

@Still34

Summary

At the moment, despite patching out the analytics upload consent, setting the entire app to offline state, Affinity Cloud Services (acs) still attempts to deliver analytics to Canva server via api.canva.com via Snowplow. This appears to be handled by libacs and is called via Affinity.CloudServices.

Image

Expected Behavior

Creating a document and/or other actions that may trigger a telemetry send should not reach Canva API or third-party analytics services.

Current Behavior

Creating a document and/or other actions triggers a telemetry send to Canva API.

Additional Details

  • Below is an example of the analytics sent when creating a new document - note that some strings have been manually replaced with variable-like names to redact information of the testing environment.

Main blob

{
    "data": [
        {
            "aid": "com.seriflabs.affinity.analytics.env-production",
            "cx": dataBlob1,
            "dtm": currentTimestamp,
            "e": "ue",
            "eid": eventId,
            "ip": "xxx.xxx.xxx.xxx",
            "lang": "en-US",
            "p": "pc",
            "stm": currentTimeStamp,
            "tna": "com.seriflabs.affinityv3",
            "tv": "cpp-2.0.0",
            "tz": currentTimezone,
            "ua": "Affinity v3/3.0.1.3808 (Retail)",
            "ue_px": dataBlob2,
            "uid": "urn:affinitycloud:anon-device:<uid>"
        }
    ],
    "schema": "iglu:com.snowplowanalytics.snowplow/payload_data/jsonschema/1-0-4"
}

DataBlob1

{
    "data": [
        {
            "data": {
                "isCritical": true
            },
            "schema": "iglu:com.seriflabs.affinity.analytics/event_description/jsonschema/1-0-0"
        },
        {
            "data": {
                "build": "AffinityRetail",
                "product": "V3",
                "version": "3.0.1.3808"
            },
            "schema": "iglu:com.seriflabs.affinity.analytics/app_description/jsonschema/2-0-0"
        },
        {
            "data": {
                "interfaceAppearance": "dark",
                "isPostCrash": false,
                "languageCode": "en-US"
            },
            "schema": "iglu:com.seriflabs.affinity.analytics/app_session_description/jsonschema/1-1-0"
        },
        {
            "data": {
                "experiments": null
            },
            "schema": "iglu:com.seriflabs.affinity.analytics/experiment_enrolments/jsonschema/1-0-0"
        },
        {
            "data": {
                "eventIndex": 9,
                "firstEventId": firstEventId,
                "firstEventTimestamp": firstEventTimestamp,
                "previousSessionId": previousSessionId,
                "sessionId": sessionId,
                "sessionIndex": 8,
                "storageMechanism": "SQLITE",
                "userId": userId
            },
            "schema": "iglu:com.snowplowanalytics.snowplow/client_session/jsonschema/1-0-2"
        },
        {
            "data": {
                "deviceManufacturer": "",
                "deviceModel": "",
                "deviceProcessorCount": processorCount,
                "osIs64Bit": true,
                "osServicePack": "0.0",
                "osType": "Windows",
                "osVersion": osVersion
            },
            "schema": "iglu:com.snowplowanalytics.snowplow/desktop_context/jsonschema/1-0-0"
        }
    ],
    "schema": "iglu:com.snowplowanalytics.snowplow/contexts/jsonschema/1-0-1"
}

DataBlob2

{
    "data": {
        "data": {
            "verb": "organise"
        },
        "schema": "iglu:com.seriflabs.affinity.analytics/activity_detected/jsonschema/2-0-0"
    },
    "schema": "iglu:com.snowplowanalytics.snowplow/unstruct_event/jsonschema/1-0-0"
}

Activity

  1. changed the title [-]Eliminate Affinity analytics upload[/-] [+]Current implementation does not eliminate Affinity analytics upload[/+] on Nov 16, 2025
  2. added a commit that references this issue on Nov 16, 2025
  3. Still34 commented on Nov 16, 2025

    @Still34
    OwnerAuthor

    Possible Solutions

    1. Block api.canva.com via hosts or DNS-based blocking solutions; however, this may render Canva unusable if the user wishes to use the main Canva website and is not a good solution for end-users due to complexity and possibly unwanted configuration changes.

    2. Patch libacs; whilst this may be the cleanest solution in ensuring libacs does not call any relevant content services, there are over 700 analytics-related functions to patch, and it may not be possible to patch all of them to a simple ret.

    Image
    1. Patch Affinity.CloudServices; this might be the preferred solution if the IL is easily patchable. This should be investigated first.

    2. Hijack all calls to certain wininet/winhttp exports; this should not affect update checks or other HTTP calls in .NET, as those are done at .NET assembly-level that do not use these standard Win32 libraries. This is a little bit extreme and may also be unreliable and will require one or two more additional libraries placed next to the main executable.

  4. stealthusk commented on Nov 18, 2025

    @stealthusk

    I believe in you man. Take all the time you need for this 💖

  5. Still34 commented on Dec 21, 2025

    @Still34
    OwnerAuthor

    Hi! I have implemented the third option in the pull request #13 @Still34

    Please do not submit LLM generated code without verifying and seeing how both the code in the repository and the underlying ACS code works. This wastes everyone's time involved.

  6. Still34 commented on Sep 13, 2026

    @Still34
    OwnerAuthor

    The patch can occur at libacs with DispatchSnowplowSelfDescribingEvent, but since it is unmanaged call, this would require us to ship the patch with a runtime DLL patcher. I'll see if I can work something out.

  7. Still34 commented on Sep 13, 2026

    @Still34
    OwnerAuthor

    Closed via 53c5f69

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions