Repository navigation
Conversation
|
Your Vercel team Analytics Test Projects is not permitted to deploy from this git repository. Contact an administrator to add github organization vercel as a Protected Git Scope in Analytics Test Projects on Vercel. Once added, commit again to see your changes. Learn more: https://vercel.com/docs/security/protected-git-scopes |
Member
Author
|
agent slop, we don't need this |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🖖 What's in there?
@vercel/analytics/serverstops sendingx-vercel-ipon the beacon it emits from the customer's function. Ingestion no longer reads it (vercel/api#95447), so the header is dead weight.Server-side events are attributed to the IP that reaches ingestion. Before and after this change, that is the function's egress, not the visitor's browser: the header copied the function's incoming
x-forwarded-for, which on Vercel carries the request's edge hop rather than the visitor. Tinybird confirms it over 7 days: 18 of the 23 owners with ≥10K server-side events have a single country (their function region), and vercel.com's own server-side events show as 76% DE / 17% US.user-agent,x-vercel-ip,x-va-server,cookieuser-agent,x-va-server,cookie🤺 How to test?
pnpm --filter @vercel/analytics test— server tests updated to assert the header is gone. No change to the event body or to any public API.🔬 Notes to reviewers
x-vercel-ipwas never documented (vercel.com/docs or this repo). It was a private contract withapi-analytics-ingestion, which was accepting any client-supplied IP on every beacon, including pageviews and vitals from the browser.x-real-ipinstead would give the visitor IP for direct traffic, but it would still be a client-supplied value that ingestion must take on faith, and the edge for anyone behind Cloudflare. Not worth keeping a forgeable channel for it.track()from@vercel/analytics/server: server-side events are attributed to the region of the function that sent them.🔗 Related PRs
x-vercel-ipand other client-supplied IP headers