Skip to content

feat(server): add url option to report another page URL - #213

Merged
feugy merged 1 commit into
canaryfrom
damienfeugas/server-url-option
Oct 2, 2026
Merged

feugy merged 1 commit into
canaryfrom
damienfeugas/server-url-option

Conversation

@feugy

@feugy feugy commented Oct 2, 2026

Copy link
Copy Markdown
Member

🖖 What's in there?

Adds an optional url to the options of the server senders (track, identify, group, trackExposure).

Server events report the URL of the incoming request in their o field, taken from the request context or from the referer header. Callers had no way to replace it, so a URL carrying a token or an email in its query (OAuth callbacks, magic links) was sent as is. With url, the caller reports the page URL it wants, for example after stripping sensitive query parameters.

await track('login_completed', undefined, {
  url: 'https://acme.org/login/callback', // instead of ...?code=…&state=…
});

An invalid url (relative, non-http) fails the send with an error in the console, instead of falling back to the URL the caller wanted to replace.

🤺 How to test?

pnpm --filter @vercel/analytics exec vitest run src/server

New cases cover:

  • url wins over the referer header and over the request-context URL (none of the original query parameters survive in the payload)
  • behaviour is unchanged when url is not passed
  • invalid values (/relative, not a url, ftp://…, empty string) do not send

🔬 Notes to reviewers

  • Precedence in resolveUrl(): explicit url → request-context URL → referer → endpoint origin. Only the first step is new.
  • The option is on the shared Options interface, so all four senders get it and the type shows up in dist/server/index.d.ts.
  • Failing closed on an invalid value is deliberate: a typo should not silently reintroduce the URL the caller tried to hide.

The server senders report the URL of the incoming request in the `o`
field, taken from the request context or the referer. Callers that
sanitize that URL (credentials, emails in callback queries) had no way
to replace it. `track`, `identify`, `group` and `trackExposure` now
accept `options.url`, which wins over both. An invalid value fails the
send instead of falling back to the URL the caller meant to replace.
@vercel

vercel Bot commented Oct 2, 2026

Copy link
Copy Markdown

Your Vercel team Analytics Test Projects is not permitted to deploy from this git repository. Contact an administrator to add github organization vercel as a Protected Git Scope in Analytics Test Projects on Vercel. Once added, commit again to see your changes.

Learn more: https://vercel.com/docs/security/protected-git-scopes

@feugy
feugy requested review from a team and rvnewolf October 2, 2026 13:56
@feugy
feugy merged commit 9c4ca12 into canary Oct 2, 2026
7 of 15 checks passed
@feugy
feugy deleted the damienfeugas/server-url-option branch October 2, 2026 14:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant