Repository navigation
feat(analytics): attribute sign-ups and demo requests to their acquisition source - #8815
Conversation
…ition source - Record first and last marketing touch (campaign params, referring domain, landing path) in consent-gated first-party cookies on marketing and sign-in pages; attach them to user_created and the PostHog person - Capture $pageview on marketing routes, landing_demo_request_submitted, landing_demo_booked, external_sign_in_started, and email_type on identify - Add useCaptureWhenReady so view events captured on mount are no longer dropped before PostHog initializes - Include attribution in the demo-request sales notification - List the attribution cookies in the cookie policy
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
There was a problem hiding this comment.
2 issues found across 31 files
Confidence score: 3/5
- In
attribution-cookie-guard.tsx, signup can proceed while consent is unresolved, so the server-side auth hook may use attribution cookies before the guard clears stale ones. Gate server attribution on consent or block signup until the guard clears them. - In
social-sign-in.ts, OAuth can navigate away before PostHog publishes its consented client, dropping the start event. Make capture readiness-aware before navigating.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="apps/sim/lib/auth/social-sign-in.ts">
<violation number="1" location="apps/sim/lib/auth/social-sign-in.ts:27">
P3: `captureClientEvent` drops this event until PostHog publishes its consented client, but the OAuth flow immediately navigates away. Make the start capture readiness-aware before navigating, without capturing before measurement consent.</violation>
</file>
<file name="apps/sim/app/_shell/consent/attribution-cookie-guard.tsx">
<violation number="1" location="apps/sim/app/_shell/consent/attribution-cookie-guard.tsx:17">
P2: The auth hook reads these cookies server-side, but signup remains usable while consent is unresolved. Gate server attribution on consent or block signup until this guard clears stale cookies.</violation>
</file>
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
|
… stored field shapes, and lock sign-in buttons while pending
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
Summary
refparams, ad network that clicked through, referring domain, landing path) in two first-party cookies, written only under measurement consent and only on marketing and sign-in pages. The server reads them in the better-auth account hook and attaches them touser_createdand as$set_onceperson properties, so OAuth sign-ups stop looking like they came from the identity providerSameSite=None; Secureso SAML's cross-site POST callback still sees them; cookies are cleared when measurement consent is withdrawn$pageviewon every marketing route,landing_demo_request_submitted(was cataloged but never fired),landing_demo_booked,external_sign_in_started(Google/GitHub/Microsoft/SSO), andemail_type(work/personal) on identifyuseCaptureWhenReady: view events captured in a mount effect were dropped on hard loads becausePostHogProviderpublishes the client after consent resolves. Moved landing, signup/login, settings tab, table opened, and knowledge base opened events onto itstartSocialSignInwrapper; share campaign param lists with the Google tag contextType of Change
Testing
lib/analytics/attribution.test.ts: each guard (intermediary/IdP referrers, auth-path referrals, customer-owned pages, own-site referrals, first-touch immutability and repair, click-id redaction, size and line-separator bounding, tampered cookies) verified red with the guard removed, green restoredbun run test(all workspaces + scripts),bun run lint,bun run type-check,bun run check:audits,docs-manifest:check, block registry check againstorigin/staging?utm_source=test, accept analytics, sign up, confirmfirst_touch_utm_sourceonuser_createdChecklist
test-auditauthoring gate)