feat(www): Phase 2 — enable cookie stamping on /dashboard and /docs paths (#43677)

This commit is contained in:
Sean Oliver authored and GitHub committed 2026-03-12 15:23:07 -07:00
1 parent befc817f94
commit b041ebfaa5
2 files changed
+29 -103

No files matched your search

+28 -76
View File
@@ -1,7 +1,7 @@
import { NextRequest } from 'next/server'
import { describe, expect, it } from 'vitest'
import { FIRST_REFERRER_COOKIE_NAME, MW_DIAG_COOKIE_NAME } from 'common/first-referrer-cookie'
import { FIRST_REFERRER_COOKIE_NAME } from 'common/first-referrer-cookie'
import { middleware } from './middleware'
@@ -18,17 +18,8 @@ function makeRequest(
return req
}
function parseDiagCookie(value: string) {
const params = new URLSearchParams(value)
return {
hit: params.get('hit') === '1',
would_stamp: params.get('would_stamp') === '1',
has_cookie: params.get('has_cookie') === '1',
}
}
describe('www middleware', () => {
describe('cookie stamping on normal paths', () => {
describe('cookie stamping on www paths', () => {
it('stamps cookie for external referrer on www path', () => {
const req = makeRequest('/pricing', { referer: 'https://google.com' })
const res = middleware(req)
@@ -44,92 +35,53 @@ describe('www middleware', () => {
})
})
describe('dashboard/docs diagnostic guard', () => {
it('sets diagnostic cookie on /dashboard paths', () => {
describe('cookie stamping on /dashboard paths', () => {
it('stamps cookie for external referrer', () => {
const req = makeRequest('/dashboard/project/123', { referer: 'https://google.com' })
const res = middleware(req)
expect(res.cookies.get(MW_DIAG_COOKIE_NAME)).toBeDefined()
expect(res.cookies.get(FIRST_REFERRER_COOKIE_NAME)).toBeDefined()
})
it('sets diagnostic cookie on /docs paths', () => {
const req = makeRequest('/docs/guides/auth', { referer: 'https://google.com' })
const res = middleware(req)
expect(res.cookies.get(MW_DIAG_COOKIE_NAME)).toBeDefined()
})
it('encodes hit=1 in diagnostic cookie', () => {
const req = makeRequest('/dashboard/project/123', { referer: 'https://google.com' })
const res = middleware(req)
const raw = res.cookies.get(MW_DIAG_COOKIE_NAME)?.value ?? ''
const diag = parseDiagCookie(raw)
expect(diag.hit).toBe(true)
})
it('encodes would_stamp=1 for external referrer with no existing cookie', () => {
const req = makeRequest('/dashboard/project/123', { referer: 'https://google.com' })
const res = middleware(req)
const raw = res.cookies.get(MW_DIAG_COOKIE_NAME)?.value ?? ''
const diag = parseDiagCookie(raw)
expect(diag.would_stamp).toBe(true)
expect(diag.has_cookie).toBe(false)
})
it('encodes would_stamp=0 for direct navigation (no referrer)', () => {
const req = makeRequest('/dashboard/project/123')
const res = middleware(req)
const raw = res.cookies.get(MW_DIAG_COOKIE_NAME)?.value ?? ''
const diag = parseDiagCookie(raw)
expect(diag.would_stamp).toBe(false)
expect(diag.has_cookie).toBe(false)
})
it('encodes would_stamp=0 for internal referrer', () => {
it('does not stamp cookie for internal referrer', () => {
const req = makeRequest('/dashboard/project/123', {
referer: 'https://supabase.com/pricing',
})
const res = middleware(req)
const raw = res.cookies.get(MW_DIAG_COOKIE_NAME)?.value ?? ''
const diag = parseDiagCookie(raw)
expect(diag.would_stamp).toBe(false)
})
it('encodes has_cookie=1 when first-referrer cookie is already present', () => {
const req = makeRequest('/dashboard/project/123', {
referer: 'https://google.com',
hasCookie: true,
})
const res = middleware(req)
const raw = res.cookies.get(MW_DIAG_COOKIE_NAME)?.value ?? ''
const diag = parseDiagCookie(raw)
expect(diag.has_cookie).toBe(true)
})
it('does NOT stamp first-referrer cookie on /dashboard paths', () => {
const req = makeRequest('/dashboard/project/123', { referer: 'https://google.com' })
const res = middleware(req)
expect(res.cookies.get(FIRST_REFERRER_COOKIE_NAME)).toBeUndefined()
})
it('does NOT stamp first-referrer cookie on /docs paths', () => {
it('does not stamp cookie for direct navigation (no referrer)', () => {
const req = makeRequest('/dashboard/project/123')
const res = middleware(req)
expect(res.cookies.get(FIRST_REFERRER_COOKIE_NAME)).toBeUndefined()
})
})
describe('cookie stamping on /docs paths', () => {
it('stamps cookie for external referrer', () => {
const req = makeRequest('/docs/guides/auth', { referer: 'https://google.com' })
const res = middleware(req)
expect(res.cookies.get(FIRST_REFERRER_COOKIE_NAME)).toBeDefined()
})
it('does not stamp cookie for internal referrer', () => {
const req = makeRequest('/docs/guides/auth', {
referer: 'https://supabase.com/pricing',
})
const res = middleware(req)
expect(res.cookies.get(FIRST_REFERRER_COOKIE_NAME)).toBeUndefined()
})
it('does NOT set diagnostic cookie on normal www paths', () => {
const req = makeRequest('/pricing', { referer: 'https://google.com' })
it('does not stamp cookie for direct navigation (no referrer)', () => {
const req = makeRequest('/docs/guides/auth')
const res = middleware(req)
expect(res.cookies.get(MW_DIAG_COOKIE_NAME)).toBeUndefined()
expect(res.cookies.get(FIRST_REFERRER_COOKIE_NAME)).toBeUndefined()
})
})
})
+1 -27
View File
@@ -1,34 +1,8 @@
import {
FIRST_REFERRER_COOKIE_NAME,
MW_DIAG_COOKIE_NAME,
shouldRefreshCookie,
stampFirstReferrerCookie,
} from 'common/first-referrer-cookie'
import { stampFirstReferrerCookie } from 'common/first-referrer-cookie'
import { NextResponse, type NextRequest } from 'next/server'
export function middleware(request: NextRequest) {
const response = NextResponse.next()
const pathname = request.nextUrl.pathname
const isDashboardOrDocs = pathname.startsWith('/dashboard') || pathname.startsWith('/docs')
if (isDashboardOrDocs) {
// Phase 1: diagnostic only — no permanent cookie mutations.
// Compute what Phase 2 would do and encode it in a short-lived cookie
// readable by client-side telemetry so we get PostHog-visible data.
// This also tests the Set-Cookie mutation path that Phase 2 will use.
const referrer = request.headers.get('referer') ?? ''
const hasCookie = request.cookies.has(FIRST_REFERRER_COOKIE_NAME)
const { stamp: wouldStamp } = shouldRefreshCookie(hasCookie, { referrer, url: request.url })
response.cookies.set(
MW_DIAG_COOKIE_NAME,
`hit=1&would_stamp=${wouldStamp ? '1' : '0'}&has_cookie=${hasCookie ? '1' : '0'}`,
{ path: '/', sameSite: 'lax', maxAge: 60 }
)
return response
}
stampFirstReferrerCookie(request, response)
return response
}