Files
supabase/packages/common/posthog-client.ts
Sean Oliver e88a3723e1 feat(studio): add PostHog session replay with masked-by-default policy (#48515)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Telemetry feature.

## What is the current behavior?

- Session replay is off, and nothing in the code keeps it off.
- `packages/common/posthog-client.ts` sets no recording config at all.
- So PostHog's project setting alone decides, for every app sharing that
project.
- Studio, www and docs share one project.
- Studio shows customer data almost everywhere: SQL editor, table rows,
connection strings, API keys.
- posthog-js masks inputs by default. It does not mask rendered text.
- [GROWTH-1055](https://linear.app/supabase/issue/GROWTH-1055)

## What is the new behavior?

- `posthogClient.init()` takes a masking config, and disables recording
when it gets none.
- Studio passes one behind `NEXT_PUBLIC_POSTHOG_SESSION_REPLAY`.
- Every other app passes nothing, so it never loads the recorder.
- Studio masks all text and all inputs.
- `data-ph-capture="true"` opts one element's text back in. Unused so
far.
- Canvas is blocked, because it records as images that text masking
cannot reach.
- Query strings and fragments are stripped from recorded URLs, where
auth callbacks carry tokens.
- Request and response bodies are never recorded.
- Console logs are never recorded, since masking only reaches DOM text.
- Masking is set in code, so PostHog's settings cannot loosen it.
- Consent gating is unchanged. Nothing records before a user accepts.

## Additional context

- Recording needs three things: this env var, the PostHog project
toggle, and user consent.
- All three are off or unset, so merging this changes nothing at
runtime.
- `NEXT_PUBLIC_POSTHOG_SESSION_REPLAY` goes into Vercel on Preview scope
first, to test on a preview build.
- Production scope comes later, once we are ready to record there.
- `NEXT_PUBLIC_*` is inlined at build time, so each scope needs a
rebuild afterwards.
- Text inside HTML attributes (`title`, `alt`, `href`) is still recorded
as-is.
- posthog-js exposes no hook for masking attributes, so covering it
needs `ph-no-capture` per component.
- Staging has no server-side masking config, so that is where this gets
verified.
- Plan: enable recording on staging, verify masked text on a preview,
then decide on production.
- Network timing stays on for the dashboard performance work. Payloads
stay off.
- Tests cover both masking functions and the config values.

## Screenshots


https://github.com/user-attachments/assets/aa064a04-f977-4453-a3da-2fe0cdcead08

<img width="889" height="651" alt="CleanShot 2026-07-31 at 10 13 43"
src="https://github.com/user-attachments/assets/f1d07946-fd68-42b2-89f1-d201bc605638"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **New Features**
  * Added privacy-focused session replay for Studio.
* Text and form inputs are masked by default, with explicit opt-in
capture.
  * Network recordings remove query strings and fragments.
  * Headers, request bodies, canvas data, and console logs are excluded.

* **Bug Fixes**
  * Improved whitespace and capture-attribute handling during masking.
* Session replay remains disabled without a masking policy or explicit
enablement.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-31 15:37:05 -07:00

459 lines
15 KiB
TypeScript

import posthog, {
type CapturedNetworkRequest,
type PostHogConfig,
type SessionRecordingOptions,
} from 'posthog-js'
import { safeSessionStorage } from './safe-storage'
export type { CapturedNetworkRequest, SessionRecordingOptions }
// Limit the max number of queued events
// (e.g. if a user navigates around a lot before accepting consent)
const MAX_PENDING_EVENTS = 20
export interface ClientTelemetryEvent {
id: string
timestamp: number
eventType: 'capture' | 'identify' | 'pageview' | 'pageleave'
eventName: string
distinctId?: string
properties?: Record<string, unknown>
}
type ClientTelemetryListener = (event: ClientTelemetryEvent) => void
interface PostHogClientConfig {
apiKey?: string
apiHost?: string
uiHost?: string
}
interface PostHogInitOptions {
hasConsent?: boolean
/**
* Masking policy for session replay. Omit to disable recording, which every app
* sharing this PostHog project does unless it passes a policy of its own.
*/
sessionReplay?: SessionRecordingOptions
}
/**
* Enables session recording when given a masking config, and disables it when
* given nothing.
*/
export function buildSessionRecordingConfig(
sessionReplay?: SessionRecordingOptions
): Partial<PostHogConfig> {
return {
disable_session_recording: !sessionReplay,
// Console output is not in the DOM, so text masking cannot reach it.
enable_recording_console_log: false,
...(sessionReplay && { session_recording: sessionReplay }),
}
}
class PostHogClient {
/** True after posthog.init() is called (prevents double-init) */
private initStarted = false
/** True after the `loaded` callback fires, meaning PostHog has fully bootstrapped */
private initialized = false
private pendingGroups: Record<string, string> = {}
private pendingIdentification: { userId: string; properties?: Record<string, any> } | null = null
private pendingEvents: Array<{ event: string; properties: Record<string, any> }> = []
private pendingExposures: Array<{ experimentId: string; properties: Record<string, any> }> = []
private config: PostHogClientConfig
private readonly maxPendingEvents = MAX_PENDING_EVENTS
private devListeners: Set<ClientTelemetryListener> = new Set()
private pendingFeatureFlagCallbacks: Set<() => void> = new Set()
constructor(config: PostHogClientConfig = {}) {
const apiHost =
config.apiHost || process.env.NEXT_PUBLIC_POSTHOG_HOST || 'https://ph.supabase.green'
const uiHost =
config.uiHost || process.env.NEXT_PUBLIC_POSTHOG_UI_HOST || 'https://eu.posthog.com'
this.config = {
apiKey: config.apiKey || process.env.NEXT_PUBLIC_POSTHOG_KEY,
apiHost,
uiHost,
}
}
init({ hasConsent = true, sessionReplay }: PostHogInitOptions = {}) {
if (this.initStarted || typeof window === 'undefined' || !hasConsent) return
if (!this.config.apiKey) {
console.warn('PostHog API key not found. Skipping initialization.')
return
}
const config: Partial<PostHogConfig> = {
api_host: this.config.apiHost,
ui_host: this.config.uiHost,
autocapture: false, // We'll manually track events
capture_pageview: false, // We'll manually track pageviews
capture_pageleave: false, // We'll manually track page leaves
...buildSessionRecordingConfig(sessionReplay),
loaded: (posthog) => {
// Apply pending properties that were set before PostHog
// initialized due to poor connection or user not accepting
// consent right away
// Apply any pending groups
Object.entries(this.pendingGroups).forEach(([type, id]) => {
posthog.group(type, id)
})
this.pendingGroups = {}
// Apply any pending identification
if (this.pendingIdentification) {
try {
posthog.identify(
this.pendingIdentification.userId,
this.pendingIdentification.properties
)
} catch (error) {
console.error('PostHog identify failed:', error)
}
this.pendingIdentification = null
}
// Flush any pending events
this.pendingEvents.forEach(({ event, properties }) => {
try {
posthog.capture(event, properties, { transport: 'sendBeacon' })
} catch (error) {
console.error('PostHog capture failed:', error)
}
})
this.pendingEvents = []
this.initialized = true
// Flush any pending experiment exposures (with deduplication)
this.pendingExposures.forEach(({ experimentId, properties }) => {
this.fireExposureIfNew(experimentId, properties)
})
this.pendingExposures = []
},
}
this.initStarted = true
posthog.init(this.config.apiKey, config)
// Register any feature flag callbacks that were queued before init
this.pendingFeatureFlagCallbacks.forEach((cb) => posthog.onFeatureFlags(cb))
this.pendingFeatureFlagCallbacks.clear()
}
capturePageView(properties: Record<string, any>, hasConsent: boolean = true) {
if (!hasConsent) return
if (!this.initialized) {
// Queue the event for when PostHog initializes (up to cap)
// (e.g. poor connection or user not accepting consent right away)
if (this.pendingEvents.length >= this.maxPendingEvents) {
this.pendingEvents.shift() // Remove oldest event
}
this.pendingEvents.push({ event: '$pageview', properties })
return
}
try {
// Store groups from properties if present (for later group() calls)
if (properties.$groups) {
Object.entries(properties.$groups).forEach(([type, id]) => {
if (id) posthog.group(type, id as string)
})
}
posthog.capture('$pageview', properties, { transport: 'sendBeacon' })
this.emitToDevListeners('pageview', '$pageview', properties)
} catch (error) {
console.error('PostHog pageview capture failed:', error)
}
}
capturePageLeave(properties: Record<string, any>, hasConsent: boolean = true) {
if (!hasConsent) return
if (!this.initialized) {
// Queue the event for when PostHog initializes (up to cap)
// (e.g. poor connection or user not accepting consent right away)
if (this.pendingEvents.length >= this.maxPendingEvents) {
this.pendingEvents.shift() // Remove oldest event
}
this.pendingEvents.push({ event: '$pageleave', properties })
return
}
try {
// Use sendBeacon for page leave to survive tab close
posthog.capture('$pageleave', properties, { transport: 'sendBeacon' })
this.emitToDevListeners('pageleave', '$pageleave', properties)
} catch (error) {
console.error('PostHog pageleave capture failed:', error)
}
}
identify(userId: string, properties?: Record<string, any>, hasConsent: boolean = true) {
if (!hasConsent) return
if (!this.initialized) {
// Queue the identification for when PostHog initializes. Merge properties
// across pre-init calls for the same user so callers don't clobber each
// other (e.g. useTelemetryIdentify sets gotrue_id, then a separate effect
// sets org_count — both should land when the SDK flushes).
const pending = this.pendingIdentification
this.pendingIdentification =
pending && pending.userId === userId
? { userId, properties: { ...pending.properties, ...properties } }
: { userId, properties }
return
}
try {
posthog.identify(userId, properties)
this.emitToDevListeners('identify', '$identify', { userId, ...properties })
} catch (error) {
console.error('PostHog identify failed:', error)
}
}
reset() {
this.pendingIdentification = null
this.pendingGroups = {}
this.pendingEvents = []
this.pendingExposures = []
if (!this.initStarted) return
try {
posthog.reset()
} catch (error) {
console.error('PostHog reset failed:', error)
}
}
/**
* Returns PostHog's distinct_id, which holds first-touch attribution data.
* Falls back to reading from PostHog cookie if SDK isn't initialized yet
* (e.g., immediately after OAuth redirect before PostHog loads).
*/
getDistinctId(): string | undefined {
if (this.initialized) {
try {
return posthog.get_distinct_id()
} catch (error) {
console.error('PostHog getDistinctId failed:', error)
}
}
// Fallback: parse distinct_id from PostHog cookie
return this.getDistinctIdFromCookie()
}
/**
* Parse distinct_id from PostHog cookie.
* PostHog stores data in a cookie named `ph_<api_key>_posthog` with format:
* { distinct_id: "...", ... }
*/
private getDistinctIdFromCookie(): string | undefined {
if (typeof document === 'undefined') return undefined
try {
const cookieName = `ph_${this.config.apiKey}_posthog`
const cookies = document.cookie.split(';')
for (const cookie of cookies) {
const trimmed = cookie.trim()
const eqIndex = trimmed.indexOf('=')
if (eqIndex === -1) continue
const name = trimmed.substring(0, eqIndex)
if (name !== cookieName) continue
// Use substring instead of split to handle '=' chars in the value
const cookieValue = decodeURIComponent(trimmed.substring(eqIndex + 1))
const phData = JSON.parse(cookieValue)
if (phData.distinct_id && typeof phData.distinct_id === 'string') {
return phData.distinct_id
}
}
} catch {
// No op, cookie may not exist (first visit) or be malformed
}
return undefined
}
/**
* Returns the current value of a person property as stored locally by posthog-js.
* Returns undefined if PostHog hasn't initialized or the property hasn't been set.
* Use this to gate behavior on whether a property has actually landed in the SDK
* (e.g., waiting for an identify to complete before evaluating flag-dependent UI).
*
* Person properties set via `identify(id, props)` are stored under the
* `$stored_person_properties` bucket in persistence — `get_property(key)`
* reads top-level super properties, not person properties, so we index in.
*/
getPersonProperty(key: string): unknown {
if (!this.initialized) return undefined
try {
const stored = posthog.get_property('$stored_person_properties')
if (!stored || typeof stored !== 'object') return undefined
return (stored as Record<string, unknown>)[key]
} catch {
return undefined
}
}
/**
* Returns a PostHog feature flag value directly from the client-side SDK.
* Use this for www/docs pages where server-side evaluation lacks full person context.
* In local dev, DevToolbar overrides (x-ph-flag-overrides cookie) take priority.
*/
getFeatureFlag(key: string): string | boolean | undefined {
if (typeof document === 'undefined') return undefined
if (process.env.NODE_ENV === 'development') {
try {
const cookieEntry = document.cookie
.split(';')
.map((c) => c.trim())
.find((c) => c.startsWith('x-ph-flag-overrides='))
if (cookieEntry) {
const overrides = JSON.parse(
decodeURIComponent(cookieEntry.substring('x-ph-flag-overrides='.length))
)
if (key in overrides) return overrides[key]
}
} catch {}
}
if (!this.initialized) return undefined
try {
return posthog.getFeatureFlag(key)
} catch {
return undefined
}
}
/**
* Subscribe to PostHog feature flag loads/reloads.
* Returns an unsubscribe function.
*/
onFeatureFlags(callback: () => void): () => void {
if (!this.initStarted) {
// Queue until init() is called
this.pendingFeatureFlagCallbacks.add(callback)
return () => this.pendingFeatureFlagCallbacks.delete(callback)
}
if (typeof posthog.onFeatureFlags !== 'function') return () => {}
return posthog.onFeatureFlags(callback) ?? (() => {})
}
/**
* Returns PostHog's session_id for the current session.
* Returns undefined until PostHog's `loaded` callback fires.
*/
getSessionId(): string | undefined {
if (!this.initialized) return undefined
try {
return posthog.get_session_id()
} catch (error) {
console.error('PostHog getSessionId failed:', error)
return undefined
}
}
/**
* Captures an experiment exposure event with session-based deduplication.
* Events are queued if PostHog is not yet initialized, then deduped on flush.
*/
captureExperimentExposure(
experimentId: string,
properties: Record<string, any>,
hasConsent: boolean = true
) {
if (!hasConsent) return
if (!this.initialized) {
// Only queue if not already queued for this experiment (first exposure wins)
if (!this.pendingExposures.some((e) => e.experimentId === experimentId)) {
if (this.pendingExposures.length >= this.maxPendingEvents) {
this.pendingExposures.shift()
}
this.pendingExposures.push({ experimentId, properties })
}
return
}
this.fireExposureIfNew(experimentId, properties)
}
private fireExposureIfNew(experimentId: string, properties: Record<string, any>) {
const sessionId = this.getSessionId()
if (!sessionId) return
const storageKey = `ph_exposed:${experimentId}`
try {
if (safeSessionStorage.getItem(storageKey) === sessionId) return
const eventName = `${experimentId}_experiment_exposed`
posthog.capture(eventName, { experiment_id: experimentId, ...properties })
safeSessionStorage.setItem(storageKey, sessionId)
} catch (error) {
console.error('PostHog experiment exposure capture failed:', error)
}
}
subscribeToEvents(listener: ClientTelemetryListener): () => void {
this.devListeners.add(listener)
return () => this.devListeners.delete(listener)
}
private emitToDevListeners(
eventType: ClientTelemetryEvent['eventType'],
eventName: string,
properties?: Record<string, unknown>
) {
if (this.devListeners.size === 0) return
let distinctId: string | undefined
try {
const id = posthog.get_distinct_id?.()
if (id && id.length > 0) {
distinctId = id
}
} catch {}
const event: ClientTelemetryEvent = {
id: `client-${Date.now()}-${Math.random().toString(36).slice(2, 9)}`,
timestamp: Date.now(),
eventType,
eventName,
distinctId,
properties,
}
this.devListeners.forEach((listener) => {
try {
listener(event)
} catch (e) {
console.error('Dev telemetry listener error:', e)
}
})
}
}
export const posthogClient = new PostHogClient()