docs(proxy): say whether the managed proxy forwards cookies - #20049
Draft
posthog[bot] wants to merge 2 commits into
Draft
docs(proxy): say whether the managed proxy forwards cookies#20049posthog[bot] wants to merge 2 commits into
posthog[bot] wants to merge 2 commits into
Conversation
The managed reverse proxy page had no answer about the Cookie header, while the self-hosted proxy guides all tell people to delete it. Add an FAQ entry that states what the managed proxy does with the header, what ingestion does with it, which request can carry cookies, and how to keep cookies inside your own domain. Generated-By: PostHog Desktop Task-Id: d15c3d10-27fe-4651-8ce0-ae8bc0a142f9
Contributor
Deploy preview
|
Two edge paths serve managed proxies, and only one has publicly verifiable route config. State the conservative answer, which holds for both, instead of a definite negative about the path that could not be checked. Generated-By: PostHog Desktop Task-Id: d15c3d10-27fe-4651-8ce0-ae8bc0a142f9
Contributor
|
Vale prose linter → found 0 errors, 6 warnings, 0 suggestions in your markdown Full report → Copy the linter results into an LLM to batch-fix issues. Linter being weird? Update the rules!
|
| Line | Severity | Message | Rule |
|---|---|---|---|
| 110:53 | warning | 'erroring' is a possible misspelling. | PostHogBase.Spelling |
| 151:4 | warning | 'FAQ' heading should be in sentence case, and product names should be capitalized. | PostHogBase.SentenceCase |
| 153:40 | warning | 'erroring' is a possible misspelling. | PostHogBase.Spelling |
| 165:5 | warning | 'For EU Cloud, is managed reverse proxy traffic guaranteed to terminate only at EU Cloudflare edges?' heading should be in sentence case, and product names should be capitalized. | PostHogBase.SentenceCase |
| 167:85 | warning | 'anycast' is a possible misspelling. | PostHogBase.Spelling |
| 178:66 | warning | Capitalize 'Logs' for PostHog's product. Use 'logs' for the general industry concept. | PostHogBase.ProductNames |
Contributor
Bundle reportTotal JS (gzip)8.86 MiB (+0.7 KiB / +0.0%) Eager graph (modules shipped in each entrypoint's initial chunks)
Largest modules in the
|
| Module | Size |
|---|---|
./src/data/mcp-tools.json |
1119.1 KiB |
css ./node_modules/.pnpm/css-loader@5.2.7_webpack@5.101.3/node_modules/css-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[1]!./node_modules/.pnpm/postcss-loader@4.3.0_postcss@8.5.6_webpack@5.101.3/node_modules/postcss-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[2]!./src/styles/global.css |
761.0 KiB |
./src/components/Stickers/Stickers.tsx |
696.4 KiB |
./node_modules/.pnpm/@radix-ui+react-icons@1.3.2_react@18.3.1/node_modules/@radix-ui/react-icons/dist/react-icons.esm.js |
481.4 KiB |
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/x-ray.mjs |
480.8 KiB |
./node_modules/.pnpm/rehype-raw@7.0.0/node_modules/rehype-raw/lib/index.js + 29 modules |
395.1 KiB |
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/im-the-driver.mjs |
385.7 KiB |
./src/hooks/useCustomers.tsx + 55 modules |
370.0 KiB |
./node_modules/.pnpm/@posthog+icons@0.36.6_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js |
354.8 KiB |
./node_modules/.pnpm/react-markdown@8.0.7_@types+react@16.14.66_react@18.3.1/node_modules/react-markdown/lib/react-markdown.js + 88 modules |
351.4 KiB |
./src/components/ProductComparisonTable/index.tsx + 126 modules |
302.5 KiB |
./node_modules/.pnpm/cloudinary-core@2.14.0_lodash@4.17.21/node_modules/cloudinary-core/cloudinary-core.js |
281.9 KiB |
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/doll-house.mjs |
281.7 KiB |
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/director.mjs |
275.6 KiB |
./src/components/SearchUI/index.tsx + 87 modules |
273.0 KiB |
Eager-graph budgets are report-only until a baseline is established. Sizes are gzip of public/**/*.js; eager size is webpack module source bytes for the modules actually shipped in the entrypoint's initial chunks (post-tree-shake).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Managed reverse proxy customers ask whether PostHog strips the
Cookieheader, and the page had no answer. This adds one FAQ entry that answers it, states what our ingestion does with the header, and gives two ways to keep cookies inside your own domain. Prose only, one file.Problem
_snippets/proxy-cookies.mdxexists for exactly that. The managed page says nothing, which reads as a contradiction.Changes
fetch/XHRand sends no cookies. The page-unload flush usesnavigator.sendBeacon, and the Beacon spec fixes its credentials mode at include, so the browser attaches apex-scoped cookies to that request and the SDK cannot opt out.persistence: "localStorage", which only moves PostHog's own state and does nothing about the reader's other cookies. The two remedies that work here are host-scoping your auth cookies, or running a self-hosted proxy that deletes the header.I wrote a purpose-fitted entry rather than importing
proxy-cookies.mdx. That snippet's main remedy is "delete the header in your proxy code", which a managed proxy customer cannot do.Evidence
What each claim in the entry rests on
CookieX-Forwarded-Proto, and no header removal is configured. See the caveat below.rust/capturereadscontent-encodingand gateway provenance headers only. No path readsCookie, and no code puts it on the event.fetch/XHRcarry no cookiespackages/browser/src/request.tsinposthog-jssets neithercredentialsnorwithCredentials, so both default to sending none cross-origin.navigator.sendBeacon, whose credentials mode the Beacon spec fixes at include.Important
The entry states the conservative answer on purpose, and an owner can tighten it. Two edge paths serve managed proxies. I verified the route config for the Contour path, which is what the setup steps on this page describe. The Cloudflare Workers path is not in a public repo, so I could not check whether its worker deletes the header. Rather than publish a definite "we do not remove it" that may be wrong for one path, the entry says do not rely on removal. If you know the worker deletes the header, that first sentence should become a plain yes.
Note
One follow-up is out of scope here and needs an infra owner. Deleting
Cookieat both managed proxy edges would remove the exposure rather than describe it, but that config lives in the infra repos and I cannot test an edge change. If it lands, this entry needs its first sentence flipped.Checklist
vercel.json— no page moved, so no redirect is neededNotes on the pre-PR checks:
pnpm formatcovershtml,js,ts,tsx,json,yml,css,scssand not.mdx, so there was nothing for it to format. I did not start the dev server. Instead I compiled the changed file with@mdx-js/mdxand it compiled clean, and I confirmed the three internal links resolve to existing pages. The change adds no imports, no JSX, and no navigation entry. The Vercel preview is the remaining check, and it needs this PR to exist first.Created with PostHog Desktop from this inbox report.