Repository navigation
Conversation
eli-r-ph
force-pushed
the
v1-sdk-identity
branch
from
October 8, 2026 00:08
44123ba to
956c711
Compare
eli-r-ph
force-pushed
the
v1-capture-redirects
branch
from
October 8, 2026 00:08
9f403f2 to
530f831
Compare
_post_v1 disables automatic redirects and resends the batch only on a 307 or 308 to the origin of host, at most 5 times. Any other redirect returns as a terminal failure. Covers the sync client and the async client, which lost its v0 same-origin guard when v1 became the only path.
eli-r-ph
force-pushed
the
v1-capture-redirects
branch
from
October 8, 2026 01:20
530f831 to
6eb24c5
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
💡 Motivation and Context
Stacked on #1034. Part of the 8.0 series (checklist in #1016).
_post_v1used the defaultrequestsredirect handling. On a cross-origin307or308it resent the event batch to the new origin.requestsdropsAuthorizationwhen the host changes, but sends the body. So a response from the ingestion host could make the SDK POST event data to another host, a loopback address, or over plain HTTP.The 7.x async client blocked this for v0 (#899, #941): it followed only same-origin
307/308, at most 5 times. #1017 made v1 the async default and #1018 removed v0, so async lost that guard. The sync client never had it.Changes:
_post_v1sends withallow_redirects=False. It follows a307or308only to the origin ofhost(scheme, host and port), at most 5 times, and keeps the body and headers. The target keeps a path prefix onhost, as fix: preserve redirect URLs with async capture host prefixes #941 did._send_v1_batchalready treats3xxas terminal, so the batch fails at once and reacheson_errorwith the redirect status._post_v1, so both are covered.typings/requests:Session.postacceptsallow_redirects.Addresses the veria-ai findings on #1017 and #1018.
💚 How did you test it?
test_follows_same_origin_redirect_with_same_body: relativeLocation, ahostwith a path prefix, and an explicit default port. Each one checks the URL that is followed, an identical body and headers, andallow_redirects=Falseon every hop.test_does_not_follow_other_redirects: another host, loopback over HTTP, HTTPS to HTTP on the same host, another port, a missingLocation, and a302. Each one sends exactly one request.test_stops_after_max_redirects: a redirect loop stops after 6 requests.test_terminal_status_raises_immediatelycovers307and308: one attempt, thenCaptureErrorwith that status.ruff,mypy(baseline filter),make public_api_check,python -W error -c "import posthog", and the fullpytestsuite pass locally.📝 Checklist
If releasing new changes
sampo addto generate a changeset file🤖 Agent context
Autonomy: Human-driven (agent-assisted)