Repository navigation
fix(analytics): count pageviews via GoatCounter API from an edge function - #144
Conversation
…tion Visits to roschaefer.de stopped showing up in GoatCounter. The /gc/count Netlify rewrite made every hit arrive from Netlify's AWS egress IPs, and GoatCounter takes the connecting proxy as the client IP and flags AWS ranges as bots (isbot BotRangeAWS). Those hits were stored as bots and never counted, while the endpoint still answered 200 with a GIF. The edge function records the hit through /api/v0/count instead, passing the visitor's own IP and user agent so bot detection and unique-visitor sessions work again. It keeps the first-party /gc/count path, so ad blockers still don't block the beacon; loading GoatCounter directly was the simpler alternative but loses that. Requires a GoatCounter API token with the "Record pageviews" permission in the GOATCOUNTER_API_TOKEN Netlify environment variable. Verified with pnpm check:quick; not yet exercised on a Netlify deploy.
✅ Deploy Preview for roschaefer ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe ChangesGoatCounter tracking
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant Visitor
participant NetlifyGoatcounterEdgeFunction
participant GoatCounterAPI
Visitor->>NetlifyGoatcounterEdgeFunction: Request /gc/count with tracking data
NetlifyGoatcounterEdgeFunction->>GoatCounterAPI: POST hit when token and page path are present
NetlifyGoatcounterEdgeFunction->>Visitor: Return no-store GIF
Merge Risk: ⚪ Minimal · up to The change preserves first-party tracking while forwarding visitor details through the GoatCounter API. No actionable merge-blocking issue was found. Configure the required API token and confirm pageviews on a Netlify deploy. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new credentialed relay is limited to one analytics site, with a fixed destination and a server-side token. Public tracking submissions were already possible. No increased access to other assets was established, but deployed token permissions, visitor identity handling, and background delivery remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Visits to roschaefer.de stopped showing up in GoatCounter. The /gc/count Netlify rewrite made every hit arrive from Netlify's AWS egress IPs, and GoatCounter takes the connecting proxy as the client IP and flags AWS ranges as bots (isbot BotRangeAWS). Those hits were stored as bots and never counted, while the endpoint still answered 200 with a GIF.
The edge function records the hit through /api/v0/count instead, passing the visitor's own IP and user agent so bot detection and unique-visitor sessions work again. It keeps the first-party /gc/count path, so ad blockers still don't block the beacon; loading GoatCounter directly was the simpler alternative but loses that.
Requires a GoatCounter API token with the "Record pageviews" permission in the GOATCOUNTER_API_TOKEN Netlify environment variable.
Verified with pnpm check:quick; not yet exercised on a Netlify deploy.