Repository navigation
fix(umami): restore /stats rewrite dropped during env-agnostic refactor #106
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
d2fec48
5d954e1
757f8cc
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| import { type NextRequest, NextResponse } from 'next/server' | ||
|
|
||
| import { readRuntimeConfigFromEnv } from '@/lib/runtimeConfig' | ||
|
|
||
| // Proxy browser-side Umami analytics requests through /stats so the | ||
| // outgoing host is the site's own domain rather than the Umami server, | ||
| // keeping it out of ad-blocker filter lists that target known analytics | ||
| // hosts/paths. | ||
| // | ||
| // The Umami URL is read via readRuntimeConfigFromEnv() (bracket-notation | ||
| // process.env lookup) so the bundler never inlines the value at build time, | ||
| // which keeps one compiled output deployable across environments without | ||
| // triggering check-env-leak in CI. | ||
| // `sendUmamiPayload.ts` routes browser requests to /stats/api/send. | ||
|
|
||
| export async function POST( | ||
| req: NextRequest, | ||
| { params }: { params: Promise<{ path: string[] }> }, | ||
| ): Promise<NextResponse> { | ||
| const umamiUrl = readRuntimeConfigFromEnv().umamiUrl | ||
| if (!umamiUrl) { | ||
| return new NextResponse(null, { status: 204 }) | ||
| } | ||
|
|
||
| const { path } = await params | ||
| const destination = `${umamiUrl}/${path.join('/')}` | ||
|
|
||
| const headers = new Headers(req.headers) | ||
| headers.delete('host') | ||
|
|
||
| const upstream = await fetch(destination, { | ||
| method: 'POST', | ||
| headers, | ||
| body: req.body, | ||
| // @ts-ignore -- duplex is required for streaming request bodies in Node fetch | ||
| duplex: 'half', | ||
| }) | ||
|
|
||
| return new NextResponse(upstream.body, { | ||
| status: upstream.status, | ||
| headers: upstream.headers, | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. SUGGESTION: Filter sensitive headers from upstream response Passing all upstream headers ( |
||
| }) | ||
| } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
WARNING: Silent 204 response hides missing Umami configuration
When
NEXT_PUBLIC_UMAMI_URLis not set, the route returns 204 (No Content) instead of 404 or 500. This makes the client think the analytics request succeeded when it was actually dropped. The previous rewrite approach simply didn't create the route (returning[]), so clients would get a 404. Consider returning 503 or 404 to surface configuration issues, or at minimum log a warning server-side.