* feat: capture ad click IDs for Meta/Google/LinkedIn/TikTok/Reddit/Pinterest attribution Adds gclid, fbclid, li_fat_id, ttclid, rdt_cid, and epik columns to users, captured the same way UTM parameters already are (query string -> session -> persisted on signup, surviving the OAuth redirect round-trip via the new PreservesClickIds trait). Forwards them as first-touch ($set_once) PostHog person properties in SyncUser, so PostHog's native ad-platform destinations (Meta Ads Conversions API, Google Ads Conversions, LinkedIn Ads, TikTok Ads, Reddit Ads, Pinterest) have first-party click IDs to match conversions back to the originating ad click. * refactor: unify PreservesUtmParameters and PreservesClickIds into one trait Both traits captured a set of query-string keys into the session and retrieved them at signup, with identical extract/store/retrieve logic and every call site always using both together — the split added no real separation, just duplicated the same mechanism twice. PreservesAttributionParameters replaces both with a single ATTRIBUTION_KEYS list and one session key. Adding a future ad network's click ID is now one line in that list instead of a second trait. * refactor: split UTM_KEYS and CLICK_ID_KEYS into separate constants Same single trait, single session key, single extract/store/retrieve mechanism — just two named arrays instead of one merged list, so it's clear at a glance which key belongs to which category. * fix: don't truncate ad click IDs to 255 chars, only UTM parameters Ad platforms explicitly warn against assuming a fixed max length for click IDs (Google: gclid has already grown from 26 to 100+ chars, and their docs say never truncate or validate against a fixed length). Truncating would silently corrupt the value into something that no longer matches the real click ID, which is worse than not capturing it at all. Widens the click-id columns from string (VARCHAR 255) to text — safe to edit the migration in place since it hasn't shipped to production yet. UTM parameters still get truncated to 255, since those are ours (our own campaign URLs) and the column stays VARCHAR(255). * refactor: use Laravel collection/Str helpers, forward UTMs to PostHog too - extractAttributionParameters now reads through collect()/Str::limit() instead of raw array_filter/array_map/mb_substr; storeAttributionParameters drops its now-redundant emptiness check since retrieveAttributionParameters already treats "absent" and "present-but-empty" the same via pull()'s default. - SyncUser forwards utm_source/medium/campaign/term/content alongside the click ids as first-touch ($set_once) PostHog person properties. UTMs were never sent to PostHog before this, on any prior code — now that PostHog is the source of truth for ad-platform attribution, it should have the full picture, not just click ids. - Adds the missing GitHub-existing-user click-id session test, mirroring the Google one (parity with the existing UTM coverage). * fix: 3 issues found by review — empty-string leak, duplicated key list, comment style - extractAttributionParameters no longer keeps an empty-string value (e.g. ?utm_source=&gclid=, which some ad/email templates always append even for unfilled slots). The refactor to collect()/Str::limit() a few commits back dropped the outer array_filter() that used to strip these, so they were slipping into User::create() as '' instead of staying null. Restored via a trailing ->filter() on the merged result, and extended the same protection to click ids (which never had it, even before that refactor). - New App\Support\AttributionKeys centralizes the UTM_KEYS/CLICK_ID_KEYS lists that PreservesAttributionParameters and SyncUser each maintained independently. SyncUser previously hand-listed the same 11 field names as a second array with no shared source of truth — a future ad network added to the trait would silently never reach PostHog unless someone remembered to update this second copy too. - Removed the // comment block from the click-id migration explaining the text-column rationale — CLAUDE.md's PHP rules reserve inline comments for exceptionally complex logic; the rationale already lives in the commit message that introduced it.
215 lines
6.6 KiB
PHP
215 lines
6.6 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
use App\Models\User;
|
|
use Laravel\Socialite\Facades\Socialite;
|
|
use Laravel\Socialite\Two\User as SocialiteUser;
|
|
|
|
beforeEach(fn () => config()->set('trypost.self_hosted', false));
|
|
|
|
test('email registration saves ad click ids from the register page query string', function () {
|
|
$clickIds = [
|
|
'gclid' => 'gclid-value',
|
|
'fbclid' => 'fbclid-value',
|
|
'li_fat_id' => 'li-fat-id-value',
|
|
'ttclid' => 'ttclid-value',
|
|
'rdt_cid' => 'rdt-cid-value',
|
|
'epik' => 'epik-value',
|
|
];
|
|
|
|
$this->get(route('register', $clickIds));
|
|
|
|
$this->post(route('register.store'), [
|
|
'name' => 'Click User',
|
|
'email' => 'click@example.com',
|
|
'password' => 'Password123!',
|
|
])
|
|
->assertRedirect(route('register.success', $clickIds, absolute: false));
|
|
|
|
$this->assertDatabaseHas('users', [
|
|
'email' => 'click@example.com',
|
|
...$clickIds,
|
|
]);
|
|
});
|
|
|
|
test('email registration without click ids saves null columns', function () {
|
|
$this->post(route('register.store'), [
|
|
'name' => 'No Click User',
|
|
'email' => 'no-click@example.com',
|
|
'password' => 'Password123!',
|
|
]);
|
|
|
|
$this->assertDatabaseHas('users', [
|
|
'email' => 'no-click@example.com',
|
|
'gclid' => null,
|
|
'fbclid' => null,
|
|
'li_fat_id' => null,
|
|
'ttclid' => null,
|
|
'rdt_cid' => null,
|
|
'epik' => null,
|
|
]);
|
|
});
|
|
|
|
test('click id values longer than 255 characters are stored in full, unlike utm parameters', function () {
|
|
$longValue = str_repeat('a', 300);
|
|
|
|
$this->get(route('register', ['gclid' => $longValue]));
|
|
|
|
$this->post(route('register.store'), [
|
|
'name' => 'Long Click User',
|
|
'email' => 'long-click@example.com',
|
|
'password' => 'Password123!',
|
|
]);
|
|
|
|
$user = User::where('email', 'long-click@example.com')->first();
|
|
|
|
expect($user->gclid)->toBe($longValue);
|
|
});
|
|
|
|
test('google registration saves ad click ids captured before the oauth round-trip', function () {
|
|
$clickIds = ['gclid' => 'g-click', 'fbclid' => 'fb-click'];
|
|
|
|
$this->get(route('auth.google.redirect', $clickIds));
|
|
|
|
$socialiteUser = new SocialiteUser;
|
|
$socialiteUser->id = 'g-click-user';
|
|
$socialiteUser->name = 'Google Click';
|
|
$socialiteUser->email = 'google-click@example.com';
|
|
|
|
Socialite::shouldReceive('driver')
|
|
->with('google-auth')
|
|
->andReturn($driver = Mockery::mock());
|
|
|
|
$driver->shouldReceive('user')
|
|
->andReturn($socialiteUser);
|
|
|
|
$this->get(route('auth.google.callback'))
|
|
->assertRedirect(route('register.success', $clickIds, absolute: false));
|
|
|
|
$this->assertDatabaseHas('users', [
|
|
'email' => 'google-click@example.com',
|
|
...$clickIds,
|
|
]);
|
|
});
|
|
|
|
test('github registration saves ad click ids captured before the oauth round-trip', function () {
|
|
$clickIds = ['li_fat_id' => 'li-click', 'ttclid' => 'tt-click'];
|
|
|
|
$this->get(route('auth.github.redirect', $clickIds));
|
|
|
|
$socialiteUser = new SocialiteUser;
|
|
$socialiteUser->id = 'gh-click-user';
|
|
$socialiteUser->name = 'GitHub Click';
|
|
$socialiteUser->email = 'github-click@example.com';
|
|
|
|
Socialite::shouldReceive('driver')
|
|
->with('github')
|
|
->andReturn($driver = Mockery::mock());
|
|
|
|
$driver->shouldReceive('scopes')
|
|
->andReturnSelf();
|
|
|
|
$driver->shouldReceive('user')
|
|
->andReturn($socialiteUser);
|
|
|
|
$this->get(route('auth.github.callback'))
|
|
->assertRedirect(route('register.success', $clickIds, absolute: false));
|
|
|
|
$this->assertDatabaseHas('users', [
|
|
'email' => 'github-click@example.com',
|
|
...$clickIds,
|
|
]);
|
|
});
|
|
|
|
test('existing google user login consumes the click id session so it does not leak to a later signup', function () {
|
|
User::factory()->create([
|
|
'email' => 'existing-click@example.com',
|
|
'google_id' => 'g-existing-click',
|
|
]);
|
|
|
|
$this->get(route('auth.google.redirect', ['gclid' => 'stale-click']));
|
|
|
|
$socialiteUser = new SocialiteUser;
|
|
$socialiteUser->id = 'g-existing-click';
|
|
$socialiteUser->name = 'Existing Click User';
|
|
$socialiteUser->email = 'existing-click@example.com';
|
|
|
|
Socialite::shouldReceive('driver')
|
|
->with('google-auth')
|
|
->andReturn($driver = Mockery::mock());
|
|
|
|
$driver->shouldReceive('user')
|
|
->andReturn($socialiteUser);
|
|
|
|
$this->get(route('auth.google.callback'))
|
|
->assertRedirect(route('app.home'));
|
|
|
|
expect(session()->get('attribution_parameters'))->toBeNull();
|
|
});
|
|
|
|
test('existing github user login consumes the click id session so it does not leak to a later signup', function () {
|
|
User::factory()->create([
|
|
'email' => 'existing-gh-click@example.com',
|
|
'github_id' => 'gh-existing-click',
|
|
]);
|
|
|
|
$this->get(route('auth.github.redirect', ['gclid' => 'stale-gh-click']));
|
|
|
|
$socialiteUser = new SocialiteUser;
|
|
$socialiteUser->id = 'gh-existing-click';
|
|
$socialiteUser->name = 'Existing GitHub Click User';
|
|
$socialiteUser->email = 'existing-gh-click@example.com';
|
|
|
|
Socialite::shouldReceive('driver')
|
|
->with('github')
|
|
->andReturn($driver = Mockery::mock());
|
|
|
|
$driver->shouldReceive('scopes')
|
|
->andReturnSelf();
|
|
|
|
$driver->shouldReceive('user')
|
|
->andReturn($socialiteUser);
|
|
|
|
$this->get(route('auth.github.callback'))
|
|
->assertRedirect(route('app.home'));
|
|
|
|
expect(session()->get('attribution_parameters'))->toBeNull();
|
|
});
|
|
|
|
test('an empty query string value is treated the same as an absent one, not stored as an empty string', function () {
|
|
// Some ad/email templates always append every tracking key, leaving
|
|
// unfilled slots blank (?utm_source=&gclid=) instead of omitting them.
|
|
$this->get(route('register', ['utm_source' => '', 'gclid' => '']));
|
|
|
|
$this->post(route('register.store'), [
|
|
'name' => 'Empty Param User',
|
|
'email' => 'empty-param@example.com',
|
|
'password' => 'Password123!',
|
|
]);
|
|
|
|
$this->assertDatabaseHas('users', [
|
|
'email' => 'empty-param@example.com',
|
|
'utm_source' => null,
|
|
'gclid' => null,
|
|
]);
|
|
});
|
|
|
|
test('click ids and utm parameters are both saved when present together', function () {
|
|
$this->get(route('register', [
|
|
'utm_source' => 'google',
|
|
'gclid' => 'mixed-click',
|
|
]));
|
|
|
|
$this->post(route('register.store'), [
|
|
'name' => 'Mixed User',
|
|
'email' => 'mixed@example.com',
|
|
'password' => 'Password123!',
|
|
]);
|
|
|
|
$this->assertDatabaseHas('users', [
|
|
'email' => 'mixed@example.com',
|
|
'utm_source' => 'google',
|
|
'gclid' => 'mixed-click',
|
|
]);
|
|
});
|