ingest: encode PostHog project path segment - #998
Open
sdivyanshu90 wants to merge 1 commit into
Open
sdivyanshu90 wants to merge 1 commit into
sdivyanshu90 wants to merge 1 commit into
Conversation
Contributor
Author
|
Hi @SilenNaihin, could you please review this when you have a chance? It keeps PostHog project IDs within one encoded path segment and adds a focused transport regression. Thanks! |
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
Contributor
|
sdivyanshu90
force-pushed
the
fix/encode-posthog-project-id
branch
from
September 16, 2026 06:34
dbbcc14 to
6b78528
Compare
sdivyanshu90
force-pushed
the
fix/encode-posthog-project-id
branch
from
September 16, 2026 06:39
6b78528 to
55dfdc3
Compare
Contributor
Author
|
@kfallah Could you please review this PR whenever you have some time? Thanks |
Contributor
Author
|
Hi @SilenNaihin @kfallah, could you please review this PR whenever you have some time. Thanks! |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
PostHogPullRequest.project_idaccepts any nonblank string, butpull_posthog_tracesinserted it directly into/api/projects/{project_id}/query/. Reserved and Unicode characters could therefore change the authorized request target instead of remaining one project path segment.Closes #997.
What
.and..segments.posthog_pull_test.pyinjected-client regression covering path, query, fragment, percent, space, and Unicode characters.Validation
test_project_id_is_encoded_as_one_url_path_segmentfailed with the raw project ID in the captured URL.uv run --no-sync pytest -q exp/simulation/ingest/posthog_pull_test.py exp/simulation/ingest/posthog_canonical_test.py: 21 passed in 1.21suv run --no-sync ruff check .: passeduv run --no-sync ruff format --check .: 859 files already formatteduv run --no-sync ty check: passedNon-goals
This change does not alter PostHog host validation, credentials, HogQL construction, response handling, or source identity.