Skip to content

feat(auth): preserve installer attribution through signup - #129

Merged
matanyall merged 2 commits into
mainfrom
codex/signup-attribution
Oct 9, 2026
Merged

matanyall merged 2 commits into
mainfrom
codex/signup-attribution

Conversation

@matanyall

Copy link
Copy Markdown
Contributor

Preserve acquisition attribution from the website installer through CLI email and browser signup. The installer record is validated and only the allowed source, campaign, landing page, blog and signup page fields are forwarded.

Also supply the required Better Stack team name during integration connection, fixing the existing typecheck mismatch with the current API schema.

Validation: typecheck, lint and the CLI test suite pass. New attribution tests are offline. Live browser/email signup remains a human check.

Companion PRs: https://github.com/coreplanelabs/nominal/pull/4513 and https://github.com/coreplanelabs/polylanedotcom/pull/573. Release the backend and CLI before the website installer handoff.

@matanyall
matanyall requested a review from justinhelmer October 9, 2026 21:45
@polylane

polylane Bot commented Oct 9, 2026

Copy link
Copy Markdown

Warning

Polylane could not verify the production impact of this pull request.

Checked the change against the deployed API: the new attribution signup field is stripped by zSignup (a non-strict z.object), and nominal-api-access-prod served 14,932 requests with 0 errors over 48h. No production path degrades on merge.

View the full analysis →

Also considered · 3 refuted
  • Refuted · New attribution field in the signup body is rejected by the backend and breaks signup · The request validator is zSignup in coreplanelabs/nominal packages/db/zod/users.ts, a plain z.object (not z.strictObject); zod strips unknown keys by default, so attribution is dropped, not rejected.
  • Refuted · Requiring --team-name on Better Stack connect breaks existing non-interactive invocations · The change exists to satisfy a server-side requirement: the API schema already requires teamName (the typecheck mismatch the commit fixes), so a body without it was already rejected downstream.
  • Refuted · Attribution JSON in the /signup query param overflows or corrupts the browser signup URL · parseSignupAttribution caps every field at 256 chars and rejects any raw source over 4096; the encoded JSON stays a few KB, within browser and Cloudflare URL limits.
Analysed against 8 cloud accounts and 1 repository
  • Cloud accounts: coreplane-prod, baseberry-uat, coreplane-infra, coreplane, coreplane-gtm, 251714435813, Polylane, coreplanelabs
  • Repository: coreplanelabs/cli

View in Polylane Disable reviews

Polylane could not find the cloud resources this repository manages, so this review looked at the entire cloud account. Connect this repository to its resources and the next review will focus on exactly what this code deploys to.

Connect resources

Polylane analysed 4b85388 for production impact. You can ask follow-ups by mentioning @polylane in a comment.

Did this help? React 👍 or 👎 so the next review is sharper.

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: 1 issue

Reviewed at 4b85388.

For agents

Rationale: No consequential code defects found; end-to-end attribution requires the documented companion rollout.

Severity Finding Where
nit F1 End-to-end attribution depends on the still-unmerged backend and installer changes. src/commands/auth/signup.ts:309

Full review

F1 (high confidence): Backend/console PR coreplanelabs/nominal#4513 and installer PR coreplanelabs/polylanedotcom#573 are still open, and the deployed signup schema does not expose attribution. This is non-blocking given the documented rollout order, but deploy the backend/console support and release this CLI before enabling the website handoff.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: coreplane-switchboard[bot] reviewed this PR and posted an LGTM verdict (see its review). A repo admin enabled this via the auto-approve workflow.

@matanyall

Copy link
Copy Markdown
Contributor Author

F1 acknowledged: the rollout order is documented in this PR and both companion PR descriptions. Deploy backend/console support from coreplanelabs/nominal#4513, release this CLI, then enable the website installer handoff from coreplanelabs/polylanedotcom#573. The optional attribution field is ignored by the current server and the record is only introduced by the companion website change. No additional code change is needed for this coordinated rollout; none of these PRs will be merged automatically.

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: no issues found

Reviewed at 4b85388.

For agents

Rationale: No actionable defects remain; F1 is closed as an intentional, documented coordinated-rollout requirement.

Prior finding Resolution Evidence at this head
review:5475686156:F1 declined Verified at the same pinned head: src/auth/signup-attribution.ts returns null for missing or invalid installer records; src/commands/auth/signup.ts and src/auth/oauth.ts conditionally forward validated attribution without changing the no-record paths. Current backend main packages/db/zod/users.ts declares attribution as an optional JSON string bounded at 4096 characters, compatible with this CLI's sanitized output. All three PR descriptions explicitly require backend deployment and CLI release before enabling the website handoff; nominal#4513 is now merged and website#573 remains open. F1 identifies that intentional release prerequisite, not an unresolved CLI defect. This disposition does not assert production deployment or completion of live signup checks.

Full review

F1 is closed as an intentional, documented coordinated-rollout requirement; no CLI code change is needed.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: coreplane-switchboard[bot] reviewed this PR and posted an LGTM verdict (see its review). A repo admin enabled this via the auto-approve workflow.

@matanyall
matanyall merged commit 6cfe382 into main Oct 9, 2026
6 checks passed
@matanyall
matanyall deleted the codex/signup-attribution branch October 9, 2026 23:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant