Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 8 additions & 4 deletions posthog/api/posthog.api
Original file line number Diff line number Diff line change
Expand Up @@ -150,8 +150,8 @@ public class com/posthog/PostHogConfig {
public static final field DEFAULT_MAX_QUEUE_SIZE I
public static final field DEFAULT_US_ASSETS_HOST Ljava/lang/String;
public static final field DEFAULT_US_HOST Ljava/lang/String;
public fun <init> (Ljava/lang/String;Ljava/lang/String;ZZZIZLjava/util/List;ZZIIIIIILcom/posthog/PostHogEncryption;Lcom/posthog/PostHogOnFeatureFlags;ZLcom/posthog/PostHogPropertiesSanitizer;Lkotlin/jvm/functions/Function1;ZLcom/posthog/PersonProfiles;ZLjava/net/Proxy;Lcom/posthog/surveys/PostHogSurveysConfig;Lcom/posthog/logs/PostHogLogsConfig;Lkotlin/jvm/functions/Function6;Lkotlin/jvm/functions/Function5;Lcom/posthog/errortracking/PostHogErrorTrackingConfig;Ljava/lang/String;Lcom/posthog/PostHogBootstrapConfig;)V
public synthetic fun <init> (Ljava/lang/String;Ljava/lang/String;ZZZIZLjava/util/List;ZZIIIIIILcom/posthog/PostHogEncryption;Lcom/posthog/PostHogOnFeatureFlags;ZLcom/posthog/PostHogPropertiesSanitizer;Lkotlin/jvm/functions/Function1;ZLcom/posthog/PersonProfiles;ZLjava/net/Proxy;Lcom/posthog/surveys/PostHogSurveysConfig;Lcom/posthog/logs/PostHogLogsConfig;Lkotlin/jvm/functions/Function6;Lkotlin/jvm/functions/Function5;Lcom/posthog/errortracking/PostHogErrorTrackingConfig;Ljava/lang/String;Lcom/posthog/PostHogBootstrapConfig;ILkotlin/jvm/internal/DefaultConstructorMarker;)V
public fun <init> (Ljava/lang/String;Ljava/lang/String;ZZZIZLjava/util/List;ZZIIIIIILcom/posthog/PostHogEncryption;Lcom/posthog/PostHogOnFeatureFlags;ZLcom/posthog/PostHogPropertiesSanitizer;Lkotlin/jvm/functions/Function1;ZLcom/posthog/PersonProfiles;ZLjava/net/Proxy;Lcom/posthog/surveys/PostHogSurveysConfig;Lcom/posthog/logs/PostHogLogsConfig;Lkotlin/jvm/functions/Function6;Lkotlin/jvm/functions/Function5;Lcom/posthog/errortracking/PostHogErrorTrackingConfig;Ljava/lang/String;Lcom/posthog/PostHogBootstrapConfig;Lkotlin/jvm/functions/Function3;)V
public synthetic fun <init> (Ljava/lang/String;Ljava/lang/String;ZZZIZLjava/util/List;ZZIIIIIILcom/posthog/PostHogEncryption;Lcom/posthog/PostHogOnFeatureFlags;ZLcom/posthog/PostHogPropertiesSanitizer;Lkotlin/jvm/functions/Function1;ZLcom/posthog/PersonProfiles;ZLjava/net/Proxy;Lcom/posthog/surveys/PostHogSurveysConfig;Lcom/posthog/logs/PostHogLogsConfig;Lkotlin/jvm/functions/Function6;Lkotlin/jvm/functions/Function5;Lcom/posthog/errortracking/PostHogErrorTrackingConfig;Ljava/lang/String;Lcom/posthog/PostHogBootstrapConfig;Lkotlin/jvm/functions/Function3;IILkotlin/jvm/internal/DefaultConstructorMarker;)V
public final fun addBeforeSend (Lcom/posthog/PostHogBeforeSend;)V
public final fun addIntegration (Lcom/posthog/PostHogIntegration;)V
public final fun getApiKey ()Ljava/lang/String;
Expand Down Expand Up @@ -187,6 +187,7 @@ public class com/posthog/PostHogConfig {
public final fun getPreloadFeatureFlags ()Z
public final fun getPropertiesSanitizer ()Lcom/posthog/PostHogPropertiesSanitizer;
public final fun getProxy ()Ljava/net/Proxy;
public final fun getPushIdentityProvider ()Lkotlin/jvm/functions/Function3;
public final fun getQueueProvider ()Lkotlin/jvm/functions/Function5;
public final fun getReleaseIdentifier ()Ljava/lang/String;
public final fun getRemoteConfig ()Z
Expand Down Expand Up @@ -237,6 +238,7 @@ public class com/posthog/PostHogConfig {
public final fun setPreloadFeatureFlags (Z)V
public final fun setPropertiesSanitizer (Lcom/posthog/PostHogPropertiesSanitizer;)V
public final fun setProxy (Ljava/net/Proxy;)V
public final fun setPushIdentityProvider (Lkotlin/jvm/functions/Function3;)V
public final fun setReleaseIdentifier (Ljava/lang/String;)V
public final fun setRemoteConfig (Z)V
public final fun setRemoteConfigHolder (Lcom/posthog/internal/PostHogRemoteConfig;)V
Expand Down Expand Up @@ -737,8 +739,10 @@ public final class com/posthog/internal/PostHogApi {
public static synthetic fun flags$default (Lcom/posthog/internal/PostHogApi;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/util/Map;Ljava/util/Map;Ljava/util/Map;Ljava/util/List;ZILjava/lang/Object;)Lcom/posthog/internal/PostHogFlagsResponse;
public final fun localEvaluation (Ljava/lang/String;Ljava/lang/String;)Lcom/posthog/internal/LocalEvaluationApiResponse;
public static synthetic fun localEvaluation$default (Lcom/posthog/internal/PostHogApi;Ljava/lang/String;Ljava/lang/String;ILjava/lang/Object;)Lcom/posthog/internal/LocalEvaluationApiResponse;
public final fun pushSubscription (Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;)V
public final fun pushUnsubscription (Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;)V
public final fun pushSubscription (Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;)V
public static synthetic fun pushSubscription$default (Lcom/posthog/internal/PostHogApi;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;ILjava/lang/Object;)V
public final fun pushUnsubscription (Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;)V
public static synthetic fun pushUnsubscription$default (Lcom/posthog/internal/PostHogApi;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;ILjava/lang/Object;)V
public final fun remoteConfig ()Lcom/posthog/internal/PostHogRemoteConfigResponse;
public final fun snapshot (Ljava/util/List;)V
}
Expand Down
20 changes: 20 additions & 0 deletions posthog/src/main/java/com/posthog/PostHogConfig.kt
Original file line number Diff line number Diff line change
Expand Up @@ -328,6 +328,26 @@ public open class PostHogConfig(
* Defaults to null (no bootstrap).
*/
public var bootstrap: PostHogBootstrapConfig? = null,
/**
* Hook that supplies a signed identity token for push subscription requests, enabling the
* optional identity verification of the push subscriptions API.
*
* Invoked with the distinctId and appId the request is about to carry, whenever a token is
* needed and none is cached for that exact pair — and once more after a 401 rejection. Your
* backend mints the token — an HS256 JWT signed with the project's secret API key (never
* embedded in the app), with claims `sub` = distinct id, `app_id`, `aud` =
* "posthog:push_identity", and an `exp` — and you pass it to `completion`, from any thread. Pass `completion(null)`
Comment thread
turnipdabeets marked this conversation as resolved.
* when no token can be minted (e.g. the user is anonymous); the request is then sent without
* one. `completion` must be called exactly once: further calls are ignored, and never calling
* it strands the current registration until the next app launch.
*
* The hook itself runs on the SDK's push executor thread (only `completion` may be called from
* any thread), so return quickly: do the token minting asynchronously and call `completion` when
* it finishes. Blocking here stalls the push retry/offline-resume loop.
*
* Defaults to null (requests are sent without an identity token).
*/
public var pushIdentityProvider: ((distinctId: String, appId: String, completion: (String?) -> Unit) -> Unit)? = null,
) {
@Volatile
private var tracingHeadersList: List<String>? = null
Expand Down
15 changes: 12 additions & 3 deletions posthog/src/main/java/com/posthog/internal/PostHogApi.kt
Original file line number Diff line number Diff line change
Expand Up @@ -139,15 +139,17 @@ public class PostHogApi(
deviceToken: String,
platform: String,
appId: String,
): Unit = sendPushSubscription("POST", distinctId, deviceToken, platform, appId)
identityToken: String? = null,
): Unit = sendPushSubscription("POST", distinctId, deviceToken, platform, appId, identityToken)

@Throws(PostHogApiError::class, IOException::class)
public fun pushUnsubscription(
distinctId: String,
deviceToken: String,
platform: String,
appId: String,
): Unit = sendPushSubscription("DELETE", distinctId, deviceToken, platform, appId)
identityToken: String? = null,
): Unit = sendPushSubscription("DELETE", distinctId, deviceToken, platform, appId, identityToken)

@Throws(PostHogApiError::class, IOException::class)
private fun sendPushSubscription(
Expand All @@ -156,6 +158,7 @@ public class PostHogApi(
deviceToken: String,
platform: String,
appId: String,
identityToken: String?,
Comment thread
ioannisj marked this conversation as resolved.
) {
val pushSubscription =
PostHogPushSubscriptionRequest(
Expand All @@ -164,12 +167,18 @@ public class PostHogApi(
deviceToken = deviceToken,
platform = platform,
appId = appId,
identityToken = identityToken,
)

val url = "$theHost/api/push_subscriptions/"
val request =
makeRequest(url, method = method) {
logRequest(pushSubscription, url)
// Redact the identity token: it is a short-lived bearer credential and logRequest
// writes the whole body to the debug logger (Logcat on Android). CWE-532.
logRequest(
pushSubscription.copy(identityToken = identityToken?.let { "<redacted>" }),
url,
)

config.serializer.serialize(pushSubscription, it.bufferedWriter())
}
Expand Down
Loading
Loading