fix: stop the PostHog OAuth sign-in redirect loop - #19456
Draft
posthog[bot] wants to merge 1 commit into
Draft
Conversation
Strip the provider access token through the Gatsby router instead of a raw history.replaceState, so the stored desktop window record forgets the token too. A later window navigation can no longer put the token back in the URL and remount the landing page into a loop. Keep the in-flight sign-in in sessionStorage (pending disambiguation token and the chosen "create vs link" screen), so a remount restores the flow rather than replaying a token the server has already consumed. Return the user to where they started after a completed sign-in or link, instead of dropping them on the marketing home page. Generated-By: PostHog Desktop Task-Id: 5434a37c-b8c3-46b7-864a-ea10b904aa61
Contributor
Deploy preview
|
Contributor
Bundle reportTotal JS (gzip)7.52 MiB (+0.6 KiB / +0.0%) Eager graph (modules shipped in each entrypoint's initial chunks)
Largest modules in the
|
| Module | Size |
|---|---|
./src/data/mcp-tools.json |
994.5 KiB |
css ./node_modules/.pnpm/css-loader@5.2.7_webpack@5.101.3/node_modules/css-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[1]!./node_modules/.pnpm/postcss-loader@4.3.0_postcss@8.5.6_webpack@5.101.3/node_modules/postcss-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[2]!./src/styles/global.css |
745.9 KiB |
./src/components/Stickers/Stickers.tsx |
696.4 KiB |
./node_modules/.pnpm/@radix-ui+react-icons@1.3.2_react@18.3.1/node_modules/@radix-ui/react-icons/dist/react-icons.esm.js |
481.4 KiB |
./node_modules/.pnpm/rehype-raw@7.0.0/node_modules/rehype-raw/lib/index.js + 29 modules |
395.1 KiB |
./node_modules/.pnpm/@posthog+icons@0.36.6_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.cjs.js |
364.8 KiB |
./node_modules/.pnpm/@posthog+icons@0.36.6_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js |
354.8 KiB |
./src/hooks/useCustomers.tsx + 54 modules |
354.5 KiB |
./node_modules/.pnpm/react-markdown@8.0.7_@types+react@16.14.66_react@18.3.1/node_modules/react-markdown/lib/react-markdown.js + 88 modules |
351.4 KiB |
./src/components/ProductComparisonTable/index.tsx + 126 modules |
296.6 KiB |
./node_modules/.pnpm/cloudinary-core@2.14.0_lodash@4.17.21/node_modules/cloudinary-core/cloudinary-core.js |
281.9 KiB |
./src/components/SearchUI/index.tsx + 87 modules |
273.0 KiB |
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/magnifying-glass.mjs |
254.7 KiB |
./node_modules/.pnpm/framer-motion@10.18.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/framer-motion/dist/es/render/dom/motion.mjs + 109 modules |
253.9 KiB |
./node_modules/.pnpm/d3@7.9.0/node_modules/d3/src/index.js + 208 modules |
247.4 KiB |
Eager-graph budgets are report-only until a baseline is established. Sizes are gzip of public/**/*.js; eager size is webpack module source bytes for the modules actually shipped in the entrypoint's initial chunks (post-tree-shake).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Problem
/connect/posthog/redirectand lands back on the marketing home page, not signed in. The defect shipped on 2026-07-22 with the flow (464d7be).window.history.replaceState. The Gatsby router and the desktop window record never learn about it, so the storedlocation.searchkeeps the token.path + stored search, puts the token back, and remounts the page. On remount the replay guard resets and re-runs the exchange with a token the server has already consumed.Fix
navigate(pathname, { replace: true })), which updates the stored window record too, so no later navigation can restore it. This ends the loop.sessionStorage— the pending disambiguation token and the chosen "create vs link" screen — so a remount restores the flow instead of replaying a consumed token.navigate('/')to the home page.Why
The PostHog sign-in path was broken end to end: users who chose the PostHog button could not complete sign-in and were dropped on the home page, with email and password the only workaround.
Checklist
vercel.jsonCreated with PostHog Desktop from this inbox report.