Skip to content

fix: stop the PostHog OAuth sign-in redirect loop - #19456

Draft
posthog[bot] wants to merge 1 commit into
masterfrom
posthog-self-driving/fixoauth-stop-the-posthog-sign-in-4940da
Draft

fix: stop the PostHog OAuth sign-in redirect loop#19456
posthog[bot] wants to merge 1 commit into
masterfrom
posthog-self-driving/fixoauth-stop-the-posthog-sign-in-4940da

Conversation

@posthog

@posthog posthog Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Changes

Problem

  • Everyone who picks "Sign in with PostHog" on posthog.com hits a redirect loop on /connect/posthog/redirect and lands back on the marketing home page, not signed in. The defect shipped on 2026-07-22 with the flow (464d7be).
  • The landing page cleared the access token with a raw window.history.replaceState. The Gatsby router and the desktop window record never learn about it, so the stored location.search keeps the token.
  • Any window navigation then rebuilds the URL from path + stored search, puts the token back, and remounts the page. On remount the replay guard resets and re-runs the exchange with a token the server has already consumed.
  • The remount also throws away component state, so the disambiguation modal loses its pending token and mode — which is why "I already have an account" appears to do nothing.

Fix

  • Strip the token through the router (navigate(pathname, { replace: true })), which updates the stored window record too, so no later navigation can restore it. This ends the loop.
  • Keep the in-flight sign-in in sessionStorage — the pending disambiguation token and the chosen "create vs link" screen — so a remount restores the flow instead of replaying a consumed token.
  • Return the user to where they started after a completed sign-in or link, instead of navigate('/') to the home page.

Why

The PostHog sign-in path was broken end to end: users who chose the PostHog button could not complete sign-in and were dropped on the home page, with email and password the only workaround.

Checklist

  • I've read the docs and/or content style guides.
  • Words are spelled using American English
  • Use relative URLs for internal links
  • I've checked the pages added or changed in the Vercel preview build
  • If I moved a page, I added a redirect in vercel.json

Created with PostHog Desktop from this inbox report.

Strip the provider access token through the Gatsby router instead of a raw
history.replaceState, so the stored desktop window record forgets the token too.
A later window navigation can no longer put the token back in the URL and remount
the landing page into a loop.

Keep the in-flight sign-in in sessionStorage (pending disambiguation token and the
chosen "create vs link" screen), so a remount restores the flow rather than
replaying a token the server has already consumed.

Return the user to where they started after a completed sign-in or link, instead
of dropping them on the marketing home page.

Generated-By: PostHog Desktop
Task-Id: 5434a37c-b8c3-46b7-864a-ea10b904aa61
@github-actions github-actions Bot added the website About the website (beyond just landing pages) label Aug 13, 2026
@github-actions

github-actions Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Deploy preview

Status Details Updated (UTC)
🟢 Ready View preview Aug 13, 2026 01:32PM

@github-actions

Copy link
Copy Markdown
Contributor

Bundle report

Total JS (gzip)

7.52 MiB (+0.6 KiB / +0.0%)

Eager graph (modules shipped in each entrypoint's initial chunks)

Entrypoint Eager size Budget Modules
app 16.86 MiB (+6.4 KiB / +0.0%) report-only 2019
Largest modules in the app closure
Module Size
./src/data/mcp-tools.json 994.5 KiB
css ./node_modules/.pnpm/css-loader@5.2.7_webpack@5.101.3/node_modules/css-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[1]!./node_modules/.pnpm/postcss-loader@4.3.0_postcss@8.5.6_webpack@5.101.3/node_modules/postcss-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[2]!./src/styles/global.css 745.9 KiB
./src/components/Stickers/Stickers.tsx 696.4 KiB
./node_modules/.pnpm/@radix-ui+react-icons@1.3.2_react@18.3.1/node_modules/@radix-ui/react-icons/dist/react-icons.esm.js 481.4 KiB
./node_modules/.pnpm/rehype-raw@7.0.0/node_modules/rehype-raw/lib/index.js + 29 modules 395.1 KiB
./node_modules/.pnpm/@posthog+icons@0.36.6_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.cjs.js 364.8 KiB
./node_modules/.pnpm/@posthog+icons@0.36.6_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js 354.8 KiB
./src/hooks/useCustomers.tsx + 54 modules 354.5 KiB
./node_modules/.pnpm/react-markdown@8.0.7_@types+react@16.14.66_react@18.3.1/node_modules/react-markdown/lib/react-markdown.js + 88 modules 351.4 KiB
./src/components/ProductComparisonTable/index.tsx + 126 modules 296.6 KiB
./node_modules/.pnpm/cloudinary-core@2.14.0_lodash@4.17.21/node_modules/cloudinary-core/cloudinary-core.js 281.9 KiB
./src/components/SearchUI/index.tsx + 87 modules 273.0 KiB
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/magnifying-glass.mjs 254.7 KiB
./node_modules/.pnpm/framer-motion@10.18.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/framer-motion/dist/es/render/dom/motion.mjs + 109 modules 253.9 KiB
./node_modules/.pnpm/d3@7.9.0/node_modules/d3/src/index.js + 208 modules 247.4 KiB

Eager-graph budgets are report-only until a baseline is established. Sizes are gzip of public/**/*.js; eager size is webpack module source bytes for the modules actually shipped in the entrypoint's initial chunks (post-tree-shake).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

website About the website (beyond just landing pages)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants