You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Load the Freebuff Ads conversion tag (freebuff-tag.js) through the consent runtime under the marketing category, on every route so the ?bfcid= click id captured on a landing page is still available at /signup
Report signup_completed from the email signup form (marketing consent only) with the new user's id as eventId
Send the same conversion server-to-server from databaseHooks.user.create.after when a bfcid cookie is present, covering OAuth/SSO signups and blocked or not-yet-loaded tags; same eventId, so Freebuff dedupes the two reports into one
Postback retries network failures and 5xx with the same eventId/occurredAt, treats every 4xx as terminal, is never awaited, and is disabled unless FREEBUFF_API_KEY is set
Allow https://freebuff.com in hosted script-src and connect-src
Type of Change
New feature
Testing
bun run type-check (apps/sim)
bun run test lib/consent lib/core/security lib/auth app/(auth)/signup: 62 files, 1,013 tests passing
bun run lint, block-registry check, bun run check:audits (52 audits), docs-manifest:check
Not yet verified end to end against Freebuff: that needs a campaign with conversion tracking and a signed test click id
Checklist
Code follows project style guidelines
Self-reviewed my changes
Tests added/updated and passing (new tests pass the test-audit authoring gate)
The PR adds consent-gated Freebuff conversion tracking through a browser tag and a server postback, with click-ID cleanup when marketing consent is absent.
The follow-up change adds the cleanup component and mounts it across routes.
The new component does not meet the repository’s props-interface requirement.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
A[Marketing consent] -->|granted| B[Freebuff tag stores click ID]
A -->|absent or withdrawn| C[Click-ID guard clears cookie]
B --> D[Signup]
D --> E[Browser conversion]
D --> F[Server postback when cookie exists]
E --> G[Freebuff deduplicates by event ID]
F --> G
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
freebuff-tag.js) through the consent runtime under themarketingcategory, on every route so the?bfcid=click id captured on a landing page is still available at/signupsignup_completedfrom the email signup form (marketing consent only) with the new user's id aseventIddatabaseHooks.user.create.afterwhen abfcidcookie is present, covering OAuth/SSO signups and blocked or not-yet-loaded tags; sameeventId, so Freebuff dedupes the two reports into oneeventId/occurredAt, treats every 4xx as terminal, is never awaited, and is disabled unlessFREEBUFF_API_KEYis sethttps://freebuff.comin hostedscript-srcandconnect-srcType of Change
Testing
bun run type-check(apps/sim)bun run test lib/consent lib/core/security lib/auth app/(auth)/signup: 62 files, 1,013 tests passingbun run lint, block-registry check,bun run check:audits(52 audits),docs-manifest:checkChecklist
test-auditauthoring gate)