Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 15 additions & 5 deletions .github/workflows/vercel-performance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -381,13 +381,23 @@ jobs:
'speed-index',
];

// Path only, deliberately dropping the query: measured URLs carry the
// Vercel bypass secret as a parameter, which must not reach a label, a
// baseline key or the comment. It also keeps labels stable when a
// caller adds a tracking parameter to a measured path.
// Path and query, so measured paths that differ only by query (e.g.
// /search?q=a and /search?q=b) keep separate labels and baselines.
// The bypass secret reaches Chrome as a header rather than a URL
// parameter, but Vercel's bypass parameters are stripped anyway in
// case a caller wrote one into measured-paths: a label reaches the
// baseline cache and the comment, neither of which is redacted.
//
// Deleting re-serialises the whole query (e.g. %20 becomes +), so
// only delete when present to keep labels as the caller wrote them.
const STRIPPED_PARAMS = ['x-vercel-protection-bypass', 'x-vercel-set-bypass-cookie'];
const toLabel = (url) => {
try {
return new URL(url).pathname || '/';
const parsed = new URL(url);
for (const name of STRIPPED_PARAMS) {
if (parsed.searchParams.has(name)) parsed.searchParams.delete(name);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You don't need the has call here, delete is a no-op if the name isn't in the URLSearchParams.

}
return `${parsed.pathname || '/'}${parsed.search}`;
} catch {
return url;
}
Expand Down
Loading