Skip to content

docs(renderer): add a consent-aware attribution recipe - #518

Merged
kevinchappell merged 3 commits into
mainfrom
docs/485-attribution-draft
Oct 1, 2026
Merged

kevinchappell merged 3 commits into
mainfrom
docs/485-attribution-draft

Conversation

@kevinchappell

Copy link
Copy Markdown
Collaborator

Adds a renderer recipe for capturing marketing attribution on form submissions only when the visitor has consented.

  • docs/renderer/consent-aware-attribution.md: an explicit allowlist of query parameters, the two ways to get values into a submission (merge at submit time, or Hidden fields filled through renderer.userData), and keeping the consent-denied path on the host page.
  • docs/renderer/renderer.md: links the recipe.

The recipe validates keys against the allowlist itself. It doesn't rely on the userData setter, which skips unknown keys with a console warning and never throws.

Refs #485

@Atroci, as promised in the issue, could you review this?

Copilot AI balanced review requested due to automatic review settings September 30, 2026 06:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Atroci

Atroci commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for writing this up. It reads well and keeps every decision on the host side, which was the point of #485. Also, thanks for the correction on the userData setter: I had it wrong in #485 when I said it throws. Filtering with present() is the better design anyway.

Two small things in Option B, neither blocking:

  1. Consent that arrives after load. Option B reads attribution once, right after render(). With a typical consent banner the visitor accepts after the page has loaded, so hasAttributionConsent() is still false at that point and the hidden fields stay empty even though consent was given before submit. Option A doesn't have this problem because it reads at submit time. One fix is to fill the fields in onSubmit (or when consent changes) instead of after render(), or to add one sentence saying the snippet has to run again once consent is granted.

  2. "Plain HTML form POST with no JavaScript handling". The fields are still filled by JavaScript in this recipe, so this phrase may confuse readers. Something like "if your backend reads a single flat form POST" would say the same thing without implying no JS.

Otherwise LGTM.

@kevinchappell

Copy link
Copy Markdown
Collaborator Author

Thanks @Atroci, both fixed in 6e7e3ba.

  1. Option B now fills the hidden fields in onSubmit, so consent given after load still counts.
  2. Swapped the "no JavaScript" line for "if your backend reads a single flat form POST".

@kevinchappell
kevinchappell merged commit fac4ae2 into main Oct 1, 2026
2 checks passed
@kevinchappell
kevinchappell deleted the docs/485-attribution-draft branch October 1, 2026 21:42
@kevinchappell

Copy link
Copy Markdown
Collaborator Author

🎉 This PR is included in version 5.17.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants