2025-12-25 12:20:46 +09:00
|
|
|
/**
|
|
|
|
|
* Generate a userId from request for tracking purposes.
|
|
|
|
|
* Uses base64url encoding of IP for URL-safe identifier.
|
|
|
|
|
* Note: base64 is reversible - this is NOT privacy protection.
|
2026-10-06 10:12:15 +09:00
|
|
|
*
|
|
|
|
|
* The first X-Forwarded-For entry is whatever the visitor sent, so behind a
|
|
|
|
|
* CDN set CLIENT_IP_HEADER to the header it fills with the real IP (e.g.
|
|
|
|
|
* cf-connecting-ip), and ORIGIN_SECRET so requests that skip the CDN are
|
|
|
|
|
* refused (see proxy.ts).
|
2025-12-25 12:20:46 +09:00
|
|
|
*/
|
|
|
|
|
export function getUserIdFromRequest(req: Request): string {
|
2026-10-06 10:12:15 +09:00
|
|
|
const ipHeader = process.env.CLIENT_IP_HEADER
|
|
|
|
|
const rawIp =
|
|
|
|
|
(ipHeader
|
|
|
|
|
? req.headers.get(ipHeader)?.trim()
|
|
|
|
|
: req.headers.get("x-forwarded-for")?.split(",")[0]?.trim()) ||
|
|
|
|
|
"anonymous"
|
2025-12-25 12:20:46 +09:00
|
|
|
return rawIp === "anonymous"
|
|
|
|
|
? rawIp
|
|
|
|
|
: `user-${Buffer.from(rawIp).toString("base64url")}`
|
|
|
|
|
}
|