feat(core): pair server previews with browser commits - #524
Open
Charles Hudson (phobetron) wants to merge 1 commit into
Open
Charles Hudson (phobetron) wants to merge 1 commit into
Charles Hudson (phobetron) wants to merge 1 commit into
Conversation
|
Bito Automatic Review Skipped - Large PR |
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
Preview ordered identify and track commands with the initial page during request-scoped server rendering, then carry browser-safe commands and preview state in a private handoff. The browser rebuilds and commits the batch through the normal consent, interceptor, queue, state, and persistence pipeline. Make global preflight and initialPageEvent inputs deprecated inert compatibility shells, restrict preflight transport to single-profile mutations, and move Next.js, Angular, and Node plus Web integrations to the paired replay path. Operational preview and private hydration failures now fall back to baseline rendering and an ordinary browser page attempt while cache-safety violations remain fail-closed. Update maintained implementations, documentation, focused coverage, install tooling, and gzip budgets for the new ownership model.
Charles Hudson (phobetron)
force-pushed
the
NT-4307_paired-replay
branch
from
September 30, 2026 08:43
5a29e8b to
b74f605
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Tracking:
NT-4307This changes private SSR and ESR personalization from server commit + browser skip to server preview + browser commit.
identifyandtrackcommands retain application order; the SDK appendspage.The change also confines low-level
preflightto supported single-profile mutations, removes Experience work from the Next.js request-context proxy, and retains superseded options as deprecated inert compatibility inputs.Why
The previous flow committed on the server and suppressed the corresponding browser page event. In hybrid integrations, later browser mutations could move the profile between regions after each server render. It also made
preflightunsafe as a global option because some runtimes had no browser owner available to perform the commit.Paired replay gives each phase one responsibility:
Request lifecycle
sequenceDiagram participant Request as Incoming request participant Server as Node / Next.js / Edge participant API as Experience API participant Handoff as Private handoff participant Browser as Web SDK Request->>Server: context, consent, existing profile ID Server->>API: POST profile?type=preflight<br/>identify*, track*, page API-->>Server: preview profile and selections Server->>Handoff: preview state + route-bound commands Handoff-->>Browser: hydrate preview state in memory Browser->>Browser: match route and re-check live consent Browser->>API: normal POST profile<br/>identify*, track*, page API-->>Browser: committed profile and selections Browser->>Browser: publish state and persist continuityFailure ownership
flowchart TD A[Prepare server preview] -->|accepted| B[Private handoff with preview state] A -->|operational failure| F[Profileless private fallback] B --> C[Hydrate state in memory] C -->|matching route| D[Attempt one-shot browser replay] C -->|stale, mismatched, or hydration failure| E[Discard replay] D -->|committed or atomically queued| G[Accept route and persist committed state] D -->|blocked or delivery failure| E E --> H[Ordinary current-page attempt] F --> H B -->|unsafe public or static cache| I[Reject handoff]Main changes
Core and API client
CoreStatelessRequest.previewInitialExperience()and browser-safe initial-command types.identify/trackorder and append the SDK-builtpagecommand.api.preflight.preflightfrom affecting profile reads or batch/eventsingestion.Web and React Web
initialPageEventinputs inert while keeping them source-compatible and deprecated.Next.js and maintained integrations
createNextjsOptimizationContextHandler()a sanitized context-forwarding helper only.identify/trackcommand resolvers to framework request helpers.Consumer DX
Custom Node SSR
Before, the server committed events and encoded browser suppression in the handoff:
Now, the server previews one ordered batch and the browser-owned route commits it:
Browser application code does not manually replay the commands. Its existing current-page call owns both the replay and ordinary fallback:
Next.js App Router
Before, the proxy could own Experience work and persistence configuration:
Now, the proxy only forwards sanitized request context and the request binding owns preview/replay:
Compatibility and release impact
The following inputs remain accepted but are deprecated and inert:
api.preflight;initialPageEvent;trustedRequestHandoff;persist().This is intentionally a non-breaking correction: obsolete inputs remain source-compatible, and consumers do not need a mode to preserve the previous server-commit/browser-skip behavior. The additive replay APIs imply minor releases for Core, Node, Web, React Web, and Next.js. API Client and native dependency releases remain patch-level where Release Please propagation allows it. The generated Release Please PR remains authoritative for the exact coordinated version set.
Direct Node + Web consumers have one deployment requirement: enable request-scoped server preview before, or atomically with, the browser version that consumes the private replay. Node-only consumers should continue using ordinary committing event methods.
No-JavaScript requests can render previewed personalized HTML, but cannot perform the browser commit or establish new durable profile continuity.
Bundle budgets
Only entries that failed the fresh aggregate report were changed. Values are rounded and retain modest headroom rather than matching the current artifact byte-for-byte.
index.cjsindex.mjsindex.cjsindex.mjsweb-components.cjsapp-router-server.cjsedge.cjsserver.cjsValidation
Passed on the final commit or during its push gate:
pnpm buildpnpm size:reportsize:checkfeat(core): pair server previews with browser commitspnpm build:pkgspnpm knowledge:checkpnpm guides:checkTargeted browser E2E completed during implementation:
Those browser suites were not repeated after the final graceful-fallback refinements. The affected final paths were covered by focused and changed-workspace unit/type gates instead. Per project direction, no full mobile E2E cycle was run.
CI remains responsible for the path-triggered aggregate lint, documentation generation, platform checks, and maintained browser scenarios on the published branch.