Skip to content

DL-349

Boot constructs analytics BEFORE the live clients (createAnalytics → createLiveClients → bootCaller → identify), so the transport’s session-id getter closes over a real Analytics rather than a mutable ref slot or a forward let. Rejected alternatives: mirroring the clients.traceId sink (a workaround for a construction-order problem the reorder deletes) and a forward let analytics (a TDZ-shaped undefined window every reader must guard). Accepted trade, stated not silent: on the WhoAmI-failure early return an analytics-enabled deployment now emits an anonymous PostHog session (init-time remote-config egress) where it previously emitted nothing — the reorder is unavoidable while the transport needs the getter at construction, and the egress itself is declined-not-absent (advanced_disable_flags would suppress it, at the cost of remote config), with nothing captured either way. The sender-side guard is printable ASCII + .length ≤ 200, STRICTER than the server’s ≤200 bytes + valid-UTF-8 pair and NARROWER than Headers.set itself, because Headers.set is a WebIDL ByteString: a well-formed id above U+00FF THROWS inside the interceptor and would fail the RPC, and U+0080–U+00FF is accepted by set but a browser then emits it as a SINGLE RAW HIGH BYTE on the wire, which fails Go’s utf8.ValidString, so sessionIDFromHeader returns "" and the id is DROPPED — silent loss, the same failure class as every other rejected value, NOT a wrong correlation key the server accepts (measured: raw-TCP wire bytes 736573732de9 from Node/undici, which serializes like a browser; and real Chromium → real Go net/http running a verbatim sessionIDFromHeader copy — len 6, utf8.ValidString false, result "". A Bun-client-to-Bun.serve round-trip measures Bun’s own encode/decode pair, not the wire, and is NOT valid evidence here)

Status: Active (Matt, 2026-09-07)

Record: ../../ui/compass-outbound-session-header/design.md#the-boot-reorder-chosen–approved-by-matt