Repository navigation
Send CLI analytics headers on all RevenueCat API requests - #186
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Core behavior and coverage are sound; only a minor README scope clarification remains.
Review effort: Balanced
Findings: 1
What changed in this PR
Extends CLI analytics headers to all RevenueCat HTTP clients while preserving opt-out, overrides, and authorization protection.
Changes:
- Adds shared headers to OAuth, SDK, Rico, and Paywall AI requests.
- Updates command wiring and analytics documentation.
- Adds end-to-end coverage across modes, overrides, and opt-out behavior.
| File | Description |
|---|---|
| README.md | Documents expanded analytics coverage. |
| internal/cli/runtime.go | Configures OAuth headers centrally. |
| internal/cli/rico.go | Adds analytics headers to Rico. |
| internal/cli/paywalls_ai.go | Adds headers to Paywall AI. |
| internal/cli/offerings.go | Configures SDK request headers. |
| internal/cli/offerings_verify_test.go | Tests offering-preview headers. |
| internal/cli/customers.go | Configures receipt request headers. |
| internal/cli/customers_simulate_purchase_test.go | Tests purchase-flow headers. |
| internal/cli/cli_test.go | Tests signup headers end-to-end. |
| internal/cli/auth.go | Uses configured OAuth service. |
| internal/cli/analytics.go | Broadens helper documentation. |
| internal/cli/analytics_test.go | Tests all non-v2 clients and modes. |
| internal/api/sdk.go | Adds SDK options and header application. |
| internal/api/sdk_test.go | Tests SDK overrides and authorization protection. |
| internal/api/oauth.go | Adds OAuth options and header application. |
| internal/api/oauth_test.go | Tests OAuth headers and token requests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
toppare
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Checklist
go build ./...,go test ./..., andgofmtpassMotivation
CLI signup and other non-v2 requests were missing the command and mode headers, so signup source couldn't be captured from the account-creation request.
Description
Send
User-Agent,X-RC-CLI-Command, andX-RC-CLI-Modeon CLI-originated RevenueCat requests: signup/login/logout, OAuth authorization and token exchange/refresh, v1 offerings/receipts, Rico, and Paywall AI (including streams). Keep the existingDO_NOT_TRACKbehavior, custom header overrides, and protected Authorization header.Update the README and add HTTP-server coverage for signup, SDK requests, OAuth, and both AI clients across interactive/agent/CI modes, opt-out, and overrides. Browser authorization and third-party requests keep their own headers; backend signup persistence isn't included here.
Validation:
make check(format, vet, race tests, lint), native build, and Windows cross-build passed. The existing scripted TUI test requires a terminal setting other thandumb; local checks usedTERM=screen-256colorto match the original checkout.Note
Medium Risk
Touches OAuth and signup HTTP paths and changes which headers backends see on auth and v1 SDK traffic; behavior is additive with existing Authorization protection and DO_NOT_TRACK semantics.
Overview
Extends
User-Agent,X-RC-CLI-Command,X-RC-CLI-Mode, andRC_HEADERSto every CLI-originated RevenueCat HTTP path—not only v2—including signup/login, OAuth token exchange/refresh, v1 SDK (offerings/ simulate purchase), Rico, and Paywall AI.Runtime.oauthService()centralizes OAuth client construction with those headers;OAuthServiceandSDKServicenow take options structs and apply extras viahttpx.Apply.Rico and Paywall AI switch from
customHeaders()(env only) torequestHeaders(rt.Globals), soDO_NOT_TRACKand mode/command labeling match the rest of the CLI. README documents the broader coverage, CI taking precedence over agent mode, and that browser/third-party traffic is unchanged.Tests assert headers on the wire for signup, SDK, OAuth refresh, Rico/Paywall streams, overrides, and opt-out.
Reviewed by Cursor Bugbot for commit 08021a1. Bugbot is set up for automated code reviews on this repo. Configure here.