Skip to content

fix(flags): Revert changes to remote_config endpoint - #36273

Merged
haacked merged 1 commit into
masterfrom
haacked/revert-remote-config-changes
Aug 6, 2025
Merged

haacked merged 1 commit into
masterfrom
haacked/revert-remote-config-changes

Conversation

@haacked

@haacked haacked commented Aug 6, 2025

Copy link
Copy Markdown
Contributor

Problem

I made some changes to the remote_config endpoint to try and make project selection deterministic:

It turns out there's already a supported and simpler way to do it: pass the project api token in the token query string parameter (like so). No changes were needed on the server.

This is what the local_evaluation endpoint does, so we should follow that example.

Changes

This PR reverts changes to the remote_config endpoint. It no longer accepts POST requests and it doesn't look in the request body for the project api token.

Note: I am not reverting the changes to ProjectSecretAPIKeyAuthentication because those were actually needed.

How did you test this code?

Unit Tests.
Manually.

👉 Stay up-to-date with PostHog coding conventions for a smoother review.

I made some changes to the `remote_config` endpoint to try and make project selection deterministic. It turns out there's already a supported and simpler way to do it: pass the project api token in the `token` query string parameter.

This is what the `local_evaluation` endpoint does, so we should follow that example.

I am not reverting the changes to `ProjectSecretAPIKeyAuthentication` because those are actually needed.
@haacked
haacked requested a review from a team as a code owner August 6, 2025 20:43
@dmarticus dmarticus moved this to In Review in Feature Flags Aug 6, 2025

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Greptile Summary

This PR reverts changes made to the remote_config endpoint in previous PRs #36154 and #36267. The original changes attempted to enable deterministic project selection by allowing POST requests with a project_api_key parameter in the request body, which would override the default behavior where personal access tokens route to whichever project the user last visited.

However, the developer discovered that PostHog already has a simpler, supported mechanism for deterministic project routing: passing the project API token directly in the token query string parameter, which is the same pattern used by the local_evaluation endpoint.

The revert involves four key changes:

  1. posthog/api/routing.py: Removes the _get_explicit_project_api_key() method and simplifies _get_team_from_request() to only use standard token authentication mechanisms
  2. posthog/api/feature_flag.py: Changes the remote_config endpoint @action decorator from methods=["GET", "POST"] back to methods=["GET"]
  3. posthog/api/test/test_routing.py: Removes the entire TestTeamAndOrgViewSetMixinProjectApiToken test class that was testing the reverted functionality
  4. posthog/api/test/test_feature_flag.py: Updates the test to use query parameters instead of POST body for API token authentication

This change eliminates unnecessary complexity by removing support for POST requests and request body parsing for project selection, while maintaining the existing authentication mechanisms that already solve the deterministic routing problem. The revert aligns the remote_config endpoint with established patterns in the codebase and follows the principle of not maintaining redundant functionality.

Confidence score: 5/5

  • This PR is safe to merge with minimal risk as it's a clean revert that removes complexity while maintaining existing functionality
  • Score reflects that this is a well-reasoned simplification that removes unnecessary code paths and aligns with existing patterns
  • No files require special attention as the changes are straightforward reverts with appropriate test updates

4 files reviewed, no comments

Edit Code Review Bot Settings | Greptile

@github-project-automation github-project-automation Bot moved this from In Review to Approved in Feature Flags Aug 6, 2025
@haacked
haacked merged commit 685ed94 into master Aug 6, 2025
@haacked
haacked deleted the haacked/revert-remote-config-changes branch August 6, 2025 21:00
@github-project-automation github-project-automation Bot moved this from Approved to Done in Feature Flags Aug 6, 2025
@haacked haacked removed this from Feature Flags Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants