Skip to main content

Subject: Query string parameters (utm_source, gclid, fbclid) are converted into

More
3 hours 48 minutes ago #100000079 by smoothie
-- url of the page with the problem -- : hungarianflavours.com/hu
-- HikaShop version -- : 6.6.0
-- Joomla version -- : 6.1.0
-- PHP version -- : 8.3
-- Browser(s) name and version -- : Chrome 150.0.7871.125

Subject: Query string parameters (utm_source, gclid, fbclid) are converted into SEF path segments via redirect – tracking data lost, cookies/session ID leaked into URL
Environment
  • Joomla 6.1.0, HikaShop [VERSION]
  • PHP 8.3 (CGI/FastCGI), Apache behind nginx
  • Joomla SEF + URL rewriting enabled, multilingual site (Language Filter, URL prefix
    Code:
    /hu
    )
  • HikaShop: "Remove products and categories id in URLs" = Yes, "Force canonical URLs on listings" = "Use canonical URL and generate it if missing", category SEF name =
    Code:
    kategoria
Steps to reproduce
  1. Open any HikaShop page with any query string parameter, e.g.:
    • Code:
      https://hungarianflavours.com/hu/webaruhaz/bio-ceklale?utm_source=facebook
    • Code:
      https://hungarianflavours.com/hu/webaruhaz/kategoria/gyumolcslevek?gclid=abc
    • Code:
      https://hungarianflavours.com/hu/webaruhaz?utm_source=x
      (menu item of the main category listing)
  2. HikaShop immediately redirects to a URL where every request variable is appended as a path segment:
    • Code:
      /hu/webaruhaz/bio-ceklale/utm_source-facebook
    • Code:
      /hu/webaruhaz/utm_source-x
      → 404 on the main shop listing
    • Code:
      /hu/webaruhaz/kosar?utm_source=x
      →
      Code:
      /hu/webaruhaz/kosar/view-category/layout-listing/utm_source-x
      → 404
Joomla com_content pages on the same site keep the query string and do not redirect, so the behaviour is HikaShop-specific.
Additional finding (security)
On our server
Code:
request_order
was empty, so
Code:
$_REQUEST
also contained cookies. Because of this, the redirect URL contained all cookie values, including the session cookie, e.g.:
Code:
/hu/webaruhaz/bio-ceklale/utm_source-x/hikashop_blockCols-.../cookie_price_display-2/.../PHPSESSID-<session id>/...

This means a visitor's session ID ends up in the address bar, in shared links and in analytics. We have set
Code:
request_order = "GP"
as a workaround, but HikaShop should not build redirect URLs from
Code:
$_REQUEST
(cookies) at all.
Impact
  • Google Ads auto-tagging (
    Code:
    gclid
    ,
    Code:
    gbraid
    ,
    Code:
    wbraid
    ), Facebook
    Code:
    fbclid
    and UTM parameters are removed from the query string before the page loads, so Google Ads / GA4 conversion attribution and campaign tracking do not work for shop pages.
  • 404 errors for ad and social clicks landing on the main shop listing and on the cart.
  • Duplicate URLs (
    Code:
    /product/utm_source-xxx
    ) that can get crawled.
Expected behaviour
Unknown or third-party query parameters (at least
Code:
utm_*
,
Code:
gclid
,
Code:
gbraid
,
Code:
wbraid
,
Code:
fbclid
,
Code:
msclkid
,
Code:
_gl
,
Code:
srsltid
) should be left in the query string, with no redirect. Cookie values must never be used to build URLs.
Question
Which code or setting triggers this "redirect to SEF URL with all request vars"? Is there a configuration option to disable it, or to whitelist or ignore tracking parameters? A patch or a pointer to the responsible file would be very welcome.
Current workaround on our side
An
Code:
.htaccess
rule that 301-redirects any
Code:
/hu/webaruhaz/...
URL containing a tracking segment (
Code:
utm_*-…
,
Code:
gclid-…
,
Code:
fbclid-…
) to the clean URL. This prevents the 404s, but the tracking data is still lost.

Please Log in or Create an account to join the conversation.

Time to create page: 0.169 seconds
Powered by Kunena Forum