- Posts: 29
- Thank you received: 0
Subject: Query string parameters (utm_source, gclid, fbclid) are converted into
3 hours 48 minutes ago #100000079
by smoothie
Subject: Query string parameters (utm_source, gclid, fbclid) are converted into was created by smoothie
-- url of the page with the problem -- :
hungarianflavours.com/hu
-- HikaShop version -- : 6.6.0
-- Joomla version -- : 6.1.0
-- PHP version -- : 8.3
-- Browser(s) name and version -- : Chrome 150.0.7871.125
Subject: Query string parameters (utm_source, gclid, fbclid) are converted into SEF path segments via redirect – tracking data lost, cookies/session ID leaked into URL
Environment
Additional finding (security)
On our server
was empty, so
also contained cookies. Because of this, the redirect URL contained all cookie values, including the session cookie, e.g.:
This means a visitor's session ID ends up in the address bar, in shared links and in analytics. We have set
as a workaround, but HikaShop should not build redirect URLs from
(cookies) at all.
Impact
Unknown or third-party query parameters (at least
,
,
,
,
,
,
,
) should be left in the query string, with no redirect. Cookie values must never be used to build URLs.
Question
Which code or setting triggers this "redirect to SEF URL with all request vars"? Is there a configuration option to disable it, or to whitelist or ignore tracking parameters? A patch or a pointer to the responsible file would be very welcome.
Current workaround on our side
An
rule that 301-redirects any
URL containing a tracking segment (
,
,
) to the clean URL. This prevents the 404s, but the tracking data is still lost.
-- HikaShop version -- : 6.6.0
-- Joomla version -- : 6.1.0
-- PHP version -- : 8.3
-- Browser(s) name and version -- : Chrome 150.0.7871.125
Subject: Query string parameters (utm_source, gclid, fbclid) are converted into SEF path segments via redirect – tracking data lost, cookies/session ID leaked into URL
Environment
- Joomla 6.1.0, HikaShop [VERSION]
- PHP 8.3 (CGI/FastCGI), Apache behind nginx
- Joomla SEF + URL rewriting enabled, multilingual site (Language Filter, URL prefix
)Code:/hu
- HikaShop: "Remove products and categories id in URLs" = Yes, "Force canonical URLs on listings" = "Use canonical URL and generate it if missing", category SEF name =
Code:kategoria
- Open any HikaShop page with any query string parameter, e.g.:
-
Code:https://hungarianflavours.com/hu/webaruhaz/bio-ceklale?utm_source=facebook
-
Code:https://hungarianflavours.com/hu/webaruhaz/kategoria/gyumolcslevek?gclid=abc
-
(menu item of the main category listing)Code:https://hungarianflavours.com/hu/webaruhaz?utm_source=x
-
- HikaShop immediately redirects to a URL where every request variable is appended as a path segment:
-
Code:/hu/webaruhaz/bio-ceklale/utm_source-facebook
-
→ 404 on the main shop listingCode:/hu/webaruhaz/utm_source-x
-
→Code:/hu/webaruhaz/kosar?utm_source=x→ 404Code:/hu/webaruhaz/kosar/view-category/layout-listing/utm_source-x
-
Additional finding (security)
On our server
Code:
request_order
Code:
$_REQUEST
Code:
/hu/webaruhaz/bio-ceklale/utm_source-x/hikashop_blockCols-.../cookie_price_display-2/.../PHPSESSID-<session id>/...
This means a visitor's session ID ends up in the address bar, in shared links and in analytics. We have set
Code:
request_order = "GP"
Code:
$_REQUEST
Impact
- Google Ads auto-tagging (
,Code:gclid,Code:gbraidCode:wbraidand UTM parameters are removed from the query string before the page loads, so Google Ads / GA4 conversion attribution and campaign tracking do not work for shop pages.Code:fbclid
- 404 errors for ad and social clicks landing on the main shop listing and on the cart.
- Duplicate URLs (
) that can get crawled.Code:/product/utm_source-xxx
Unknown or third-party query parameters (at least
Code:
utm_*
Code:
gclid
Code:
gbraid
Code:
wbraid
Code:
fbclid
Code:
msclkid
Code:
_gl
Code:
srsltid
Question
Which code or setting triggers this "redirect to SEF URL with all request vars"? Is there a configuration option to disable it, or to whitelist or ignore tracking parameters? A patch or a pointer to the responsible file would be very welcome.
Current workaround on our side
An
Code:
.htaccess
Code:
/hu/webaruhaz/...
Code:
utm_*-…
Code:
gclid-…
Code:
fbclid-…
Please Log in or Create an account to join the conversation.
Time to create page: 0.169 seconds