Opened 4 years ago

Closed 3 years ago

Last modified 3 years ago

#1553 closed New feature (fixed)

Tracker API improvements : enable set IP and set server date & time

Reported by: matt Owned by: vipsoft
Priority: major Milestone: Piwik 1.2
Component: Core Keywords:
Cc: Sensitive: no

Description

Tracker API allows to record visits, pages and goal conversions using http rest API. Commonly users would have a webserver make the request to Piwik to record visits. This causes piwik to read the visit/page/goal conversion IP as being the server IP issuing the request to piwik.

This could cause discrepancies or generally wrong user data. It would be nice to be able to customize the IP and server time that Piwik uses in the tracker.

It is critical that these 2 attributes can only be set by the Super User, otherwise anyone could record fake time/ fake IP visits in a piwik instance. I suggest we check and require super user token_auth in the piwik.php request to allow setting IP + server time.

Note that in tests, we already set these 2 parameters. To allow this, the proxy-piwik.php hack is used. This mechanism could then be removed to use the token_auth mechanism.

Attachments (1)

1553.patch (3.5 KB) - added by mauser 3 years ago.
Allow overriding ip & serverdate time in Tracking API if proper super user token_auth given.

Download all attachments as: .zip

Change History (16)

comment:1 Changed 4 years ago by matt (mattab)

Note: Image tracker (simple or advanced) solutions are not affected by the "wrong IP" issue, as the browser itself does the request to Piwik, so IP is set correctly to visitor IP.

comment:2 Changed 4 years ago by Vladimir

Is there any updates? Will this feature implemented in next release.

comment:3 Changed 4 years ago by vipsoft (robocoder)

  • Milestone changed from Features requests 1.x or 2.x to 1.1 - Piwik 1.1

No update yet. Not planned for 1.1, but I'll put it on the current milestone so that it has higher near-term visibility.

comment:4 Changed 4 years ago by vipsoft (robocoder)

  • Owner set to vipsoft

comment:5 Changed 3 years ago by vipsoft (robocoder)

  • Owner vipsoft deleted

comment:6 Changed 3 years ago by Vladimir

Who is current owner of this feature?

comment:7 Changed 3 years ago by vipsoft (robocoder)

Matt or myself... whoever gets to it first. Of course, you're welcome to submit a patch... ;)

comment:8 Changed 3 years ago by matt (mattab)

  • Summary changed from Tracker API: Add possibility to define IP and Server time for all requests to Tracker API improvements : enable set IP and set server date & time

comment:9 Changed 3 years ago by matt (mattab)

  • Milestone changed from 1.1 - Piwik 1.1 to 1.2 - Piwik 1.2

comment:10 Changed 3 years ago by matt (mattab)

  • Milestone changed from 1.2 Piwik 1.2 to 1.x - Piwik 1.x

comment:11 Changed 3 years ago by vipsoft (robocoder)

  • Owner set to vipsoft

Changed 3 years ago by mauser (zawadzinski)

Allow overriding ip & serverdate time in Tracking API if proper super user token_auth given.

comment:12 Changed 3 years ago by mauser (zawadzinski)

@vipsoft a patch resolving the issue attached

comment:13 Changed 3 years ago by vipsoft (robocoder)

  • Resolution set to fixed
  • Status changed from new to closed

Thanks, maciej. (Don't you still have commit privileges?)

In r3945, fixes #1553. Accidentally checked in with piwik.js changes for #2072.

comment:14 Changed 3 years ago by vipsoft (robocoder)

  • Milestone changed from 1.x - Piwik 1.x to 1.2 Piwik 1.2
Note: See TracTickets for help on using tickets.