The collection domain
The script and the collection endpoint are served at the COLLECT_URL address: by default,
the administration address (PUBLIC_URL). This is the one the Installation tab puts in the tag.
<script defer src="https://stats.example.com/a.js" data-site="s_arvordemo001"></script>Many publishers prefer to serve collection from a subdomain of their own site:
stats.maison-arvor.fr.
- Trust: the visitor, and their browser, see a request to the site they are visiting, not to a third party.
- Blockers: blocklists target the known domains of measurement tools; a subdomain of the
site is less known. It is not a way to get around a refusal:
optOut()and the Global Privacy Control signal are still respected. - The measurement cookie is set by the script on the page’s domain anyway: the collection domain does not change its scope.
-
With the site’s DNS provider, a CNAME record:
stats.maison-arvor.fr. CNAME stats.example.com. -
In front of the instance, the proxy must serve this name over HTTPS. With the bundled Caddy, add the name to the site block in
docker/Caddyfile(stats.example.com, stats.maison-arvor.fr { … }): Caddy obtains a certificate for each. Only/a.js,/p.jsand/collect*need to respond there. -
Set
COLLECT_URLto this address, if a single site uses it:Fenêtre de terminal COLLECT_URL=https://stats.maison-arvor.frWith several sites, each on its own subdomain, leave
COLLECT_URLon the shared address and simply change the address in each site’s tag: the collection endpoint responds the same way under all its names. -
Update the site’s security policy:
script-srcandconnect-srcto the subdomain.
What does not change
Section titled “What does not change”The collection endpoint still checks that the page belongs to the site’s declared domains
(Origin header), whatever name it is called under. A collection subdomain does not allow
another site to send data in its place.
eodia analytics is free software by Eodia.