@@ -82,18 +82,14 @@ import { AUTO_LAUNCH_NONE } from './settings'
8282import { lookupInstallUpdateOverride , recordIpcInvocation } from './lib/e2eOverrides'
8383import * as mainTelemetry from './lib/telemetry'
8484import {
85- clearPendingDownloadToken ,
86- markDownloadTokenAttributed ,
87- readPendingDownloadToken
88- } from './lib/downloadAttribution'
89- import {
90- clearPendingAlias ,
85+ clearLegacyIdentityRetryMarker ,
9186 consumeFirstLaunch ,
9287 getDeviceId ,
9388 getIdClass ,
9489 initDeviceId ,
9590 markIdentityMigrationCompleted
9691} from './lib/deviceId'
92+ import { getInitialAnonymousDistinctId } from './lib/websiteAnonymousIdentity'
9793import { initExperiments } from './lib/experiments'
9894import { initCloudCapacity } from './lib/cloudCapacity'
9995import { initUserTier } from './lib/userTier'
@@ -1414,21 +1410,21 @@ if (app.isPackaged && !app.requestSingleInstanceLock()) {
14141410 mainTelemetry . setConsentState ( initialConsent )
14151411 mainTelemetry . installAppHooks ( )
14161412
1417- // Initialize the deterministic device identity. Replaces the legacy
1418- // random-UUID device-id.txt with SHA-256(machine_id + salt) so the id
1419- // survives a clean reinstall and can be matched against the same hash
1420- // computed by other Comfy products on the same machine. The legacy id,
1421- // if any, is persisted in pending-identity-alias.txt by initDeviceId
1422- // so a denied / undecided consent state at first boot does not lose
1423- // the migration — it ships on the next consent-grant transition.
1413+ // Initialize installation metadata, then bind a separate persisted random
1414+ // PostHog anonymous id. installation_id is never used as an identity.
14241415 const { legacyId } = await initDeviceId ( )
1416+ // Desktop no longer performs legacy PostHog aliases. Remove any retry
1417+ // marker left by an older build, including when its migration guard exists.
1418+ clearLegacyIdentityRetryMarker ( )
14251419 const installationId = getDeviceId ( )
1426-
1427- // Bind the anonymous distinct id before any capture runs. Does NOT
1428- // `$identify` the installation_id (that would block the login stitch —
1429- // see identity model in lib/telemetry.ts); the props below ship as a
1430- // capture-`$set`.
1431- mainTelemetry . identify ( installationId , {
1420+ // A fresh Windows install can inherit the exact anonymous PostHog
1421+ // $device_id W carried in the Router's Content-Disposition filename. The
1422+ // installer stores only its filename-safe payload; this resolves and
1423+ // durably persists W before any capture. Existing Desktop state wins, and
1424+ // missing/invalid carriers fall back to a persisted/generated random D.
1425+ const anonymousDistinctId = getInitialAnonymousDistinctId ( )
1426+
1427+ mainTelemetry . bindAnonymousId ( anonymousDistinctId , installationId , {
14321428 app_version : APP_VERSION ,
14331429 platform : process . platform ,
14341430 arch : process . arch ,
@@ -1442,42 +1438,18 @@ if (app.isPackaged && !app.requestSingleInstanceLock()) {
14421438 mainTelemetry . registerPersonProperties ( settings . getTrackedSettingsTelemetryProperties ( ) )
14431439
14441440 const isFirstLaunch = consumeFirstLaunch ( )
1445- const pendingDownloadToken = readPendingDownloadToken ( )
1446- if ( pendingDownloadToken ) {
1447- mainTelemetry . deferDownloadTokenAlias ( {
1448- downloadToken : pendingDownloadToken . token ,
1449- installationId,
1450- source : pendingDownloadToken . source ,
1451- attachToFirstLaunch : isFirstLaunch ,
1452- onAliased : ( ) => {
1453- clearPendingDownloadToken ( )
1454- markDownloadTokenAttributed ( )
1455- }
1456- } )
1457- }
1458-
14591441 if ( legacyId ) {
1460- // Queue the alias instead of awaiting it on the boot critical path.
1461- // - Fires as soon as consent is granted (synchronously if already so,
1462- // on the next setConsentState('granted') transition otherwise).
1463- // - Persisted pending-alias file (in deviceId.ts) is the source of
1464- // truth across boots — clear it AND mark migration complete only
1465- // inside the onAliased callback so a denied user does not skip the
1466- // alias permanently.
1467- mainTelemetry . deferMigrationAlias ( {
1468- legacyId,
1469- installationId,
1470- idClass : getIdClass ( ) ,
1471- onAliased : ( ) => {
1472- clearPendingAlias ( )
1473- markIdentityMigrationCompleted ( )
1474- }
1475- } )
1442+ // Historical random installation ids are reconciled directly in
1443+ // PostHog, not by Desktop alias writes. Complete only the local migration.
1444+ markIdentityMigrationCompleted ( )
14761445 }
14771446
14781447 // Boot the experiments cache. Synchronously loads the on-disk flag
14791448 // values for `getFlag()`, then kicks off a background refresh whose
14801449 // result lands on disk for the NEXT boot. Does not block boot.
1450+ // Flag evaluation uses the installation-stable property key only. It never
1451+ // captures or identifies this value, so W/D rotation cannot change an
1452+ // experiment arm or create a PostHog person.
14811453 void initExperiments ( {
14821454 distinctId : installationId ,
14831455 personProperties : {
0 commit comments