Skip to content

_fbc cookies written by Meta are not parsed: SDK regex rejects '-'/'_' and the newer 5-segment format #20

Description

@loevgaard

Problem

CookieBasedFbcContext (src/Context/Fbc/CookieBasedFbcContext.php:26) parses the _fbc cookie with Setono\MetaConversionsApi\ValueObject\Fbc::fromString() from the SDK, which requires

/^fb\.([012])\.(\d{13})\.([a-zA-Z0-9]+)$/

and the bundle silently returns null when it throws.

Two classes of legitimate cookies do not match:

  1. Click ids containing - or _. Real fbclid values are base64url and regularly contain both characters. QueryBasedFbcContext + StoreFbcSubscriber store fb.1.<ts>.IwAR1a-b_c in the cookie; on the next request fromString() throws, the exception is swallowed, and fbc is null. The cookie is written but never read back.
  2. Meta's current five-segment format. Meta's official parameter builder (facebook/capi-param-builder-php, installed transitively through facebook/php-business-sdk) writes _fbc as fb.<idx>.<ts>.<fbclid>.<appendix> where the appendix is a 2- or 8-character token (see php/capi-param-builder/src/ParamBuilder.php around lines 261-267 and model/Constants.php: APPENDIX_LENGTH_V1 = 2, APPENDIX_LENGTH_V2 = 8). The browser pixel has been moving to the same format. The SDK regex requires exactly four segments, so such a cookie yields fbc = null, and server-side events lose click attribution precisely when the browser pixel is active.

Please verify the second point against what fbevents.js writes in a current browser before changing anything; the parameter builder source is the reference used here.

Impact

Lost click attribution on server-side events. It is silent: no log, no exception, just a missing parameter and a lower Event Match Quality in Events Manager.

Suggested fix

The regex lives in setono/meta-conversions-api-php-sdk:

  • SDK: relax the click id charset to [A-Za-z0-9_-]+ and accept an optional trailing \.[A-Za-z0-9_-]{2,8} segment, preserving it in value() so an existing cookie is not rewritten in a different shape.
  • Bundle: bump the SDK constraint once released, add regression tests for both cookie shapes, and log at debug level when a cookie value cannot be parsed so the situation is at least visible.

Related: #19.

Tests

Unit tests for CookieBasedFbcContext: four-segment cookie, cookie with -/_, five-segment cookie, garbage cookie, no cookie, no request.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions