Info about Vanilla Cookies
Comments
-
That's a "session" cookie (sid = session ID). The value maps to a row in Vanilla's
Sessiontable. This table is used to temporarily store information for a user. More often than not, this cookie is created as part of an SSO sign-in (although it can also make an appearance when users initiate the "forgot my password" workflow). Depending on the SSO method, Vanilla might need to "remember" some initial values to complete sign-in, after the user is redirected back to the site from the authentication provider. @patrick_kelly might be able to give greater detail for specific instances, as necessary.0 -
Fox still pushing back asking:
Fox still has one question:
>would you categorize these cookies as functional, targeting or essential?
For each of:
%-tk
- Cookie Type: sessions/ tracking
- Cookie Name %-tk
- Third or First party cookie? First Party
- Description: This token is anonymous and is used for CSRF protection.
- How to opt-out - they cannot be opted out of.
%-Vv
- Cookie Type: sessions/tracking
- Cookie Name: %-Vv
- Third or First party cookie? First Party
- Description: This token is anonymous and is used to track visits.
- How to opt-out - they cannot be opted out of
%-vA
- Cookie Type: analytics tracking
- Cookie Name %-vA
- Third or First party cookie? First Party
- Description: This token is used for Analytics tracking and is anonymous for EU users.
- How to opt-out - they cannot be opted out of, though you could turn off advanced analytics - note that EU users are automatically opted out.
__vnf
- Cookie Type: Troll management tracking
- Cookie Name__vnf
- Third or First party cookie? First Party
- Description: is the Troll Management cookie. It is not anonymous and does persist after logout. It's not used by anything except Troll Management. It is only initially assigned when users log in, not users who remain as guests. You can turn off the ‘troll’ add-on if you do not want this.
- How to opt-out - they cannot be opted out of (with the exception of disabling the add-on altogether)
0 -
Would you categorize these cookies as functional, targeting or essential?
To my knowledge, Vanilla doesn't issue any targeting/advertising cookies on customer communities.
- The "tk" cookie is essential. You won't be able to use most input forms without it.
- If we had to pick from those three buckets, specifically, I'd put "visit", "analytics" and "troll" into "functional". Without them, the site will still work from the users perspective, but it will adversely affect things like analytics and hinder the ability to track "trolls" on a site.
- If we can use the "performance" cookie bucket, that's where I'd put "visit" and "analytics".
1 -
Amazing, thank you Ryan!!! The fox predator folks thank you!
0 -
I summarized this for opentext: https://docs.google.com/document/d/1itEAQP_32jbh_lPesjmoSnOPYD3V1TPhl1xibX6ZFRw/edit?usp=sharing
1 -
@shaunamcclemens This would make for a good knowledge base article I think!
2 -
can someone clarify some follow up questions on our cookies :)
%-tk and %-Vv
- Are these persistent or sessions cookies?
- Are these essential or can users opt-out?
%-vA
- How is country of origin detected?
- Is this all one cookie? How can each piece of info have a different lifespan/persistence?
- Do you know what the lifespan of the data is for this cookie? If relevant.
- If it is anonymous for EU users, why are they opted out?
__vnf
- Is not derived from an personally identifiable information, but is it linked to other user info in any way?
vf-%-sid
- Is this essential or can users opt-out?
__cfduid and __cfruid –
- Is Cloudflare optional?
- Are they both essential? I see that __cfduid is, but I’m not sure about the second one
- Are they persistent? If so, for how long?
- Are they anonymous?
0 -
%-vA
- How is country of origin detected?
- Do you know what the lifespan of the data is for this cookie? If relevant.
__cfduid and cfruid -
- Are they persistent? If so, for how long?
- Are they anonymous?
@Todd @Ryan @Linc I found the answers to the other questions but these are still outstanding if you could take a look :) Thanks!
0 -
Well this is a new one!
From EA: As for the crazyegg.com cfuid one, do you know if Cloudflare requires it?
It's been my understanding that the cfuid is Cloudflare, and EA is curious where crazyegg fits in..
I imagine it's still required, but I'm not sure about this CrazyEgg business?
0 -
I'm not aware of us using CrazyEgg.com for anything. This is the first I've heard of it.
0 -
The Cloudflare cookie questions above from @SheenaP would be better answered by @D̸̨͝ą̸͂a̵͍̔z̴̙͋K̶̤̀u̷̢̇ than the folks tagged in that comment.
Is this essential or can users opt-out?
In general, we only set essential cookies and none can be opted out of.
How is country of origin detected?
I believe this is an Ops question also. I do not know how they are detecting that.
0 -
%-vA
How is country of origin detected?
Do you know what the lifespan of the data is for this cookie? If relevant.
I don't know that cookie is set by the analytics plugin
__cfduid and cfruid -
Are they persistent? If so, for how long?
Are they anonymous?
For good information about __cfduid:
https://support.cloudflare.com/hc/en-us/articles/360024915491-Privacy-and-the-cfduid-Cookie and https://support.cloudflare.com/hc/en-us/articles/200170156
This should answer both your questions for '__cfduid'. We have an enterprise account with Cloudflare.
For '__cfruid' I can only speculate since there are not documentation about it but from what I see they are set for a year and are only used to rate limit requests.
1 -
I think the CrazyEgg is something EA instituted as I cannot find it on any other Vanilla sites....
0 -
How is country of origin detected?
CloudFlare provides some geolocation hints (What does CloudFlare IP Geolocation do?). Vanilla's analytics addon takes its cue from CloudFlare.
0 -
Just an FYI. Marketing hired an agency which is using crazyegg on vanillaforums.com for tracking heatmaps and usage of our marketing sites (blog, landing pages ect).
It should not be impacting any of our forums.
0 -
I think that person A set it up on EA and person B did not know, and EA has not yet pushed back on that notion.
0 -
It's for certain not on any of our hosted forums
0 -
MFP is going through the cookie consent stuff these days and asked me this as a side note:
>Follow up question related to zero-tracker load functionality - do you know if the Vanilla implemented tags/trackers are managed via a tag management system - if so, what provider? I ask because TrustArc has different implementation docs per Tag Management provider.
Does this ring any bells?
0
