Page 1 of 2

Cookie Notice

Posted: Sun Jan 08, 2017 9:38 am
by david63
I am surprised that after so many protestations by various Team members over the years that phpBB has included in the gold release of phpBB 3.2 a Cookie Notice - albeit not working at the moment. I am guessing that the reasoning behind this is because of VigLink.

Having spent several years working on my Cookie Policy extension I believe that I have a fairly reasonable understanding of the Cookie Law not only as it relates to the UK but to other EU countries.

Unfortunately the way that this has been implemented in phpBB is, I believe, flawed.

There are three basic rules for complying with the Cookie Law
The rules on cookies are in regulation 6. The basic rule is that you must:
  • tell people the cookies are there;
  • explain what the cookies are doing and why; and
  • get the person’s consent to store a cookie on their device.
(source - ICO : https://ico.org.uk/for-organisations/gu ... hnologies/)

Whilst points 1 and 3 are being handled point 2, in my opinion, is not as all there is is a link on the acceptance banner to an remote page (http://cookies.insites.com/) which is only giving some basic information about cookies in general, not specific to any particular site. Also there is no permanent link to the "Cookie policy" once the banner has been dismissed and if the remote site is not accessible then the user will have no information at all.

Furthermore this implementation does not, as far as my understanding goes, comply with the requirements of some other EU countries.

Re: Cookie Notice

Posted: Sun Jan 08, 2017 10:24 am
by canonknipser
David, maybe the european cookie rules will change in the near future, there seems to be a paper by the commission.

Re: Cookie Notice

Posted: Sun Jan 08, 2017 10:42 am
by david63
canonknipser wrote:
Sun Jan 08, 2017 10:24 am
David, maybe the european cookie rules will change in the near future, there seems to be a paper by the commission.
I am aware of that and from what I have read the biggest change will probably be that there will be an implicit requirement to accept the policy rather than an assumed one. Also there may be some more types of cookie that could be excluded.

Re: Cookie Notice

Posted: Sun Jan 08, 2017 10:45 am
by Marshalrusty
david63 wrote:
Sun Jan 08, 2017 9:38 am
I am surprised that after so many protestations by various Team members over the years that phpBB has included in the gold release of phpBB 3.2 a Cookie Notice - albeit not working at the moment. I am guessing that the reasoning behind this is because of VigLink.
Yeah, there's unfortunately a bug there. We'll release a temporary fix and properly patch it in the next maintenance release.

As for the reasoning, it's simply that a few people kept asking, and we listen to requests. VigLink couldn't possibly care less whether you display a cookie notice on your site.

I'll look into the rest of your points, thanks!

Cookie Notice - script fix

Posted: Mon Jan 09, 2017 3:08 am
by 3Di
For those are interested I wrote a script that fixes this bug
https://tracker.phpbb.com/browse/PHPBB3-14967 in 3.2.0 Gold.
To be used in the meantime the next 3.2.1 will be released with the Official patch (merged).

[3.2.0 Gold][FIX] -> Cookie notice

The future phpBB 3.2.1 updater will not interfere with this because it already checks if this config exists.
This tools checks if this config exists as well else it does nothing but tells you that everything's all right. Only Founders or admins can use it, requires min. phpBB 3.2.0 Gold (the logic will check the phpBB version too). Self file deletion included.

Have fun.

Edit: fixed URL

Re: Cookie Notice

Posted: Tue Jan 10, 2017 1:33 pm
by stevemaury
phpBB itself does not set any cookies that are subject to the rule. Individual users and/or extensions may do so. So, without knowing what those future cookies may do, there is no way for phpBB to tell the user what the cookie does.

Re: Cookie Notice

Posted: Wed Jan 11, 2017 11:55 am
by david63
stevemaury wrote:
Tue Jan 10, 2017 1:33 pm
without knowing what those future cookies may do, there is no way for phpBB to tell the user what the cookie does.
Then surely that is enough of a reason to have a customisable/translatable page within phpBB.

Re: Cookie Notice

Posted: Wed Jan 11, 2017 12:29 pm
by Ger
stevemaury wrote:
Tue Jan 10, 2017 1:33 pm
phpBB itself does not set any cookies that are subject to the rule. Individual users and/or extensions may do so.
Somewhat true, but with Viglink shipped as part of the package, intending for most board admins to enable it, I would say that the Viglink extension should at least contain a cookie notice.

Re: Cookie Notice - script fix

Posted: Sat Apr 29, 2017 11:07 am
by richardgrue
3Di wrote:
Mon Jan 09, 2017 3:08 am
For those are interested I wrote a script that fixes this bug
https://tracker.phpbb.com/browse/PHPBB3-14967 in 3.2.0 Gold.
To be used in the meantime the next 3.2.1 will be released with the Official patch (merged).

[3.2.0 Gold][FIX] -> Cookie notice

The future phpBB 3.2.1 updater will not interfere with this because it already checks if this config exists.
This tools checks if this config exists as well else it does nothing but tells you that everything's all right. Only Founders or admins can use it, requires min. phpBB 3.2.0 Gold (the logic will check the phpBB version too). Self file deletion included.

Have fun.
Works great. Thanks!

Re: Cookie Notice - script fix

Posted: Wed Jul 04, 2018 5:46 pm
by Affin
3Di wrote:
Mon Jan 09, 2017 3:08 am
For those are interested I wrote a script that fixes this bug
https://tracker.phpbb.com/browse/PHPBB3-14967 in 3.2.0 Gold.
To be used in the meantime the next 3.2.1 will be released with the Official patch (merged).

[3.2.0 Gold][FIX] -> Cookie notice

The future phpBB 3.2.1 updater will not interfere with this because it already checks if this config exists.
This tools checks if this config exists as well else it does nothing but tells you that everything's all right. Only Founders or admins can use it, requires min. phpBB 3.2.0 Gold (the logic will check the phpBB version too). Self file deletion included.

Have fun.

Edit: fixed URL
What should you do then download it and upload where?

Re: Cookie Notice - script fix

Posted: Wed Jul 04, 2018 5:58 pm
by 3Di
Affin wrote:
Wed Jul 04, 2018 5:46 pm
3Di wrote:
Mon Jan 09, 2017 3:08 am
For those are interested I wrote a script that fixes this bug
https://tracker.phpbb.com/browse/PHPBB3-14967 in 3.2.0 Gold.
To be used in the meantime the next 3.2.1 will be released with the Official patch (merged).

[3.2.0 Gold][FIX] -> Cookie notice

The future phpBB 3.2.1 updater will not interfere with this because it already checks if this config exists.
This tools checks if this config exists as well else it does nothing but tells you that everything's all right. Only Founders or admins can use it, requires min. phpBB 3.2.0 Gold (the logic will check the phpBB version too). Self file deletion included.

Have fun.

Edit: fixed URL
What should you do then download it and upload where?
Download: https://gist.github.com/3D-I/11f85b66b2 ... 6ba8e3.zip

usage: upload it to your forum's root (ie.: http://www.example.com/my_forum/fix_cookie_notice_320.php ) and run it from your browser.

Re: Cookie Notice - script fix

Posted: Wed Jul 04, 2018 6:28 pm
by Affin
3Di wrote:
Wed Jul 04, 2018 5:58 pm
Affin wrote:
Wed Jul 04, 2018 5:46 pm
3Di wrote:
Mon Jan 09, 2017 3:08 am
For those are interested I wrote a script that fixes this bug
https://tracker.phpbb.com/browse/PHPBB3-14967 in 3.2.0 Gold.
To be used in the meantime the next 3.2.1 will be released with the Official patch (merged).

[3.2.0 Gold][FIX] -> Cookie notice

The future phpBB 3.2.1 updater will not interfere with this because it already checks if this config exists.
This tools checks if this config exists as well else it does nothing but tells you that everything's all right. Only Founders or admins can use it, requires min. phpBB 3.2.0 Gold (the logic will check the phpBB version too). Self file deletion included.

Have fun.

Edit: fixed URL
What should you do then download it and upload where?
Download: https://gist.github.com/3D-I/11f85b66b2 ... 6ba8e3.zip

usage: upload it to your forum's root (ie.: http://www.example.com/my_forum/fix_cookie_notice_320.php ) and run it from your browser.
Should the file be hot zip? If it does, then there was no difference

Re: Cookie Notice

Posted: Wed Jul 04, 2018 6:32 pm
by 3Di
You need to extract the file from that zip and use that extracted file fix_cookie_notice_320.php.

Re: Cookie Notice

Posted: Wed Jul 04, 2018 6:52 pm
by Affin
3Di wrote:
Wed Jul 04, 2018 6:32 pm
You need to extract the file from that zip and use that extracted file fix_cookie_notice_320.php.

:-D But should not it be added to any folder? Should not be just on root?

Re: Cookie Notice

Posted: Wed Jul 04, 2018 7:19 pm
by 3Di
you can trash the folder and keep the file. The file have to be in the root. ;)
  • upload it to your forum's root (ie.: http://www.example.com/my_forum/fix_cookie_notice_320.php ) and run it from your browser.