4 ms·
No cookies are 'necessary' for site functionality, unless there is a login needed. No cookies are 'necessary' to just display information, pics and videos.
by 0df8dkdf 6y ago
No cookies are 'necessary' for site functionality, unless there is a login needed.
No cookies are 'necessary' to just display information, pics and videos.
- jchw 6y agoFrom GDPR.eu: > Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. Seems like you can in fact set first-party session tokens without consent. Does not seem like you need a specific reason to do so.
- g_p 6y agoOnly if it's needed for giving the user functionality they explicitly request (i.e. after adding something to their basket, they implicitly accept a session cookie that's solely used to hold their basket content). That wouldn't extend to using that cookie for analytics or retargeting though. https://ico.org.uk/for-organisations/guide-to-pecr/cookies-and-similar-technologies/ https://ico.org.uk/for-organisations/guide-to-pecr/cookies-a... So I'd argue it does need to be a specific reason, at least if you follow the ICO guidance (which is probably the best I've found for explaining what's required by the ePrivacy directive)
- jchw 6y agoStrictly necessary can also include security measures, of which session IDs tend to be a part of.
- merb 6y agobullshit. any site with a form needs a cookie, unless the site is stupid. any site that tries to use post requests might need some. heck even the confirmation or storing which cookies should be saved needs a fucking cookie.
- 0df8dkdf 6y agono you don't unless authentication is needed. How is post request and cookie even related? It is simple web dev 101.
- TimWolla 6y agoYou need to store some kind of state if you want to protect the form from CSRF attacks. You usually want to protect the form.
- 411111111111111 6y agoYou don't need a cookie for that though... Even a window variable would suffice
- deleted 6y ago[deleted]
- iamacyborg 6y agoI have a form on my site. My site has no cookies. I have no issues.
- Seb-C 6y agoIf you don't even have a CSRF you actually probably have an issue that you are not aware of.
- iamacyborg 6y agoIt's an email signup form so it's fine.