Jump to content

PrivacyWire - Cookie Management & async external asset loading


joshua

Recommended Posts

@joshua thx again.

Works great for iframes.
Is there also a solution to have it for external content which loads through scripts and divs. For example GoogleMaps. Right now i can do this:

// this puts content into #myMap
<script type="text/plain" data-type="text/javascript" data-category="external_media" data-src="gmaps.js"></script>

<div id='myMap'></div>

But unlike the your-iframe solution i cant have a ask-consent-button. It would be nice to have links like this integrated:

<a href="#" class="privacywire-allow-category" data-category="external_media" data-ask-consent="0">Allow Cookies for external media</a>


 

Link to comment
Share on other sites

That's right - you cann add a button (or link, whatever you prefer) with this css class and the data-consent-category attribute. PrivacyWire will handle it 😉

I definetely have to update the documentation with all the added features - will do that in the next weeks.

  • Like 2
Link to comment
Share on other sites

Hey @joshua!

I'm not sure if this is a real bug, but on one site I have a script like this:

<script id='taeggie-feed-widget-script-xxx' type="text/plain" data-type="text/javascript" data-category="marketing" data-ask-consent="1">
  jQuery.getScript(...);
</script>

This works and the consent info/request box is displayed. If I click the "accept" button from this info box it goes away and the script gets executed, so all is good in that case — but if I instead click the "accept all" button from the (separate) cookie management banner, the info and accept button next to the script are not removed.

Note that the script works as expected regardless of which accept method I use, so the only issue here seems to be that the info box / accept button are not removed. If I refresh the page, they are gone.

Is that a bug, feature, or user error? 🙂

  • Like 1
Link to comment
Share on other sites

Awesome — thanks Joshua!

Just a heads-up: I've opened a new PR for you to check out at https://github.com/blaueQuelle/privacywire/pull/10. This is quite opinionated, so let me know if you don't feel it's a great match with the module. Basically what I've added is support for the textformatter module to replace embedded media/video iframes with PrivacyWire enabled ones.

It's mainly a compatibility layer for TextformatterVideoEmbed 🙂

  • Like 4
Link to comment
Share on other sites

Hi Joshua,

just an idea. If there were a counter for all closes of all finished user decisions and a separate one only for the "accept all" decisions, it would give me a perfect idea of the accept ratio of the specific site. Either generally (probably enough), or even per month in a table (to monitor changes in behaviour). In the module, or in logfiles or a CSV file with a row limit? Basically, sort of mini-statistics.

I have guesswork right now regarding Analytics' / Matomo's result changes and of how many users (in percent) those analytics results represent?

  • Like 2
Link to comment
Share on other sites

Hi @ceberlin,

sounds like an good idea to me. To allow this kind of "tracking" we would need to send this decission via JS to an endpoint which connects to the ProcessWire API.

I will think about an way to implement this feature. I'm also open for a PR, if you already have an idea how to realize this feature.

Link to comment
Share on other sites

I tried to disable or hide a "Remember me" checkbox. My HTML is

<div class="field has-text-right">
    <label class="checkbox">
        <input type="checkbox" name="rememberme" value="<?=(int) input()->cookie->rememberme?>">
        <?=__('Remember me')?>
    </label>
</div>

The code I'd prefer would be (notice the two "disabled" attributes on the label and the input)

<div class="field has-text-right">
    <label class="checkbox" disabled>
        <input type="checkbox" name="rememberme" value="<?=(int) input()->cookie->rememberme?>" disabled>
        <?=__('Remember me')?>
    </label>
</div>

Although I could live with only hiding it, which is what I've tried by adding

data-category="functional" data-ask-consent="0" data-ask-consent-rendered="1"

to the div, the label or the checkbox. And it hides them all right. The issue is that PrivacyWire does not care about innerHTML of my poor div, or about its class. I changed o.innerText=e.innerText with o.innerHTML=e.innerHTML directly into js/PrivacyWireUnstyled.js and I got my checkbox back, but without its initial class. I think it is the code at line 231 in src/js/PrivacyWire.js.

I know almost no JavaScript, so start throwing tomatoes - in the priw_updateAllowedElement there is no way to let the old element live instead of copy into a new one > insert the new one in the DOM > delete the old one?

Also, it feels to me that flipping between two attributes or two CSS classes should be all PrivacyWire needs to do in regard to the elements that need consent.

LATER: hmm, maybe not in regard to scripts. Leaving for the coffee machine...

 

hmmm.jpg.d15604314fa2490e9b29acac524ac0bc.jpg

 

  • Like 1
  • Thanks 1
Link to comment
Share on other sites

Hi @The G,

thanks for noticing this behavior! During the development of PrivacyWire I never thought of showing or hiding divs or "regular" elements - only thought of scripts, videos, media ... So, good catch!

I refactored that part of the priw_updateAllowedElement function to fix this bug.

Cloning is required for everything, where media, scripts or other external stuff gets loaded...
Waaaait a minute... While I was writing these lines of nonesense, I realized that this idea is wrong! 🥳 You're right - keeping the elements alive and just update the attributes works for scripts, images, iframes and of course divs and other elements, too. I refactored again and tested the new version with all kind of elements and media...

Only script tags need to be a new added element, as they will not run otherwise: https://html.spec.whatwg.org/multipage/scripting.html#script-processing-model

0.4.2 fixed it!

Edited by joshua
Added another bug within the old bugfix. It's fixed now :D
  • Like 3
  • Thanks 1
Link to comment
Share on other sites

On 11/25/2020 at 5:59 PM, joshua said:

@teppo Thanks alot for your PR with the TextformatterVideoEmbed integration! I tested and merged your PR today.

I like the idea of adding more and more integrations with other modules like TextformatterVideoEmbed.

@teppo & @joshua does this mean, that iframes generated via TextformatterVideoEmbed will use PrivvacyWite data-attributes and are hidden untill given consent?

 

Link to comment
Share on other sites

12 minutes ago, ngrmm said:

does this mean, that iframes generated via TextformatterVideoEmbed will use PrivvacyWite data-attributes and are hidden untill given consent?

If enabled in the TextformatterPrivacyWire settings, yes.

grafik.png.64904c7279fe590b671b1e8cc053cf74.png

But it's disabled by default.

  • Like 3
Link to comment
Share on other sites

47 minutes ago, joshua said:

If enabled in the TextformatterPrivacyWire settings, yes.

But it's disabled by default.

Ok. Then i'm doing something wrong.
I installed PrivacyWire and TextformatterVideoEmbed and added them both to my textarea-field as textformatters.
After that i choosed ExternalMedia to as you suggest above.
Now when i add a YouTube-Link inside my textarea and external-media-cookies are off, i still can see the Iframe.

I also installed TextformatterVideoEmbedOptions and activated YouTube: Enable privacy-enhanced mode.

All Modules are updated to newest version. 

Link to comment
Share on other sites

13 minutes ago, ngrmm said:

I installed PrivacyWire and TextformatterVideoEmbed and added them both to my textarea-field as textformatters.
After that i choosed ExternalMedia to as you suggest above.
Now when i add a YouTube-Link inside my textarea and external-media-cookies are off, i still can see the Iframe.

Just checking: TextformatterVideoEmbed is listed before TextformatterPrivacyWire? If it's the other way around, this won't work.

13 minutes ago, ngrmm said:

I also installed TextformatterVideoEmbedOptions and activated YouTube: Enable privacy-enhanced mode.

This could potentially affect the situation. I would make sure if it makes difference, i.e. try disabling it and see if that changes anything.

So far this has worked for me, but let us know if the issue persists 🙂

Edit: if TextformatterVideoEmbedOptions runs before TextformatterPrivacyWire, this will definitely break things due to this line: https://github.com/blaueQuelle/privacywire/blob/master/TextformatterPrivacyWire.module#L51. Seems like an easy fix, though. Admittedly the order of the modules is a bit fragile, but part of it is really due to the way textformatters work and there's not much that can be done about that.

Edited by teppo
  • Like 2
Link to comment
Share on other sites

TextformatterPrivacyWire.module works fine here as long as:
1) the iframe contains www.youtube.com/embed/ and not www.youtube-nocookie.com/embed/ and
2) as long as its the second textformatter (or at least the textformatter after VideoEmbed).

Just played around with it here in my testing setup.

  • Like 2
Link to comment
Share on other sites

Thank you all!

I had the formatters not in the right order!
So for all noobs like me: 

Textarea Text Formatters:
1. Video embed for YouTube/Vimeo
2. PrivacyWire Textformatter

and i guess after updating to 0.4.3 then:
1. Video embed for YouTube/Vimeo
2. Apply options for embedded YouTube and Vimeo videos
3. PrivacyWire Textformatter

Link to comment
Share on other sites

Well... while this works (1):

screenshot-20201201163234.thumb.png.e4dd9af8b3bc380aa5a12fdb87892825.png

This doesn't (2):

screenshot-20201201163315.thumb.png.10bf47160908c66aa4c539c5dc245d96.png

I use a slightly modified version of Ryan's Video embed for YouTube/Vimeo module which already saves the "no cookie" domain to the database.
Users would paste the URL as usual, the module fetches the oEmbed data but in my case the domain will be replaced.

Around line 104 in Ryan's module I changed that part:

$embedCode = str_replace('youtube.com', 'youtube-nocookie.com', $data['html']);

 

  • Confused 1
Link to comment
Share on other sites

@joshua thanks for the module.

I unchecked the module config checkbox "CSS: Add basic CSS Styling" and added via <script> the PrivacyWire.js (which, as of module implementation, seems to include CSS itself), but the PrivacyWireUnstyled.js still loads in network (i.e. a HTTP request is made to get it).

Is there a way to include "manually" all the JS files (including PrivacyWireUnstyled.js)?

That is, to make possible something like this:

<script src="/site/modules/PrivacyWire/js/PrivacyWire.js"></script>
<script src="/site/modules/PrivacyWire/js/PrivacyWireUnstyled.js"></script>

so it would be the developer choose to minify and merge files, and to manage for less HTTP requests.

 

Maybe a config option? 

Link to comment
Share on other sites

You have the "Render Banner and Header Content Manually" option in the module settings. After checking it you can insert the module generated code wherever you'd like. The script tags are generated by the folowing snippet:

$modules->get('PrivacyWire')->renderHeadContent()

Disclaimer: didn't tested my suggestion, this is just what I saw in the module's code.

Why would you want to include both PrivacyWire.js and PrivacyWireUnstyled.js? AFAIK they only differ in including or not the module's CSS for the frontend. Including PrivacyWireUnstyled.js would only waste resources if PrivacyWire.js is included.

  • Like 1
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Similar Content

    • By MarkE
      This fieldtype and inputfield bundle was built for storing measurement values within a field, rendering them in a variety of formats and converting them to other units or otherwise modifying them via the API.
      The API consists of a number of predefined functions, some of which include...
      render() for rendering the measurement object, valueAs() for converting the value to another unit value, convertTo() for converting the whole measurement object to different units, and add() and subtract() for creating a new measurement object from the sum or difference between two other objects. In the admin the inputfield includes a checkbox (which can be optionally disabled) for converting values on page save. For an example if a value was typed in as centimeters, the unit was changed to metres, and the page saved with this checkbox selected, said value would be automatically converted so that e.g. 170 cm becomes 1.7 m.
      A simple length field using Fieldtype Measurement and Inputfield Measurement.
      Combination units (e.g. feet and inches) are also supported.
      Please note that this module is 'proof of concept' at the moment - there are limited units available and quite a lot of code tidying to do. More units will be added shortly.
      See the GitHub at https://github.com/MetaTunes/FieldtypeMeasurement for full details and updates.
    • By tcnet
      File Manager for ProcessWire is a module to manager files and folders from the CMS backend. It supports creating, deleting, renaming, packing, unpacking, uploading, downloading and editing of files and folders. The integrated code editor ACE supports highlighting of all common programming languages.
      https://github.com/techcnet/ProcessFileManager

      Warning
      This module is probably the most powerful module. You might destroy your processwire installation if you don't exactly know what you doing. Be careful and use it at your own risk!
      ACE code editor
      This module uses ACE code editor available from: https://github.com/ajaxorg/ace

      Dragscroll
      This module uses the JavaScript dragscroll available from: http://github.com/asvd/dragscroll. Dragscroll adds the ability to drag the table horizontally with the mouse pointer.
      PHP File Manager
      This module uses a modified version of PHP File Manager available from: https://github.com/alexantr/filemanager
       
    • By tcnet
      This module implements the website live chat service from tawk.to. Actually the module doesn't have to do much. It just need to inserted a few lines of JavaScript just before the closing body tag </body> on each side. However, the module offers additional options to display the widget only on certain pages.
      Create an account
      Visit https://www.tawk.to and create an account. It's free! At some point you will reach a page where you can copy the required JavaScript-code.

      Open the module settings and paste the JavaScript-code into the field as shown below. Click "Submit" and that's all.

      Open the module settings
      The settings for this module are located int the menu Modules=>Configure=>LiveChatTawkTo.

       
    • By tcnet
      Session Viewer is a module for ProcessWire to list session files and display session data. This module is helpful to display the session data of a specific session or to kick out a logged in user by simply delete his session file. After installation the module is available in the Setup menu.

      The following conditions must be met for the module to work properly:
      Session files
      Session data must be stored in session files, which is the default way in ProcessWire. Sessions stored in the database are not supported by this module. The path to the directory where the session files are stored must be declared in the ProcessWire configuration which is by default: site/assets/sessions.
      Serialize handler
      In order to transform session data easier back to a PHP array, the session data is stored serialized. PHP offers a way to declare a custom serialize handler. This module supports only the default serialize handlers: php, php_binary and php_serialize. WDDX was dropped in PHP 7.4.0 and is therefore not supported by this module as well as any other custom serialize handler. Which serialize handler is actually used you can find out in the module configuration which is available under Modules=>Configure=>SessionViewer.

      Session data
      The session data can be displayed in two different ways. PHP's default output for arrays print_r() or by default for this module nice_r() offered on github: https://github.com/uuf6429/nice_r. There is a setting in the module configuration if someone prefers print_r(). Apart from the better handling and overview of the folded session data the output of nice_r() looks indeed nicer.

      Links
      ProcessWire module directory
      github.com
    • By Robin S
      Repeater Easy Sort
      Adds a compact "easy-sort" mode to Repeater and Repeater Matrix, making those fields easier to sort when there are a large number of items.
      The module also enhances Repeater Matrix by allowing a colour to be set for each matrix type. This colour is used in the item headers and in the "add new" links, to help visually distinguish different matrix types in the inputfield.
      Screencasts
      A Repeater field

      A Repeater Matrix field with custom header colours

      Easy-sort mode
      Each Repeater/Matrix item gets an double-arrow icon in the item header. Click this icon to enter easy-sort mode.
      While in easy-sort mode:
      The items will reduce in width so that more items can be shown on the screen at once. The minimum width is configurable in the field settings. Any items that were in an open state are collapsed, but when you exit easy-sort mode the previously open items will be reopened. You can drag an item left/right/up/down to sort it within the items. The item that you clicked the icon for is shown with a black background. This makes it easier to find the item you want to move in easy-sort mode. You can click an item header to open the item. An "Exit easy-sort mode" button appears at the bottom of the inputfield. Configuration
      In the field settings for Repeater and Repeater Matrix fields you can define a minimum width in pixels for items in easy-sort mode. While in easy-sort mode the items will be sized to neatly fill the available width on any screen size but will never be narrower than the width you set here.
      In the field settings for Repeater Matrix you can define a custom header colour for each matrix type using an HTML "color" type input. The default colour for this type of input is black, so when black is selected in the input it means that no custom colour will be applied to the header.
      Exclusions
      The easy-sort mode is only possible on Repeater/Matrix fields that do not use the "item depth" option.
       
      https://github.com/Toutouwai/RepeaterEasySort
      https://processwire.com/modules/repeater-easy-sort/
×
×
  • Create New...