We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

EE3.4.3: disable system cookies

How Do I?

pirco's avatar
pirco
218 posts
5 years ago
pirco's avatar pirco

my client is asking to remove all non-essential cookies. after searching for an hour, I can’t find a way to do that through the CP (setting “Website Session type” to “Session ID” still sets those cookies ‘exp_csrf_token’, ‘exp_last_activity’, ‘exp_last_visit’, ‘exp_tracker’). I’m not sure why some of those are “strictly necessary” (per EE documentation) but at least I’d like to avoid the other two not functionally required cookies.

please!!!

       
Rob Allen's avatar
Rob Allen
2,950 posts
5 years ago
Rob Allen's avatar Rob Allen

Hi Pirco

There’s been a conversation on Slack about removing cookies like these where possible.

exp_last_activity and exp_last_visit do get used in various places, though as to whether they are strictly necessary is open to interpretation, they don’t contain any personal info.

exp_tracker should only really be set when view tracking is enabled IMHO, this one might be a bug or just something that needs tweaking in the core. Again no personal info is stored in the cookie.

exp_crsf_token is security related so is very essential, without it you could expose your site to attack.

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.