Skip to content

Establish a technical permission model and gate Edge Cookie creation on it #779

Description

@jwrosewell

User story

As a deployer, I want Edge Cookie creation gated by technical permissions that are established outside the core, so that the legal policy is mine to set and is not baked into Trusted Server.

Description

Replace the country-based allows_ec_creation check with a technical permission model that separates legal policy from the core. Each module declares the permissions its data use requires, named by the IAB Tech Lab Privacy Taxonomy's Data Uses and used only as technical identifiers. No policy framework is implemented in the core. The core runs a module only when every required permission is held. Whether a permission is held is established from the country the geo module returns (keyed by ISO 3166-1) and from request signals. When no country is known, or the country and region match no rule, the deployer's configured default country applies. The model is source-agnostic, so a held permission can equally come from an interaction with the user that establishes a preference, or from data provided by another source. The EC Set-Cookie operation always requires store-on-device (purpose 1). A module that stores nothing requires nothing, so a default deployment needs no policy interaction at all.

Done when

  • A technical permission model resolves held permissions, keyed by country or region. An unmatched request (no country, or no rule for the country and region) falls to the required top node of the policy's rules: tree, and a failed lookup floors instead, so no failure reaches a permissive default.
  • A module's required permissions are honored, and it runs only when all are held.
  • The built-in HMAC module declares necessary.operations.storage, and a module that stores nothing requires nothing.
  • consent::allows_ec_creation is removed, and its country-based gate tests are replaced by permission-model tests.
  • The permission vocabulary is the IAB Tech Lab Privacy Taxonomy's Data Uses, used only as identifiers, with the TCF purposes mapped onto them inside the TCF module and no policy framework in the core.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions