gpt4 book ai didi

Firebase/Firestore - 是否有需要在隐私政策中引用的特定 cookie?

转载 作者:行者123 更新时间:2023-12-04 17:38:49 25 4
gpt4 key购买 nike

我有一个使用 Firestore 存储数据和 Firebase Storage 存储图像的网络应用程序。创建帐户后(通过 iOS 应用程序进行),用户可以登录 Web 应用程序并添加新项目和新图像。但是,在阅读 cookie 政策后,似乎我需要通知用户该站点是否使用任何特定的 cookie - Cookie consent banner

我没有主动将任何 cookie 添加到 Web 应用程序中。它纯粹是使用 AngularFire 和 Firebase 来允许用户进行身份验证和交互。

上面的 cookie 站点链接声明如下:

To be compliant, the cookie notice should be one component of a cookie management 
solution for your website, that takes care of the following tasks:

1. To provide the website users with specific and accurate information on all
cookies and other tracking technologies in use on the website.

2. To give the users the possibility to opt in and opt out of the various
types of cookies, and to have access to their settings and make subsequent changes
to them if they change their mind.

3. To make sure that the user consent is requested prior to the setting of cookies
in the users' browsers.

4. To make sure that the website functions properly even though the user has chosen
to opt out of all but the strictly necessary cookies.

5. To keep a record of all given consents for documentation, and to make sure that
this documentation is securely stored.

6. Ask for renewed consent every 12 months upon the user's
first revisit to the site.

我需要向潜在用户明确概述 Firebase/Firestore 使用的任何特定 cookie 吗?

最佳答案

我可能真的迟到了,但这是我在遇到相同问题后发现的。无论如何,简短的回答是默认情况下您所拥有的就是下面的信息。

https://firebase.google.com/docs/auth/admin/manage-cookies

这是该页面的摘录

Firebase Auth provides server-side session cookie management for traditional websites that rely on session cookies. This solution has several advantages over client-side short-lived ID tokens, which may require a redirect mechanism each time to update the session cookie on expiration:

  • Improved security via JWT-based session tokens that can only be generated using authorized service accounts.
  • Stateless session cookies that come with all the benefit of using JWTs for authentication. The session cookie has the same claims (including custom claims) as the ID token, making the same permissions checks enforceable on the session cookies.
  • Ability to create session cookies with custom expiration times ranging from 5 minutes to 2 weeks.
  • Flexibility to enforce cookie policies based on application requirements: domain, path, secure, httpOnly, etc.
  • Ability to revoke session cookies when token theft is suspected using the existing refresh token revocation API. Ability to detect session revocation on major account changes.


如果您在该页面上阅读了有关如何配置更多信息的其他信息。我希望有人可以对此做出更多回答。

关于Firebase/Firestore - 是否有需要在隐私政策中引用的特定 cookie?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/55493873/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com