Page content:
...
Cookie name | Duration | Description | Purpose |
---|---|---|---|
Google analytics | |||
_ _utma | 2 years from set/update | Used to distinguish users and sessions. The cookie is created when the javascript library executes and no existing _ _utma cookies exists. The cookie is updated every time data is sent to Google Analytics. | Tracks how many times (if any) you have visited the Trainee Information System (TIS) website. |
_ _utmt | 10 minutes | Used to throttle request rate. | |
_ _utmb | 30 minutes after your visit, or after 30 minutes of inactivity | Used to determine new sessions/visits. The cookie is created when the javascript library executes and no existing _ _utmb cookies exists. The cookie is updated every time data is sent to Google Analytics. | Tracks how long you have spent on the website. |
_ _utmc | End of browser session | Not used in ga.js. Set for interoperability with urchin.js. Historically, this cookie operated in conjunction with the _ _utmb cookie to determine whether the user was in a new session/visit. | |
_ _utmd | 6 months after it was last set | Gives us information on how the site was reached (e.g. directly or a link, organic search or paid search) | |
_ _utmz | 6 months after it was last set | Stores the traffic source or campaign that explains how the user reached your site. The cookie is created when the javascript library executes and is updated every time data is sent to Google Analytics. | Identifies where you've come from e.g. from a search engine or from another website |
_ _utmv | 2 years from set/update | Used to store visitor-level custom variable data. This cookie is created when a developer uses the_setCustomVar method with a visitor level custom variable. This cookie was also used for the deprecated _setVar method. The cookie is updated every time data is sent to Google Analytics. | |
Content experiments - cookie usage | |||
_ _utmx | 18 months | used to determine a user's inclusion in an experiement | |
_ _utmxx | 18 months | Used to determine the expiry of experiements a user has been included in | |
Optimize 360 - cookie usage | |||
_gaexp | Depends on the length of the experiment but typically 90 days. | Used to determine a user's inclusion in an experiment and the expiry of experiments a user has been included in. | |
Keycloak and application cookies <<Requires dev input>> | |||
AUTH_SESSION_ID | session | Used for sticky connections to an individual node in the Keycloak cluster | https://github.com/keycloak/keycloak-documentation/blob/master/server_installation/topics/clustering/sticky-sessions.adoc |
KEYCLOAK_IDENTITY | session | JWT representing the user identity. | |
KEYCLOAK_SESSION | 12hr | keycloak's session token | |
KC_RESTART | session | JWT containing the redirect information to determin where a user should be returned to after logging in. | |
mod_auth_openidc | |||
mod_auth_openidc_state_ | session | representation of the state of the current login | The "state" cookie is created when the user is redirected away to the OpenID Connect Provider for authentication. It is a cookie with unique name (prefixed with a constant mod_auth_openidc_state_ ) that is tied to the state parameter that is sent in the authentication request. It is deleted when the user returns to the Apache server with an authentication response (indicating either success or failure) |
mod_auth_openidc_session | session | mod_auth_openidc's session token | The "session" cookie is created after the user returns from the OpenID Connect provider with a successful authentication response (note that the state cookie is deleted at the same time) |
Unknown | |||
dashBoardState | session | ||
defaultLocale | 1 month | User's current locale | |
session | session | unique session identifier | |
TIS Apps | |||
user | session | Cached user representation |
Scenarios:
Process Name | PN1 - Trainees Accept/Decline Privacy Notice when logging in for the first time. | Comments | ||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description | Users should be able to Accept/Decline Privacy Policy and Cookie Policy when logging in for the first time either on a mobile or desktop. | Mobile design consideration to be discussed with Steve. | ||||||||
Actors | Trainee | |||||||||
Pre-Conditions | User is not logged in | |||||||||
Post-Conditions | System presents Privacy Notice & Cookie Policy with options to and accept/decline | |||||||||
Process Steps |
| |||||||||
Alternative Process | N/A | |||||||||
Rules |
| |||||||||
JIRA Reference |
| |||||||||
Audit Log | Who accepted/declined the Privacy Notice and when Present audit log to all admins with view permissions |
Process Name | PN2 - Non-trainees Accept/Decline Privacy Notice and Cookie Policy when logging in for the first time. | Comments | ||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description | Users should be able to Accept/Decline Privacy Policy and Cookie Policy when logging in for the first time | |||||||||
Actors | Trainers, Educational Supervisors, Clinical Supervisors, TPD's | |||||||||
Pre-Conditions | User is not logged in | |||||||||
Post-Conditions | System presents Privacy Notice & Cookie Policy with options to and accept/decline | |||||||||
Process Steps |
| |||||||||
Alternative Process | N/A | |||||||||
Rules |
| |||||||||
JIRA Reference |
| |||||||||
Audit Log | Who accepted/declined the Privacy Notice and when Present audit log to all admins with view permissions |
Process Name | PN3 - Users should be able to access and read the Privacy and Cookie Policy via a hyperlink all the times | Comments | ||||||||
---|---|---|---|---|---|---|---|---|---|---|
Description | Users should be able to access and read the Privacy & Cookie Policy all the times | Note: This could be via a hyperlink on the header/footer of TIS site visible all the times. This link should not provide the options to accept/decline but just the content. | ||||||||
Actors | All users | |||||||||
Pre-Conditions | User is logged in or not logged in | |||||||||
Post-Conditions | Privacy and Cookie Policy can be can be accessed and read | |||||||||
Process Steps |
| |||||||||
Alternative Process | N/A | |||||||||
Rules |
| |||||||||
JIRA Reference |
| |||||||||
Audit Log | N/A |