You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds a renderer recipe for capturing marketing attribution on form submissions only when the visitor has consented.
docs/renderer/consent-aware-attribution.md: an explicit allowlist of query parameters, the two ways to get values into a submission (merge at submit time, or Hidden fields filled through renderer.userData), and keeping the consent-denied path on the host page.
docs/renderer/renderer.md: links the recipe.
The recipe validates keys against the allowlist itself. It doesn't rely on the userData setter, which skips unknown keys with a console warning and never throws.
Thanks for writing this up. It reads well and keeps every decision on the host side, which was the point of #485. Also, thanks for the correction on the userData setter: I had it wrong in #485 when I said it throws. Filtering with present() is the better design anyway.
Two small things in Option B, neither blocking:
Consent that arrives after load. Option B reads attribution once, right after render(). With a typical consent banner the visitor accepts after the page has loaded, so hasAttributionConsent() is still false at that point and the hidden fields stay empty even though consent was given before submit. Option A doesn't have this problem because it reads at submit time. One fix is to fill the fields in onSubmit (or when consent changes) instead of after render(), or to add one sentence saying the snippet has to run again once consent is granted.
"Plain HTML form POST with no JavaScript handling". The fields are still filled by JavaScript in this recipe, so this phrase may confuse readers. Something like "if your backend reads a single flat form POST" would say the same thing without implying no JS.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a renderer recipe for capturing marketing attribution on form submissions only when the visitor has consented.
docs/renderer/consent-aware-attribution.md: an explicit allowlist of query parameters, the two ways to get values into a submission (merge at submit time, or Hidden fields filled throughrenderer.userData), and keeping the consent-denied path on the host page.docs/renderer/renderer.md: links the recipe.The recipe validates keys against the allowlist itself. It doesn't rely on the
userDatasetter, which skips unknown keys with a console warning and never throws.Refs #485
@Atroci, as promised in the issue, could you review this?