summaryrefslogtreecommitdiff
path: root/help/CookieMonitorIncoming_p.md
diff options
context:
space:
mode:
Diffstat (limited to 'help/CookieMonitorIncoming_p.md')
-rw-r--r--help/CookieMonitorIncoming_p.md76
1 files changed, 76 insertions, 0 deletions
diff --git a/help/CookieMonitorIncoming_p.md b/help/CookieMonitorIncoming_p.md
new file mode 100644
index 000000000..805b62f22
--- /dev/null
+++ b/help/CookieMonitorIncoming_p.md
@@ -0,0 +1,76 @@
+---
+page: htroot/CookieMonitorIncoming_p.html
+help: help/CookieMonitorIncoming_p.md
+title: Incoming Cookies Monitor
+package: blacklist-security-access
+access: admin
+kind: admin-page
+backend_java: source/net/yacy/htroot/CookieMonitorIncoming_p.java
+---
+
+# Incoming Cookies Monitor
+
+## Purpose
+
+Incoming Cookies Monitor shows cookies received by the peer.
+
+Use it to inspect what browsers or clients send before diagnosing session or privacy behavior.
+
+## What You Can Do Here
+
+- Incoming Cookies Monitor shows cookies received by the peer.
+- Test a concrete URL, request, user, or pattern before applying broad policy.
+- Keep rules narrow enough that they block the intended problem without hiding useful content.
+
+## Page Architecture
+
+Security and blacklist pages turn names, patterns, credentials, or request properties into allow/block decisions. The architecture is rule-oriented: define the rule, test the rule, then apply it to crawling, search, or access.
+
+| Control | Meaning | Values or examples |
+| --- | --- | --- |
+| `enableCookieMonitoring` | Enables the named feature. | `Enable Cookie Monitoring` |
+| `disableCookieMonitoring` | Disables the named feature. | `Disable Cookie Monitoring` |
+
+## Correct Use
+
+Test with a concrete example. A blacklist, regular expression, rate limit, cookie rule, or access rule is only understandable when checked against a real URL or request. Prefer narrow patterns and document the reason for broad rules.
+
+## Access And Safety
+
+Administrator access is required. YaCy protects `_p` pages as administration pages.
+
+Protected related endpoint(s): `/CookieMonitorIncoming_p.html`.
+
+## Automation And API
+
+Page backend: `source/net/yacy/htroot/CookieMonitorIncoming_p.java`.
+
+| Endpoint | Method | Access | Backend |
+| --- | --- | --- | --- |
+| `/CookieMonitorIncoming_p.html` | `POST` | admin | `source/net/yacy/htroot/CookieMonitorIncoming_p.java` |
+
+### Parameter Guide
+
+The table explains values that an agent or script must set deliberately. Parameters not relevant to a task should be omitted or left at the page default.
+
+| Parameter | Meaning and valid values | Care |
+| --- | --- | --- |
+| `enableCookieMonitoring` | Enables the named feature. | Changes stored data, configuration, or a running job. Use the authenticated action flow where required and verify the result. |
+| `disableCookieMonitoring` | Disables the named feature. | Changes stored data, configuration, or a running job. Use the authenticated action flow where required and verify the result. |
+
+Example request shape:
+
+```http
+POST /CookieMonitorIncoming_p.html
+Content-Type: application/x-www-form-urlencoded
+
+enableCookieMonitoring=...&disableCookieMonitoring=...
+```
+
+## What To Expect
+
+Expect a rule list, match test, access record, cookie view, or confirmation. The real proof is behavioral: the same URL, request, or user should now be accepted, blocked, limited, or displayed as intended.
+
+## Related Pages
+
+- Related security work is usually reached through blacklist administration, blacklist testing, cookie monitors, robots data, or access-rate settings.