summaryrefslogtreecommitdiff
path: root/help/CookieMonitorIncoming_p.md
blob: 805b62f2273ce8d468744ebc693f4fe7af9e2ece (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
---
page: htroot/CookieMonitorIncoming_p.html
help: help/CookieMonitorIncoming_p.md
title: Incoming Cookies Monitor
package: blacklist-security-access
access: admin
kind: admin-page
backend_java: source/net/yacy/htroot/CookieMonitorIncoming_p.java
---

# Incoming Cookies Monitor

## Purpose

Incoming Cookies Monitor shows cookies received by the peer.

Use it to inspect what browsers or clients send before diagnosing session or privacy behavior.

## What You Can Do Here

- Incoming Cookies Monitor shows cookies received by the peer.
- Test a concrete URL, request, user, or pattern before applying broad policy.
- Keep rules narrow enough that they block the intended problem without hiding useful content.

## Page Architecture

Security and blacklist pages turn names, patterns, credentials, or request properties into allow/block decisions. The architecture is rule-oriented: define the rule, test the rule, then apply it to crawling, search, or access.

| Control | Meaning | Values or examples |
| --- | --- | --- |
| `enableCookieMonitoring` | Enables the named feature. | `Enable Cookie Monitoring` |
| `disableCookieMonitoring` | Disables the named feature. | `Disable Cookie Monitoring` |

## Correct Use

Test with a concrete example. A blacklist, regular expression, rate limit, cookie rule, or access rule is only understandable when checked against a real URL or request. Prefer narrow patterns and document the reason for broad rules.

## Access And Safety

Administrator access is required. YaCy protects `_p` pages as administration pages.

Protected related endpoint(s): `/CookieMonitorIncoming_p.html`.

## Automation And API

Page backend: `source/net/yacy/htroot/CookieMonitorIncoming_p.java`.

| Endpoint | Method | Access | Backend |
| --- | --- | --- | --- |
| `/CookieMonitorIncoming_p.html` | `POST` | admin | `source/net/yacy/htroot/CookieMonitorIncoming_p.java` |

### Parameter Guide

The table explains values that an agent or script must set deliberately. Parameters not relevant to a task should be omitted or left at the page default.

| Parameter | Meaning and valid values | Care |
| --- | --- | --- |
| `enableCookieMonitoring` | Enables the named feature. | Changes stored data, configuration, or a running job. Use the authenticated action flow where required and verify the result. |
| `disableCookieMonitoring` | Disables the named feature. | Changes stored data, configuration, or a running job. Use the authenticated action flow where required and verify the result. |

Example request shape:

```http
POST /CookieMonitorIncoming_p.html
Content-Type: application/x-www-form-urlencoded

enableCookieMonitoring=...&disableCookieMonitoring=...
```

## What To Expect

Expect a rule list, match test, access record, cookie view, or confirmation. The real proof is behavioral: the same URL, request, or user should now be accepted, blocked, limited, or displayed as intended.

## Related Pages

- Related security work is usually reached through blacklist administration, blacklist testing, cookie monitors, robots data, or access-rate settings.