BareProxy Cookie Consent Plugin: A Consent Banner and Cookie Blocking at the Proxy
Status: planned, number 13 of 21 in BareProxy’s build order. The plugins are built easiest first, and this one is about two days of coding: a banner in HTML pages and cookies held back by category. It comes after the Markdown serving plugin. This post describes what it will do, and it will be updated as it is built.
Under the EU’s ePrivacy rules and the GDPR, a site needs consent before it sets cookies that aren’t strictly necessary: analytics, advertising, embedded third-party content. Most sites handle it with a consent platform loaded as a script, which adds weight to every page and only works as well as the site’s code that is supposed to wait for it.
A proxy sees every cookie a site sets, because each one passes through it in a Set-Cookie header. That makes it a natural place to enforce the visitor’s choice, rather than just ask for it.
What It Will Do
- Show a banner. On HTML pages, the plugin adds a small consent banner just before
</body>, with the site’s own wording from its config. The visitor’s choice is stored in one strictly necessary cookie. - Hold back cookies until there’s consent. Cookies the config lists as non-essential are removed from responses until the visitor accepts that category. A cookie set by the app before consent never reaches the browser at all.
- Respect Global Privacy Control. A browser that sends the
Sec-GPCsignal is treated as having declined, with no banner needed. - Keep a record. Each consent given or withdrawn is counted, for the site’s own records.
A config will look something like this:
plugin consent /etc/bareproxy/plugins/cookie-consent.wasm
config /etc/bareproxy/plugins/consent.json
body response
site example.com
use consent
route /* -> app
What It Can’t Do
A proxy sees cookies that cross it. Cookies that scripts on the page set for themselves, through JavaScript, never pass through a Set-Cookie header, and third-party scripts that load from other domains don’t pass through the proxy at all. The plugin can keep those scripts out of the page until consent, by rules in its config, but a site with many third-party tags will still want a review by someone who knows them. This post isn’t legal advice, and neither will the plugin be.
The whole program is on the plugins page.