Hello,

Due to the GDPR for European citizen which will be applied may 25, we need the consent of the user before setting any google analytics cookies. So we can support eu_cookie_compliance to get that consent, this is basically what have been said on this issue: #2917905 but it is for Drupal 8, so I've created this issue for Drupal 7.

I've just added a checkbox in the settings of the module in order to add the support of eu_cookie_compliance. The patch is pretty simple, it's just a test that check that the eu_cookie_compliance consent cookie is there before executing the google analytics script.

Comments

phjou created an issue. See original summary.

phjou’s picture

hass’s picture

Status: Active » Needs work

There has nothing been decided in #2917905: Add JS-function / method to set ga-disable-....

This is not the api way. We may need to write a js plugin and ther is also a gs disable feature.

phjou’s picture

Issue summary: View changes
phjou’s picture

Sorry I chose the wrong word, not decided indeed. We need to move the initialization of the script tag from the PHP to a JS Plugin?
I've seen that the gs disable feature does not send data to google but does it also block cookies?

hass’s picture

I think it blocks running the code, so no cookie can be set as the code does not run. Not verified myself yet, but only this makes sense.

gmaximus’s picture

Thank you @phjou. Works for me!

gmaximus’s picture

Just noticed that this patch in #2 doesn't remove the cookie if consent is withdrawn. It is part of the new features in dev for the eu_cookie_compliance module. Any ideas?

gmaximus’s picture

I changed the last function in the patch to this

/**
 * Function to prevent google analytics tracking without the user consent
 * from eu_cookie_compliance module.
 */
function _googleanalytics_eu_cookie_compliance_script_alter($script) {
  $cookie_settings = eu_cookie_compliance_get_settings();
  $cookie_name = (!empty($cookie_settings['cookie_name'])) ? $cookie_settings['cookie_name'] : 'cookie-agreed';
  global $cookie_domain;
  // 2 is the accepted value in eu_cookie_compliance.
  $eu_script = "function delete_cookie(name) {
    document.cookie = name +'=; Domain=$cookie_domain; Path=/; Expires=Thu, 01 Jan 1970 00:00:01 GMT;';
}; if (document.cookie.indexOf('$cookie_name=2') > -1) {";
  $eu_script .= $script;
  $eu_script .= "} else {delete_cookie('_ga'); delete_cookie('_gat'); delete_cookie('_gid'); }";
  return $eu_script;
}

Now it will delete cookies when consent is withdrawn. Wasn't sure of how to create a patch and with GDPR I'm a little stretched for time.

gmaximus’s picture

I edited the original patch to include my changes

MaskOta’s picture

Status: Needs work » Needs review
StatusFileSize
new3.18 KB

The code from the patch seems to work. However i did have problems applaying the patch.

Here is a reroll. I also changed the module_enable function to module_exists beacause:
a) i dont think we should enable modules for users
b) module_exists is much faster on each run (noticed while debuging)

gmaximus’s picture

Thank you @MaskOta. Good spot. I didn't look up the module_enable function. I thought that is what it was doing.

gmaxwelled’s picture

Worked for me, thanks.

luksak’s picture

Does anyone have a working version for D8?

phjou’s picture

There is no working D8 patch for now, but the D8 issue is there: https://www.drupal.org/project/google_analytics/issues/2917905
There is also an issue in eu_cookie_compliance: https://www.drupal.org/project/eu_cookie_compliance/issues/2933614

rob c’s picture

I just uploaded a D7 patch to #2976470: cookie is set before accepting that uses ga-disable + i believe we can fix it there + this patch did not work for me.

klabautermann_’s picture

Tried to port the patch #11 to D8.
Works for me, but is not really tested yet. Also I had to create a get_settings function in eu_cookie_compliance module. I do not know if it is the recommended way. I did not get to manage the customizability with a checkbox in google_analytics module. With this patch, tracking cookies are only set when User accepts eu_cookie_compliance.

Status: Needs review » Needs work
klevyke’s picture

The patch #11 works for me. Thanks!
The only minus is that the first visit isn't tracked this way.
I tried to make a patch to solve this problem. This loads the analytics script when the user clicks on Agree button.

subhojit777’s picture

Status: Needs work » Needs review

Changing to Needs review as the tests have passed.

subhojit777’s picture

StatusFileSize
new4.6 KB
new1 KB

whitespaces removed

mpadilla’s picture

The patch #22 works for me. Thanks!

heddn’s picture

Status: Needs review » Needs work
  1. +++ b/googleanalytics.admin.inc
    @@ -319,6 +319,14 @@ function googleanalytics_admin_settings_form($form_state) {
    +      '#title' => t('Eu cookie compliance support'),
    +      '#description' => t('If enabled, the Google Analytics module will not track users as long as we have not their consent. This option is designed to work with the module @eu_cookie_compliance.', array('@eu_cookie_compliance' => 'https://www.drupal.org/project/eu_cookie_compliance')),
    

    The url should be a link.

    English suggestion:

    If enabled, the Google Analytics module will not track users as long as we do not have their consent.

  2. +++ b/googleanalytics.module
    @@ -117,6 +117,7 @@ function googleanalytics_page_alter(&$page) {
    +	$eu_cookie_compliance_support = variable_get('googleanalytics_eu_cookie_compliance', 0);
    
    @@ -143,6 +144,12 @@ function googleanalytics_page_alter(&$page) {
    +	if (module_exists('eu_cookie_compliance') && $eu_cookie_compliance_support) {
    +		if ($eu_compliance = variable_get('googleanalytics_eu_cookie_compliance', 0)) {
    +		  $link_settings['trackEuCompliance'] = $eu_compliance;
    +		  $url_custom = 'location.pathname + location.search + location.hash';
    +		}
    +	}
    

    Whitespace nits. Things should move back to the left.

phjou’s picture

Just did the patch with the corrections listed by @heddn in #24

phjou’s picture

StatusFileSize
new4.67 KB

I selected my old patch. Sorry, this one is the good one :)

phjou’s picture

Status: Needs work » Needs review
phjou’s picture

Something just came up my mind.
Should we rollback what have been done in #19 ? If we want to track the first visit, we have the Reload page after user clicks the "Agree" button. feature from Eu Cookie Compliance. We could keep less code. What do you think?

heddn’s picture

Status: Needs review » Needs work

If EU has it, then no need to add a feature for EU cookies to GA. Let's nix it. And don't forget an interdiff, I don't want to have to re-review the entire patch.

phjou’s picture

Ok so I've based the new patch on #11.

- I've drop all the code from #19 because Eu cookie compliance allow us to reload the page and track it and also #22 because it was some code styling on #19.
- I've kept the transformation into a link from #26

I've attached Interdiff files this time. Sorry.

phjou’s picture

Status: Needs work » Needs review
heddn’s picture

Status: Needs review » Needs work
+++ b/googleanalytics.admin.inc
@@ -319,6 +319,14 @@ function googleanalytics_admin_settings_form($form_state) {
+      '#description' => t('If enabled, the Google Analytics module will not track users as long as we have not their consent. This option is designed to work with the module <a href="@eu_cookie_compliance">Eu Cookie Compliance</a>.', array('@eu_cookie_compliance' => 'https://www.drupal.org/project/eu_cookie_compliance')),

So close. Looking a real good here. However, this would ready more clearly if we re-ordered the english and put in another verb:

If enabled, the Google Analytics module will not track users as long as we do not have their consent...

phjou’s picture

I changed the english :)

phjou’s picture

Status: Needs work » Needs review
heddn’s picture

Status: Needs review » Reviewed & tested by the community

Let's try RTBC on for size? I think this will work now.

anybody’s picture

Confirming RTBC. This is a great feature and step forward, thank you all! Hopefully this will be part of the next release.

anybody’s picture

cheope’s picture

Great! Patch in #33 works like a charm! Thank you very much! :-)

frankdesign’s picture

Patch at #33 works perfectly. Please commit.

Thanks

F

jcnventura’s picture

RTBC++

johncionci’s picture

Is there a patch for D8?

phjou’s picture

johncionci’s picture

@phjou Thanks!

hass’s picture

Version: 7.x-2.x-dev » 8.x-3.x-dev
Status: Reviewed & tested by the community » Needs work
hass’s picture

Status: Needs work » Closed (duplicate)
jcnventura’s picture

Version: 8.x-3.x-dev » 7.x-2.x-dev
Status: Closed (duplicate) » Reviewed & tested by the community

@hass: it's not a duplicate in the sense that this is for D7, and that other issue is covering the D8 issue. Normally both patches are developed in the same issue, but that trend was not followed here. Closing this issue without adding the D7 patch to #2917905: Add JS-function / method to set ga-disable-... is worse than having two open issues on the same problem.

jummonk’s picture

Patch #33 does not seem to work anymore with version 7.x-1.27 of eu_cookie_compliance.

romdouze’s picture

Hi all,
thank you very much for this great work !!

It's ok for me with:
D7 core v7.64
Eu-cookie-compliance v7.x-1.28
GA v7.x-2.6

Thank you again !

travis-bradbury’s picture

Status: Reviewed & tested by the community » Needs work

There seems to be a conflict between this and advanced aggregation because it wrapped the ga code in two layers of the delete_cookie and checktracking functions.

<script>function delete_cookie(name) {
  document.cookie = name + '=; Domain=.example.com; Path=/; Expires=Thu, 01 Jan 1970 00:00:01 GMT;';
};

function checktracking() {
  if ((document.cookie.indexOf('cookie-agreed=1') > -1) || (document.cookie.indexOf('cookie-agreed=2') > -1)) {
    function delete_cookie(name) {
      document.cookie = name + '=; Domain=.example.com; Path=/; Expires=Thu, 01 Jan 1970 00:00:01 GMT;';
    };

    function checktracking() {
      if ((document.cookie.indexOf('cookie-agreed=1') > -1) || (document.cookie.indexOf('cookie-agreed=2') > -1)) {
        (function (i, s, o, r) {
          i["GoogleAnalyticsObject"] = r;
          i[r] = i[r] || function () {
            (i[r].q = i[r].q || []).push(arguments)
          }, i[r].l = 1 * new Date()
        })(window, document, "script", "ga");
        ga("create", "UA-example-1", {"cookieDomain": "auto"});
        ga("set", "anonymizeIp", true);
        ga("set", "page", location.pathname + location.search + location.hash);
        ga("send", "pageview");
      }
      else {
        delete_cookie('_ga');
        delete_cookie('_gat');
        delete_cookie('_gid');
      }
    }

    checktracking();
  }
  else {
    delete_cookie('_ga');
    delete_cookie('_gat');
    delete_cookie('_gid');
  }
}

checktracking();</script>

Even if that isn't this issue's fault, this one needs work because it's only going to work until the moment something changes in eu_cookie_compliance. This module should provide a way for that module - or others - to decide to disable tracking, not do the checks itself.

You can also have eu_cookie_compliance set to opt-in by default and not disable any scripts/tracking and this patch will still disable google analytics.

anybody’s picture

Please try the patch in #3060312: Better GDPR compliance: Fix Do not track & EU Cookie Privacy integration which provides integration for EU Cookie Compliance in the UI combined with Do-Not-Track. I'd like to have your help with tests there and your feedback, if it fixed your problems. If yes, we can close this as duplicate perhaps.

Please note that you will need the patch from #2986131: JS loads too late to affect Google Analytics #7.

anybody’s picture

Status: Needs work » Closed (duplicate)

This is fixed for 7.x-2.x in #3060312: Better GDPR compliance: Fix Do not track & EU Cookie Privacy integration please help to review / test.