Follow-up from #1188.
handle_admin_eids_lookup (crates/trusted-server-core/src/ec/admin.rs) previews partner-ID matches from the ts-eids and sharedId cookies only. After #1188, response-finalization ingestion differs in two ways the preview does not reflect:
- Identity-graph EID writes require TCF Purpose 1 + 4 (
allows_eid_persistence), so for a Purpose-4-denied request the preview lists matches that are never written.
POST /auction also ingests request-body EIDs, which the GET preview cannot see.
It also ignores add-only semantics from #1157 (a different stored UID is kept).
#1188 documents the preview as cookie-only and ungated. Options:
- Run the preview through
allows_eid_persistence (building consent from the request) and report a consent_gated flag.
- Keep it cookie-only and expose the consent decision as a separate field.
Raised in review of #1188.
Follow-up from #1188.
handle_admin_eids_lookup(crates/trusted-server-core/src/ec/admin.rs) previews partner-ID matches from thets-eidsandsharedIdcookies only. After #1188, response-finalization ingestion differs in two ways the preview does not reflect:allows_eid_persistence), so for a Purpose-4-denied request the preview lists matches that are never written.POST /auctionalso ingests request-body EIDs, which the GET preview cannot see.It also ignores add-only semantics from #1157 (a different stored UID is kept).
#1188 documents the preview as cookie-only and ungated. Options:
allows_eid_persistence(building consent from the request) and report aconsent_gatedflag.Raised in review of #1188.