[E17-S01] Anonymous preference identity #123

Open
opened 2026-08-27 00:03:44 +00:00 by kpcto · 0 comments
Owner

Parent epic: [E17] Generic visitor preferences (#45)

Intent

Provide anonymous visitors a persistent preference identity that is created only when a preference is actually set, without building tracking records for ordinary page views.

Acceptance criteria

  • An identity is created lazily only when a visitor first sets a preference.
  • The identity token uses at least 256 bits of secure randomness.
  • Only a one-way lookup hash of the token is stored server-side.
  • Preference identities support an expiration time.
  • The preference cookie contains no personal or theme data.
  • A corrupt or unknown token is ignored safely without error.

Explicitly out of scope

  • The generic preference service API (that is E17-S02).
  • The owner theme policy settings (that is E17-S03).
  • The public theme selector UI and endpoint (that is Epic E18).

Test plan

  • Assert the identity is created only on the first preference write.
  • Assert the stored record holds a hash, not the raw token.
  • Assert the cookie value carries no theme or personal data.

Rollback note

  • Additive table and cookie; revert the commit. No destructive migration.

Owning stream

platform

Risk quadrant

agent-full

> Parent epic: [E17] Generic visitor preferences (#45) ## Intent Provide anonymous visitors a persistent preference identity that is created only when a preference is actually set, without building tracking records for ordinary page views. ## Acceptance criteria - An identity is created lazily only when a visitor first sets a preference. - The identity token uses at least 256 bits of secure randomness. - Only a one-way lookup hash of the token is stored server-side. - Preference identities support an expiration time. - The preference cookie contains no personal or theme data. - A corrupt or unknown token is ignored safely without error. ## Explicitly out of scope - The generic preference service API (that is E17-S02). - The owner theme policy settings (that is E17-S03). - The public theme selector UI and endpoint (that is Epic E18). ## Test plan - Assert the identity is created only on the first preference write. - Assert the stored record holds a hash, not the raw token. - Assert the cookie value carries no theme or personal data. ## Rollback note - Additive table and cookie; revert the commit. No destructive migration. ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 5 milestone 2026-08-27 00:03:44 +00:00
kpcto added the
kind
story
status
proposed
labels 2026-08-27 00:03:44 +00:00
Sign in to join this conversation.