---
title: "Data and network requests"
manual: "Coding Freaks Cookie Manager"
version: "main"
source: "DataAndRequests/Index.rst"
rendered: "2026-09-27T16:07:18+00:00"
---

# Data and network requests {#data-and-requests}

What the extension loads in the visitor's browser, what your TYPO3 server sends to the
CodingFreaks platform, and when. Every request to the platform goes to the address in
the setting `end_point` (see [Extension Settings](../Configuration/ExtensionSettings/Index.html#extension-settings)). In the tables below,
`{end_point}` stands for that address.

This page describes what the software does. Whether and how you have to mention it in
your privacy policy is for you to decide.

## Frontend: the visitor's browser {#frontend-the-visitor-s-browser}

The extension itself makes no request to CodingFreaks or any other third party from the
visitor's browser. Everything it adds is served by your own site:

-   `consent.js`, `iframemanager.js` and `default.css` from the
    extension's public resources.
-   The banner configuration, either inline in the page or as
    `typo3temp/assets/cookieconfig<language><hash>.js`. The field
    **In Line Execution** in the Frontend Settings decides which.
-   The branding notice is a plain link. It loads nothing (see [Branding](../Configuration/Branding/Index.html#branding)).

What loads after consent is what you configure: the scripts and iframes of your
services. One field can load something **before** consent: a service's
**iFrame Thumbnail function or url**. If you fill it, the browser loads that URL
(or runs that function) to show the preview of blocked content, and that can be a third
party host.

The consent cookie (`cookie_name`, default `cf_cookie`) is set by `consent.js`
in the browser.

### Thumbnail API {#data-thumbnails}

With `thumbnail_api_enabled` (default `true`) and no own thumbnail on the service,
blocked iframes get a preview image:

1.  The browser requests the image from your own site (page type `1723638651`).
1.  If `typo3temp/assets/cfthumbnails/` holds a copy younger than seven days,
    TYPO3 returns it. Nothing is sent.
1.  Otherwise your **server** sends `POST {end_point}getThumbnail` with the URL of the
    embedded content, the width and height, the host name of your site (`domain`), and
    `scan_api_key` and `scan_api_secret` if they are set. The visitor's browser does
    not talk to the platform.

Switch it off with `thumbnail_api_enabled = false`. The cache can be cleared in the
**Administration** tab (**Clear Thumbnail Cache**).

### Consent tracking {#data-consent-tracking}

Off by default (`tracking_enabled`). When on, the browser sends one request to your
own site (page type `1682010733`) after the visitor's first choice in the banner. TYPO3
stores it in the table `tx_cfcookiemanager_domain_model_tracking`:

-   from the browser: language (`navigator.language`), referrer,
    `navigator.webdriver`, consent type (`all`, `necessary` or `custom`)
-   added by the server: page ID, user agent header, time

The Dashboard widget reads this table. In 2.x nothing of it is sent to the platform.

## Backend: your TYPO3 server {#backend-your-typo3-server}

Only the actions below send requests. The requests come from the TYPO3 server, so the
server needs outgoing HTTPS access to `{end_point}`.

| When | Request | What is sent |
| --- | --- | --- |
| **Start Configuration**, **Install Presets** | `GET {end_point}frontends/{lang}`, `categories/{lang}`, `services/{lang}`, `cookie/{lang}`, for every site language | The language code in the URL. No key, no secret. |
| **Start Configuration**, API step, when you enter key and secret | `POST {end_point}v1/integration/ping` | `api_key`, `api_secret`, `platform` (`typo3`), `plugin_version`. On success the values are saved in the site settings. |
| **Start Configuration**, API step, when the site settings already hold key and secret | `POST {end_point}v1/integration/ping` | The same fields, with the stored key and secret, to the stored endpoint. Nothing is saved. |
| **Administration**, **Check for Dataset API-Updates** | The same four `GET` requests as the preset install | The language code in the URL. No key, no secret. |
| **Administration**, **Check API Integration** | `POST {end_point}v1/integration/ping`, then share-config (below) | As above, with the stored key and secret |
| **Autoconfiguration & Reports**, start a scan | `POST {end_point}scan` | The URL to scan, the page limit, the XPath of the banner's accept button (or the flag that disables clicking), `apiKey` if set. No secret. |
| Opening the **Cookie Settings** module while a scan is waiting or running | `GET {end_point}scan/{identifier}` | The scan identifier in the URL |
| Importing a scan result, and after **Install Presets** | share-config (below) | Only when key and secret are set |
| Saving or deleting a cookie service, cookie, category or frontend record | share-config (below) | Only when key and secret are set |

**share-config** is `POST {end_point}v1/integration/share-config` with `api_key`,
`api_secret` (also as header `x-api-key`) and your banner configuration: the banner
settings (cookie name, revision, lifetime, path, autorun, force consent, layout), and per
language the banner texts, categories, services (name, description, identifier, provider,
category) and cookies (name, regex flag, lifetime, domain, path, secure flag, description,
and the service name linked to its **DSGVO Link** as provider). It
contains no visitor data. The platform uses it to compare its scan results with what your
banner declares.

Nothing is sent by **Offline Configuration**: you download the preset archive in
your browser and upload it into TYPO3.

Links in the backend module open pages in your browser when you click them:
**Open report on the platform** goes to the scan report in your project on the
platform. The address is `end_point` without a trailing `api/` (an endpoint without
it is used as it is), followed by
`administration/manage/<Project ID>/cmp/scan-show/<scan identifier>`. It needs a login
on the platform and is only shown with key and secret set. Register and tutorial links
go to `coding-freaks.com`.

## What 2.x does not send {#what-2-x-does-not-send}

-   No consent records of your visitors. Consent tracking stays in your database.
-   No usage data or telemetry of the extension, whatever `allow_data_collection` says.
-   Nothing on a normal page view, except the thumbnail request described above.
