Esatto.CookieScan.Core
1.1.0
dotnet add package Esatto.CookieScan.Core --version 1.1.0
NuGet\Install-Package Esatto.CookieScan.Core -Version 1.1.0
<PackageReference Include="Esatto.CookieScan.Core" Version="1.1.0" />
<PackageVersion Include="Esatto.CookieScan.Core" Version="1.1.0" />
<PackageReference Include="Esatto.CookieScan.Core" />
paket add Esatto.CookieScan.Core --version 1.1.0
#r "nuget: Esatto.CookieScan.Core, 1.1.0"
#:package Esatto.CookieScan.Core@1.1.0
#addin nuget:?package=Esatto.CookieScan.Core&version=1.1.0
#tool nuget:?package=Esatto.CookieScan.Core&version=1.1.0
Esatto.CookieScan.Core
The rules behind the Esatto cookie scanner, with no dependencies at all.
- Known-cookie catalogue with wildcard patterns and most-specific-wins matching
- Consent-category inference from which passes a cookie appeared in
- The violation rule: set outside the consent it needed
- Append-only merge planning against what a policy page already declares
- Localised duration formatting (
sv,en) from a machine-readable day count - Scan-to-scan diffing: appeared, disappeared, recategorised
Why it exists as its own package
The scanner is a browser automation tool; the endpoint it writes through is an Umbraco web application. Both have to agree exactly on what counts as a violation, what category an unrecognised cookie gets and how a duration reads in Swedish — a site that declared a cookie differently from the way the tool proposed it would be the one bug this whole design exists to prevent.
So the shared rules live here, and having no PackageReference whatsoever is what enforces it:
the Umbraco package can depend on the rules without dragging Playwright into a web application, and
the rules can be unit tested without a browser or a published content graph.
Install
dotnet add package Esatto.CookieScan.Core
You want this package directly only if you are building your own front end or your own write-back.
To run a scan, install Esatto.CookieScan.Cli.
The catalogue
CookieCatalogue is loaded from JSON rather than declared in code, because its purpose text
becomes public legal wording on a policy page and must be changeable without a rebuild. One entry
looks like this:
{
"pattern": "_ga_*",
"provider": { "sv": "Google Analytics", "en": "Google Analytics" },
"category": "statistics",
"tracker": true,
"durationDays": 730,
"purpose": { "sv": "Mäter användningen av webbplatsen.", "en": "Measures use of the site." }
}
pattern—*is the only wildcard. The most specific match wins: fewest characters absorbed by wildcards, then the longest literal prefix. A name nothing matches returnsnullrather than a guess, which is what routes it into the needs-review path instead of a confident wrong declaration.expected— this site's own stack sets it, so its absence from a scan is itself a finding. Third-party entries leave it off: an absent Google cookie is normal.consentCookie— marks the banner's own consent cookie, the one entry whose name is per-site configuration.WithConsentCookieNamedrewrites it for a site that renamed it.durationDays— a number rather than pre-written text, soDurationFormattercan render it in either language.0is a session cookie; omitted means no documented lifetime, so use what the browser reported.
The shipped catalogue deliberately has no catch-all entry. With one, nothing could ever reach needs-review, and every unknown cookie would be declared with the catch-all's wording.
License
MIT.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- No dependencies.
NuGet packages (2)
Showing the top 2 NuGet packages that depend on Esatto.CookieScan.Core:
| Package | Downloads |
|---|---|
|
Esatto.Umbraco.Backoffice.CookieScan
The site-side half of the Esatto cookie scanner. Adds one management-API endpoint that appends a scan's findings to the cookie policy page as a draft - append-only, never publishing, never rewriting an editor's legal wording - plus the API user and client credentials that authenticate the post. Companion to Esatto.Umbraco.Backoffice.CookieBanner, whose cookieDefinition element type and cookiePolicy page it writes into. Run the scan itself with the Esatto.CookieScan.Cli tool. Wiring is one AddCookieScan() call and one SeedCookieScanApiUserAsync() on start. |
|
|
Esatto.CookieScan.Engine
The cookie consent audit engine behind the esatto-cookiescan tool. Crawls a site with a real headless browser, replays it once per consent decision a visitor can make, and reports every cookie and storage entry set outside the consent it needed. Reference it to build your own front end; install Esatto.CookieScan.Cli if you just want to run it. Pairs with the Esatto.Umbraco.Backoffice.CookieScan endpoint to append findings to an Umbraco cookie policy page as a draft. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.1.0 | 145 | 9/1/2026 |