Context
The job-search plan wants to know whether an application link was opened (/review?ref=<code>). Analytics
scripts add a third-party origin to the CSP, add JavaScript to every page, and collect visitor data.
Decision
The site loads no analytics scripts and sets no cookies. ref parameters are accepted and ignored by the
application. The nginx and API access logs record client addresses only in truncated form (IPv4 /24, IPv6 /48);
logs are rotated by size (5 × 10 MiB per container). Whether an application link was opened can be answered
from those logs on the server. Nothing leaves the server.
Consequences
- Since ADR-0011, requests pass through Cloudflare's CDN, which processes full client addresses under its own policy. The site itself still adds no scripts or cookies, and its own logs stay truncated.
- The CSP stays
'self'-only. - No page-level metrics. If they are ever needed, a cookieless, self-hostable counter is the candidate, with this ADR superseded.