IMO, the 'service requested by the user' is to deliver the website, and all that the 'website' entails.
One might also say that cookies are never strictly necessary. We can always just put tracking IDs in the URL. And when browsers get rid of URL bars, it'll be harder for people to copy/paste the URL (with session ID) so the 'security' aspect against that argument will fall on deaf ears ("I can't see the problem you're talking about, so it's not real").
Comments
IMO, the 'service requested by the user' is to deliver the website, and all that the 'website' entails.
One might also say that cookies are never strictly necessary. We can always just put tracking IDs in the URL. And when browsers get rid of URL bars, it'll be harder for people to copy/paste the URL (with session ID) so the 'security' aspect against that argument will fall on deaf ears ("I can't see the problem you're talking about, so it's not real").