Guide
Blocking, in detail
What "blocked" means here
A blocked script has type="text/plain", so the browser treats it as data: it is never fetched, never
parsed and never run. When its category is allowed, we build a real <script> with the same
attributes and put it in the same place — which is when it runs, exactly once.
Blocked embeds keep their URL in data-cc-src instead of src, so nothing is requested — no
connection to YouTube, no cookie from a CDN.
Tag Manager
Load GTM itself under necessary only if your container respects Consent Mode; otherwise block GTM
too and let consent release it:
<script type="text/plain" data-cc="analytics/gtm" src="https://www.googletagmanager.com/gtm.js?id=GTM-XXXX"></script>
With Consent Mode on, the better arrangement is: GTM loads immediately, Consent Mode denies everything, and your decision sends the update. Tags inside the container then fire or not by themselves.
createCookieConsent({ consentMode: true, categories });
A strict Content Security Policy
createCookieConsent({ nonce: document.querySelector('meta[name="csp-nonce"]').content, categories });
The nonce is copied onto every script we create. We never inject a <style> element, so
style-src 'unsafe-inline' is not needed either.
Content that arrives later
After you inject markup that contains blocked tags — a modal, a page from your router — tell the consent instance to look again:
consent.apply();
Withdrawing
Switching a category off removes src from its embeds immediately and marks them
[data-cc-placeholder], which the stylesheet draws as an empty frame you can style:
[data-cc-placeholder]::after {
content: 'Allow marketing cookies to see this';
}
A script that has already run cannot be unrun. If that matters for your tags:
createCookieConsent({ reloadOnWithdraw: true, categories });
The page then reloads when consent is withdrawn from something that was already running — and after the reload, it is blocked.
Cookies that are already there
autoClear deletes them whenever the category is refused — including cookies set on an earlier visit,
by your server, or by a tag that ran before you installed this.
{ id: 'analytics', autoClear: [{ name: '_ga' }, { name: '_ga_.*', pattern: true }, { name: '_gid' }] }
Deletion is attempted on the exact host, the dotted host and the registrable domain, because that is where third-party scripts put them.
Checking your work
import { blockedKeys } from '@devix-labs/cookie-consent/core';
console.log(blockedKeys()); // every category and service named on this page
If a tag you expected is missing from that list, it is not blocked — check that it has
type="text/plain" as well as data-cc.