v0.4.5-beta
flydelabs/flydev0.4.5-betaFeb 15, 2026by southwellmedia
AI Summary
This beta release introduces a Cookie Consent Manager with Google Consent Mode v2 and updates security configurations by removing Astro CSP and simplifying headers. It also fixes mobile menu rendering and consent logic race conditions.
Key Highlights
- New Cookie Consent Manager with Google Consent Mode v2
- Security: Removed Astro CSP and simplified security headers
- Fix mobile menu backdrop blur not applying
- Fix dynamic consent mapping and race condition bugs
Breaking Changes
- Removed Astro CSP which breaks inline styles
New Features
- Cookie Consent Manager with Google Consent Mode v2
- Full consent banner with Accept All / Decline All / Customize options
- Settings panel via Dialog component with per-category toggles
Full Release Notes
## What's New ### Cookie Consent Manager with Google Consent Mode v2 - Full consent banner with Accept All / Decline All / Customize options - Settings panel via Dialog component with per-category toggles - Google Consent Mode v2 integration (analytics, marketing, preferences) - Supports both `consent_mode_v2` and `strict` blocking modes - Configurable via `consent.config.ts` — categories, UI text, delay - Reopener button after consent is saved - `PUBLIC_CONSENT_ENABLED` env var to toggle on/off ### Security - Removed Astro CSP (auto-hashes `<style>` blocks, breaking inline styles — revisit when stable) - Kept `checkOrigin: true` for CSRF protection - Simplified security headers via `vercel.json` (clickjacking, MIME sniffing, referrer, permissions) - Dropped deprecated `X-XSS-Protection` header ### Fixes - Fixed mobile menu backdrop blur not applying (scoped style → global) - Fixed lint errors in Analytics and ConsentBanner - Fixed dynamic consent mapping and race condition bugs