v0.4.5-beta
southwellmedia/velocityv0.4.5-betaFeb 15, 2026by southwellmedia
AI Summary
This update focuses on privacy and security by introducing a comprehensive Cookie Consent Manager with Google Consent Mode v2. It also removes Astro's auto-hashing CSP feature and simplifies security headers.
Key Highlights
- Introduced full Cookie Consent Manager with Google Consent Mode v2
- Removed Astro CSP auto-hashing which breaks inline styles
- Simplified security headers by dropping X-XSS-Protection
- Fixed mobile menu backdrop blur and consent mapping bugs
Breaking Changes
- Removed Astro CSP auto-hashing feature, which breaks inline styles in `<style>` blocks
New Features
- Cookie Consent Manager with Accept/Decline/Customize options
- Settings panel via Dialog component
- Google Consent Mode v2 integration (analytics, marketing, preferences)
- Configuration via `consent.config.ts`
Full Release Notes
## What's New ### Cookie Consent Manager with Google Consent Mode v2 - Full consent banner with Accept All / Decline All / Customize options - Settings panel via Dialog component with per-category toggles - Google Consent Mode v2 integration (analytics, marketing, preferences) - Supports both `consent_mode_v2` and `strict` blocking modes - Configurable via `consent.config.ts` — categories, UI text, delay - Reopener button after consent is saved - `PUBLIC_CONSENT_ENABLED` env var to toggle on/off ### Security - Removed Astro CSP (auto-hashes `<style>` blocks, breaking inline styles — revisit when stable) - Kept `checkOrigin: true` for CSRF protection - Simplified security headers via `vercel.json` (clickjacking, MIME sniffing, referrer, permissions) - Dropped deprecated `X-XSS-Protection` header ### Fixes - Fixed mobile menu backdrop blur not applying (scoped style → global) - Fixed lint errors in Analytics and ConsentBanner - Fixed dynamic consent mapping and race condition bugs