v0.4.5-beta
umputun/ralphexv0.4.5-betaFeb 15, 2026by southwellmedia
AI Summary
Adds a comprehensive Cookie Consent Manager integrated with Google Consent Mode v2 and improves security configurations by simplifying headers and removing Astro CSP.
Key Highlights
- Cookie Consent Manager with Google Consent Mode v2 integration
- Security header simplification and CSRF protection
- Fixes for mobile menu backdrop blur and lint errors
Breaking Changes
- Removed Astro CSP (auto-hashes style blocks, breaking inline styles)
New Features
- Accept All / Decline All / Customize consent banner
- Settings panel via Dialog component with per-category toggles
- Configurable via consent.config.ts
- PUBLIC_CONSENT_ENABLED environment variable
- Reopener button after consent is saved
Full Release Notes
## What's New ### Cookie Consent Manager with Google Consent Mode v2 - Full consent banner with Accept All / Decline All / Customize options - Settings panel via Dialog component with per-category toggles - Google Consent Mode v2 integration (analytics, marketing, preferences) - Supports both `consent_mode_v2` and `strict` blocking modes - Configurable via `consent.config.ts` — categories, UI text, delay - Reopener button after consent is saved - `PUBLIC_CONSENT_ENABLED` env var to toggle on/off ### Security - Removed Astro CSP (auto-hashes `<style>` blocks, breaking inline styles — revisit when stable) - Kept `checkOrigin: true` for CSRF protection - Simplified security headers via `vercel.json` (clickjacking, MIME sniffing, referrer, permissions) - Dropped deprecated `X-XSS-Protection` header ### Fixes - Fixed mobile menu backdrop blur not applying (scoped style → global) - Fixed lint errors in Analytics and ConsentBanner - Fixed dynamic consent mapping and race condition bugs