Skip to content
Devix Open Source

Guide

Blocking, in detail

What "blocked" means here

A blocked script has type="text/plain", so the browser treats it as data: it is never fetched, never parsed and never run. When its category is allowed, we build a real <script> with the same attributes and put it in the same place — which is when it runs, exactly once.

Blocked embeds keep their URL in data-cc-src instead of src, so nothing is requested — no connection to YouTube, no cookie from a CDN.

Tag Manager

Load GTM itself under necessary only if your container respects Consent Mode; otherwise block GTM too and let consent release it:

<script type="text/plain" data-cc="analytics/gtm" src="https://www.googletagmanager.com/gtm.js?id=GTM-XXXX"></script>

With Consent Mode on, the better arrangement is: GTM loads immediately, Consent Mode denies everything, and your decision sends the update. Tags inside the container then fire or not by themselves.

createCookieConsent({ consentMode: true, categories });

A strict Content Security Policy

createCookieConsent({ nonce: document.querySelector('meta[name="csp-nonce"]').content, categories });

The nonce is copied onto every script we create. We never inject a <style> element, so style-src 'unsafe-inline' is not needed either.

Content that arrives later

After you inject markup that contains blocked tags — a modal, a page from your router — tell the consent instance to look again:

consent.apply();

Withdrawing

Switching a category off removes src from its embeds immediately and marks them [data-cc-placeholder], which the stylesheet draws as an empty frame you can style:

[data-cc-placeholder]::after {
  content: 'Allow marketing cookies to see this';
}

A script that has already run cannot be unrun. If that matters for your tags:

createCookieConsent({ reloadOnWithdraw: true, categories });

The page then reloads when consent is withdrawn from something that was already running — and after the reload, it is blocked.

Cookies that are already there

autoClear deletes them whenever the category is refused — including cookies set on an earlier visit, by your server, or by a tag that ran before you installed this.

{ id: 'analytics', autoClear: [{ name: '_ga' }, { name: '_ga_.*', pattern: true }, { name: '_gid' }] }

Deletion is attempted on the exact host, the dotted host and the registrable domain, because that is where third-party scripts put them.

Checking your work

import { blockedKeys } from '@devix-labs/cookie-consent/core';

console.log(blockedKeys());   // every category and service named on this page

If a tag you expected is missing from that list, it is not blocked — check that it has type="text/plain" as well as data-cc.

Updated 15 Sep 2026