Download the PHP package estouai/cookie-consent without Composer
On this page you can find all versions of the php package estouai/cookie-consent. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package cookie-consent
Cookie Consent
RGPD/GDPR-first cookie consent addon for Statamic 6.
It gives you a Shadow DOM cookie banner, per-site Control Panel settings, Google Consent Mode v2 defaults/updates, generic script and iframe gating for vendors like GTM, GA4, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, Hotjar, Clarity, and embeds, plus an append-only server-side consent log for proof of consent.
The public banner includes a small Powered by estou.ai attribution.
Features
- RGPD/GDPR-first default copy in Portuguese.
- Per-site Statamic Control Panel settings.
- Enable/disable toggle per site.
- Versioned consent: bump the version to force visitors to decide again.
- Google Consent Mode v2 support (
ad_storage,analytics_storage,ad_user_data,ad_personalization,security_storage). - Inline Consent Mode defaults for
<head>before GTM/gtag.js loads. - Generic
data-cookie-categoryscript and iframe gating for non-Google vendors. - Content gating tags for Antlers templates.
- Server-side JSONL consent log for RGPD Art. 7º(1) / LGPD Art. 8º proof.
- Global Privacy Control auto opt-out.
- Equal prominence accept/reject buttons.
- Shadow DOM styling with
::part()hooks. Powered by estou.aibranding.
Installation
If you install from a local path repository during development:
Then run:
Recommended template setup
Put defaults before any GTM/gtag.js snippet:
Put banner/button/scripts near the end of the page. Keep scripts outside
{{ nocache }} so they work with full-measure static caching:
Tags
{{ cookie_consent }}
Renders the banner web component.
Suppress it manually:
{{ cookie_consent:defaults }}
Renders inline Consent Mode defaults. Use in <head> before GTM/gtag.js.
Defaults grant only required groups and deny non-essential groups:
This is what GTM Consent Settings / built-in consent variables read before the first pageview.
{{ cookie_consent:scripts }}
Loads the compiled JavaScript bundle. It registers custom elements, applies stored consent, updates Consent Mode, activates gated scripts/iframes, resolves content gates, handles Global Privacy Control, and logs decisions server-side.
{{ cookie_consent:button }}
Renders a floating button that reopens preferences.
{{ cookie_consent:allowed }} / {{ cookie_consent:denied }}
Client-side content gating by group:
When the addon is disabled for the current site, allowed renders directly and
denied renders nothing.
{{ cookie_consent:groups }}
Render a privacy-policy cookie table:
Script and iframe gating
Add data-cookie-category to any vendor script or iframe. Use
data-cookie-src instead of src for remote assets.
GA4 / gtag.js
Meta Pixel
LinkedIn Insight Tag
Embeds
Control Panel
Go to Tools → Cookie Consent.
Permission: manage cookie consent settings.
The screen edits:
- enabled toggle
- consent version
- banner position
- theme mode
- copy
- cookie groups JSON
- Consent Mode mapping JSON
Multi-site installs get a site switcher. Each site stores independent settings under:
If no CP settings exist, the addon uses config/cookie-consent.php defaults.
Consent Mode v2 and GTM
{{ cookie_consent:defaults }} writes default denied/granted values before GTM
loads. {{ cookie_consent:scripts }} later sends gtag('consent', 'update', ...) after a visitor chooses.
Default mapping:
GTM tags should still use Consent Settings / Additional Consent Checks for the signals they require. The addon provides the signal state; GTM enforces it per tag.
2026 consent rules covered
- Global Privacy Control. If
navigator.globalPrivacyControl === trueand no stored decision exists yet, non-essential groups are auto-rejected without flashing the banner. The decision is logged withsource: 'gpc'. - Equal prominence. Accept and reject buttons on the first layer use equal visual weight. Customize stays secondary.
- Google June 2026 Consent Mode change.
ad_storageis denied by default until the marketing group is granted, so Google Ads data stays gated by the consent signal that now matters.
Not implemented: IAB TCF v2.2+. Add a dedicated TCF CMP if you sell ad inventory programmatically through real-time bidding.
Consent log
Every accept/reject/save decision is sent to:
It appends one JSON line per decision:
Fields:
versiongroupspagesitetimestampsource(explicitorgpc)ip_hash(SHA-256 of IP + app key, not raw IP)user_agent
Query examples:
The endpoint is CSRF-exempt because static-cached pages may not have a CSRF cookie to send. It is throttled at 60 requests/minute per IP. Prune or rotate old logs according to your retention policy.
JavaScript API
Styling
The banner and button use Shadow DOM. Style via parts:
Configuration
Published config lives at:
Important keys:
enabledversiontextpositionthemebuttongroupsconsent_mode
Floating preferences button
button controls {{ cookie_consent:button }}:
When the banner is open, the button hides automatically so it cannot overlap the dialog. Before first consent, it also stays hidden while the banner is visible.
License
Proprietary. See LICENSE.md.