Registro de cambios
Cambios en el runtime de consentimiento que se ejecuta en tu sitio web, por versión y fecha, desde que empezó el registro. Las entradas están escritas en inglés y se compilan a partir de archivos de versión controlados.
0.3.24
The consent runtime exposes bounded automation scores and records the Google Consent Mode update issued for each decision, including off and failed statuses. Capable newly published banners attach these fields to consent records and flag obvious automation in impression reports. Older published wrappers keep their existing payloads. Evidence describes what the banner sent, not confirmation that Google received or honoured it.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.24/cookiebeam-core.umd.min.js0.3.23
Published banner scripts no longer carry an A/B experiment saved in a theme's advanced configuration. Only a build for a running test's variant can include an experiment, so a leftover theme value can no longer apply a test's consent-model override to the default banner. Saving a theme now drops the value. Published banners are not automatically rebuilt.
0.3.22
Newly published banners with the Microsoft Advertising bridge send a UET consent default before any update: ad_storage is denied in opt-in regions, for visitors sending Global Privacy Control, and when inputs are missing, and follows the matched regional rule otherwise. Previously UET received only updates, so it treated ad_storage as granted until the visitor chose. Published banners are not automatically rebuilt.
0.3.21
Visitors whose Global Privacy Control signal was applied now see a confirmation without opening anything. For regional rules that honor GPC (the CCPA and US opt-out frameworks, hard opt-out rules, and visitors in US states that mandate GPC) a small, dismissible status notice reports that the opt-out request was honored. It does not reopen the banner for visitors who already made a choice, is announced as a status message, and follows the banner theme. The US opt-out panel now reports whether the signal was actually processed instead of whether the browser sent it, and names the rights it was and was not applied to under a per-right policy. The confirmation can be turned off or on per regional rule and reworded through the rule's translation overrides. Banners loading the shared latest core show it without republishing; banners with purposes enabled pin their core version and show it after a republish.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.21/cookiebeam-core.umd.min.js0.3.20
Global Privacy Control is now honored consistently for US visitors. Confirming the US opt-out panel no longer grants back categories the signal withheld at load, including on older saved US policies that map no category to sale and sharing; a deliberate opt-back-in to sale and sharing still re-allows that right's mapped categories, and an explicit Accept All keeps its existing behaviour. Categories a regional rule leaves out of scope are no longer auto-granted to a visitor whose privacy signal is honored or who opted out of the matching US right, on the banner and in hidden regions. When a regional rule matches a visitor in a US state whose law requires honoring GPC (California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon and Texas), the signal is honored even if the rule has no US opt-out framework and Respect GPC is off. Banners loading the shared latest core pick up the runtime change without republishing; banners with purposes enabled pin their core version and, like the hidden-region gate in the published script, change after a republish.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.20/cookiebeam-core.umd.min.js0.3.19
Google Consent Mode defaults follow the A/B experiment arm a visitor is actually served. When an arm applies a stricter consent model than the visitor's baseline region (for example opt-in where the region is otherwise opt-out), the baseline rule's granted defaults are withheld and ad and analytics storage stay denied until the visitor chooses. Banners without an applied experiment override are unchanged.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.19/cookiebeam-core.umd.min.js0.3.18
Newly published banners report drift observations without blanket sampling when the inventory manifest fails, times out, or is still pending at page exit. Existing client send budgets and server rate limits remain in place; available known-item baselines retain heartbeat sampling. Published banners are not automatically rebuilt.
0.3.17
Newly published banners use the shared inventory manifest instead of embedding duplicate known-item lists. Known observations retain heartbeat sampling; partial manifests still report genuinely new drift, and the scanner warns about incomplete default baselines. Sampling applies when no manifest is available, including page exit. Deployment requires the inventory-manifest refresh and cache-window rollout gates.
0.3.16
WordPress consent resynchronizes after delayed core initialization using the final runtime policy. Optional consent remains denied while core is unavailable; visitor choices and withdrawals take precedence over initialization defaults.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.16/cookiebeam-core.umd.min.js0.3.15
Fixes floating cookie settings icons collapsing on sites whose button CSS matches btn-- class fragments. Floating buttons now use cb-fab-pos-top-left, cb-fab-pos-top-right, cb-fab-pos-bottom-left and cb-fab-pos-bottom-right position classes, with stronger button resets and non-shrinking SVG icons. Customer CSS targeting cb-settings-btn--<position> must switch to cb-fab-pos-<position>; the cb-settings-btn base class and existing banner configuration remain unchanged. Higher specificity is limited to host-framework resets, so later customer rules on .cb-settings-btn can still customise border-radius, shadows and transitions. Temporary CSS-only aliases preserve positioning for cached older JavaScript and will be removed in a later release. After insertion, new JavaScript adds logical corner offsets inline only on axes left unpositioned by the stylesheet, keeping the button on-screen with cached older CSS. Current CSS needs no inline insets, and later customer rules such as .cb-settings-btn { bottom: 90px } still work. Fallback offsets use --cb-fb-offset and --cb-spacing-md. Direct background and border overrides on .cb-settings-btn now lose to the defensive resets: use --cb-fb-bg, --cb-fb-hover-bg and the new --cb-fb-border variable instead (or equally specific rules). Pending stylesheet load/error events and window load recheck temporary positioning, releasing inline fallbacks when CSS takes over. The button stays fixed on-screen while core CSS is pending, including for returning visitors.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.15/cookiebeam-core.umd.min.js0.3.14
New banner builds recognize historical regional preset text and use the current wording when an entire language block still matches a previous default. Customer-edited blocks remain unchanged. Uncustomized languages continue loading on demand, reducing stale inline copy without changing saved banner settings.
0.3.13
Newly published banner scripts reduce the public connection checklist and use compact data when it saves space. Published enforcement maps and purpose policies still use the complete inventory, and cached loaders receive the same decoded object format. Existing scripts need a rebuild to receive the size reduction.
0.3.12
Newly published banner scripts serialize regional settings once and reuse them for the early location check and core initialization. This reduces script size while preserving saved, automatic and disabled regional behavior. No core runtime version change is required; existing published scripts remain unchanged until republished.
0.3.11
Banner scripts published from this release carry a per-banner token on the consent log, impression, drift, load-order and enforcement-summary requests (a cbt query parameter, so no new headers or preflight requests). The server rejects a token that does not belong to the banner and still accepts requests without a token, so scripts published earlier keep working until they are republished. Drift items are promoted into the inventory only after they have been reported from several distinct networks. The core runtime itself is unchanged apart from its version.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.11/cookiebeam-core.umd.min.js0.3.10
Adds tolerant readers for optional per-right US GPC overrides and presentation-only category visibility. Existing consent signatures remain unchanged when fields are absent. Category records and events are never more permissive than purpose enforcement across consent actions, including hidden categories and legacy non-displayable entries. Both Reject All controls apply the same refusals, unrendered US controls do not create grants, and privacy-signal audit flags and acknowledgments follow the effective policy. No dashboard writer is enabled in this release. Published banners retain their existing snapshots until republished. Existing California GPC category denials remain unless applicable US rights explicitly override GPC. New US policies map marketing to sale/sharing; saved policies are not migrated. In purpose mode, categories outside regional scopedCategories no longer receive automatic category grants and require an allowed purpose decision (stricter behavior). Site acceptCategory and GTM updateConsent calls cannot create grants for hidden categories.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.10/cookiebeam-core.umd.min.js0.3.9
The US privacy panel initializes sensitive-data processing from its independent regional consent policy. New opt-in rules start unchecked unless a valid explicit grant exists; confirming unchanged choices cannot grant sensitive-data processing from a broadly allowed Functional category. Existing opt-out policies and banners without category consent retain their defaults.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.9/cookiebeam-core.umd.min.js0.3.8
Consent events can now carry the explicit visitor action (accept, reject, dismiss or custom) independently of the resulting category selection. Free-plan publications enforce the included design, language and regional settings while preserving saved drafts for future upgrades.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.8/cookiebeam-core.umd.min.js0.3.7
Published banners and outcome monitoring now resolve regional consent settings from the same published configuration, keeping expected banner behavior aligned with the settings delivered to visitors.
0.3.6
Site logos now use start, center or opposite-title placement. Box and cloud banners show a larger logo above the title; bars place it beside the title and stack it on mobile. Box and cloud banners place configured close controls alongside start/center logos or above opposite-title rows; bars retain their existing no-close behavior, and tight opposite-title rows fall back above the title. Preferences show the logo and close control in a divided header with the title in the body. Saved placements are mapped to the new options, and decorative watermark settings are ignored. The designer and website style suggestions use the same three placements. Old logo class names and data-cb-logo values remain on already-published banners, but switch to the new names (start/center/title-end) when a banner is next saved and published; custom CSS should target the new names.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.6/cookiebeam-core.umd.min.js0.3.5
Preferences now show only the purposes offered in the visitor’s region. Visitors outside the US no longer see inapplicable US privacy rights. Previously saved denials of inapplicable US privacy rights no longer block resources after the visitor allows the required category. Saved choices still apply wherever those purposes are offered, and US opt-out controls are unchanged.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.5/cookiebeam-core.umd.min.js0.3.4
Not published separately; shipped as part of 0.3.5. Banner owners can place their logo opposite the title, above it at the end, or as a faint decorative watermark behind the banner. The title placement keeps the banner height and falls back above the title on small screens or when there is no title. Watermarks take no layout space, never intercept clicks, and offer subtle or medium opacity and corner or centre placement. The preferences header keeps a small accessible logo. Existing logo placements are unchanged. Match my website includes the available logo in every suggested style and offers a Show logo checkbox for previews and saved themes. Owners can recapture their homepage inside the dialog and choose when to suggest styles again.
0.3.3
Banner owners can show consent choices as checkboxes instead of switches. The new Consent controls setting in the designer's Layout panel applies to every consent choice in the preferences panel (categories, services and purposes) and to the US opt-out panel. Checkboxes are real, labelled form controls that work with the keyboard like the switches and are announced to screen readers as checkboxes, take their colours from the existing switch colours so themes and dark mode keep matching, and show always-on categories as checked and disabled. Banners that never choose a style keep their switches. Services inside an always-on category, such as necessary, are now shown checked and disabled too, and are always recorded as accepted, even if a visitor unticks one.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.3/cookiebeam-core.umd.min.js0.3.2
Accessibility fixes for WCAG 2.2 AA. A banner that leaves the page usable is now announced as a non-modal dialog and no longer traps the Tab key; the preferences dialog and blocking banners still keep focus inside, and closing the preferences dialog returns focus to the button that opened it. Opening a dialog moves focus to the dialog itself so screen readers read its title and text, and the first-layer banner is described by its text. Consent toggles are announced as switches, and the switches in the US privacy choices panel and the purpose list, which were invisible, are now drawn like the other toggles; service checkboxes are visible again. The IAB TCF vendor rows no longer nest toggles inside a button (IAB TCF itself is built but not enabled in production). Links inside banner text are underlined, switch tracks have a ring in the body-text colour so they stay visible on pale presets, toggle hit areas are at least 24 pixels, small transitions stop when reduced motion is requested, and a right-to-left layout is used for regional codes such as ar-EG. The default off-toggle colour is now gray-500 (#6b7280), and the built-in dark mode uses dark button text on its cyan buttons so labels reach 4.5:1 contrast. Themes based on a dark preset now render their title, links and focus ring in the theme's text colour instead of the light default; this takes effect for an existing theme when it is saved and the banner is published again.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.2/cookiebeam-core.umd.min.js0.3.1
A banner logo can sit on a subtle plate when its main colour would otherwise disappear into the banner background, such as a white logo on a light banner. Match my website adds the plate only when the logo has less than 3:1 contrast with the banner, taking the plate colour from the banner background. Logos without a plate look exactly as before, and a site's own image styles no longer change the logo's size. Banner text now aligns to the start of the language's reading direction by default, so Arabic and Hebrew banners are right-aligned without a setting; an alignment an owner chose is kept. The banner's style reset now also covers list items, tables, bold text and h1 to h4 headings, so a site's own styles for those elements no longer change the banner. The centred preferences dialog can take a width from the theme; without one it keeps its current width. Text and spacing in the preferences and US privacy panels now size from the banner's own base font size instead of the site's root font size, so a site with a small root size no longer shrinks them; body and legal text never goes below 12px. At the default size they look exactly as before.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.1/cookiebeam-core.umd.min.js0.3.0
Banners can show the site's logo. Owners can use the logo detected on their homepage or upload their own (PNG, JPEG, WebP, or SVG, up to 200 KB; SVG files are cleaned of scripts and external references), then choose its placement (top left, top center, or beside the text) and size (small, medium, or large). The logo is served from the CookieBeam CDN, never loaded from the customer's site, appears in the banner and in the preferences header, uses the site name as alternative text unless the owner sets one, and stacks above the text on small screens so the buttons stay visible. When the logo is off, the banner creates no image and makes no extra request.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.3.0/cookiebeam-core.umd.min.js0.2.0
Adds optional regional consent purposes for scripts, connections, cookies, and browser storage. Site owners can maintain a purpose catalog, declare the uses of each resource, preview regional decisions, and publish changes together. Every required purpose must allow a resource; independent US opt-outs and respected privacy signals remain restrictive. Published policies use versioned visitor choices and a compatible core runtime, with safe rollback and stale-choice handling. Existing banners keep their current behavior until purpose enforcement is explicitly enabled and published. While the runtime loads, only purpose-assigned resources wait, and they fall back to the visitor's stored choice if the runtime cannot start. A visitor whose location cannot be determined keeps the region recorded with their choice. Loaders only include the purpose evaluator for banners that use purposes.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.2.0/cookiebeam-core.umd.min.js0.1.1
Consent withdrawal now reaches vendor integrations and denial-only scripts. Banner button clicks produce one consent action. Ads data redaction is sent as a Google setting rather than a consent type. Shared core compatibility events use a version handshake with generated banners. US privacy choices use a separate overlay and close cleanly after confirmation. Presentation updates reject malformed patches without mutation and preserve omitted nested options; policy and adapter changes require runtime reinitialization. Publishing stages the full asset set before activating pointers and compensates failed uploads or database activation, while dashboard visibility choices retain explicit false values.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.1.1/cookiebeam-core.umd.min.js0.1.0
Baseline: the cookiebeam-core consent runtime as of this changelog's introduction. Earlier runtime changes are not enumerated; every subsequent runtime-affecting change is recorded from here.
Artefacto inmutable:
https://cdn.cookiebeam.com/lib/core/0.1.0/cookiebeam-core.umd.min.js