Version 5.0.2
October 7, 2026
Fixed
- The front-end runtime never ran. It is inlined into the page, and a comment in it contained a closing script tag, which ended the element early and left the rest as a syntax error — so the consent panel never appeared and no gated tag was ever released. The comment is reworded, and closing tags are now escaped whenever the runtime is inlined, so it cannot happen again.
- Consent was wrong on statically cached pages (Blitz, a CDN, Varnish). The panel, the tag
islands and
|tossGatewere rendered with the consent state of whichever visitor the page was first generated for, and the runtime trusted it — so everybody could be served one person's answer. Nothing about a visitor is rendered into the page any more: the runtime reads the visitor's own cookie, asks nobody when there is none, and otherwise resolves it once per session fromtoss/consent/state, which now sendsCache-Control: no-store, private. |tossGatenow always holds an embed back and lets the runtime release it, even when the visitor rendering the page has granted the category.
Changed
craft.toss.allows(),craft.toss.consent()andtossAllows()still read the current request, so their output must not be cached for other visitors. See Static caching in the usage docs.
Version 5.0.1
October 6, 2026
Custom script code is now admin-only: users with Manage cookie scripts and kits can still manage presets and a custom script's cookies, category and placement, but not its code. Clause overrides and custom sections are now cleaned before they are published. A policy published before this release keeps the HTML it was published with, so if anybody without admin rights has edited overrides or custom sections, recompile (
php craft toss/policies/compile) and republish those policies.
Security
- Clause overrides and custom sections were published as written, so a user with Create and
edit policies could put a
<script>or anonclickin a policy. It then ran for every admin who opened the policy editor, and for every reader of the published policy. People's own text is now cleaned when a policy is compiled, after placeholders are filled in, so links built from{{ … }}still work: no scripts, styles, forms, frames, event handlers orjavascript:links. The library's own clauses are left as they are. - Manage cookie scripts and kits could write custom script that runs on every page, in admins' sessions as readily as visitors'. Writing or changing custom code now needs an admin.
- A preset's parameters, such as a measurement ID, were substituted into its
<script>unchecked, so a quote in a value could break out into arbitrary JavaScript. Values are now limited to the characters vendor IDs use (letters, numbers and. _ : / -), checked on save. Any value stored earlier that doesn't fit renders as nothing.
Fixed
- The control panel's subnav offered every screen to everyone with access to Toss, so users without View and export acceptances got a 403 from the Acceptances link. Each item now appears only for users who can open it.