Skip to main content

Astro Scripts and embeds

Network blocker

What the network blocker does

networkBlocker stops fetch and XMLHttpRequest calls that match a rule until the visitor allows the rule's category. A blocked fetch resolves to a 451 response, and nothing is sent. It covers requests that code already on the page makes, such as an SDK you load yourself or a tag manager's own calls.

It does not stop navigator.sendBeacon, WebSockets, image pixels, <script> tags or iframes. Load scripts through c15t and gate iframes as Scripts and Embeds describe.

Add rules

Rules are plain data, so they can go in the integration options:

astro.config.mjs (partial)
c15t({
	networkBlocker: {
		rules: [
			{ category: 'measurement', domain: 'google-analytics.com' },
			{
				category: 'marketing',
				domain: 'ads.example.com',
				pathIncludes: '/collect',
				methods: ['POST'],
			},
		],
	},
});
Rule fieldEffect
categoryThe category that must be allowed for the request to go through
domainThe host to match. It also matches every subdomain
pathIncludesMatches only URLs whose path contains this text
methodsMatches only these HTTP methods
vendorAlso requires this vendor to be allowed, for vendor-level consent
OptionDefaultEffect
rulesRequiredThe rules to apply
enabledtrueSet false to keep the rules but stop blocking
logBlockedRequeststrueLogs each blocked request to the console. Set false to silence it

The blocker starts with the consent runtime, from a module script. A request made before that, such as from an inline script at the top of <head>, is not blocked.

Log or report blocked requests

onRequestBlocked is a function, so it cannot go in astro.config.mjs. Set networkBlocker in the default export of your client entrypoint instead. It replaces the integration's networkBlocker completely, so repeat the rules there:

src/consent-client.ts (partial)
export default {
	scripts,
	networkBlocker: {
		rules: [{ category: 'measurement', domain: 'google-analytics.com' }],
		onRequestBlocked: ({ url, rule }) => {
			console.info('Blocked until consent:', url, rule?.category);
		},
	},
} satisfies C15tClientOptionsExtension;

Check the network blocker

  1. Open the site in a private window with DevTools Network open, and trigger the code that calls a blocked host. The request does not appear, and a fetch receives a 451 response.
  2. Allow the rule's category. The next request to that host goes through.
  3. Withdraw the category and save. After the reload, requests to the host are blocked again.