Content Security Policy and consent
Content Security Policy
Section titled “Content Security Policy”If your site sends a Content-Security-Policy header, allow your tag host (tgmads.example.com,
or cdn.terramedia-sandbox.com before your CNAME is verified):
script-src https://tgmads.example.com;connect-src https://tgmads.example.com;frame-src https://tgmads.example.com;The one-line site tag needs no 'unsafe-inline'. With a nonce-based policy, add the nonce to the
<script> (the packages accept nonce). Ads render in sandboxed iframes on your tag host, load
their own images and fonts under their own policy, and never run script on your page.
Consent
Section titled “Consent”The tag checks, in order:
- Global Privacy Control: when it is on, nothing is loaded or requested.
- Your consent manager: c15t, IAB TCF v2.2, OneTrust or Termly, detected automatically. Ads load once the visitor allows advertising. Without a decision, the tag waits, so accepting later shows ads without a reload.
The tag drops one first-party cookie, _tgm_vid, on your tag host for frequency capping and local
geofencing. List it in your cookie policy.
