Skip to content
Back to skills

Web Log

ASecurity

How to use @owlmeans/web-log — the consent-gated analytics plugins for @owlmeans/log in a browser. gtmAnalyticsPlugin pushes `log` calls that carry an analytics option onto window.dataLayer for a tag manager, and only while analytics consent is granted (an event without consent is dropped, never queued); consentedAnalyticsPlugin is the same gate over any sender. Auto-invoked when sending analytics or tag-manager events from application code, importing gtmAnalyticsPlugin or consentedAnalyticsP...

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 6, 2026
datago

Security analysis

A100/100

Scanned October 6, 2026

npx -y skills add owlmeans/common --skill web-log --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Web Log?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Web Log
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/owlmeans-web-log/badge)](https://www.skillsdirectory.com/skills/owlmeans-web-log)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: web-log
description: How to use @owlmeans/web-log — the consent-gated analytics plugins for @owlmeans/log in a browser. gtmAnalyticsPlugin pushes `log` calls that carry an analytics option onto window.dataLayer for a tag manager, and only while analytics consent is granted (an event without consent is dropped, never queued); consentedAnalyticsPlugin is the same gate over any sender. Auto-invoked when sending analytics or tag-manager events from application code, importing gtmAnalyticsPlugin or consentedAnalyticsPlugin, or wiring a second analytics system next to GTM.
user-invocable: false
---

# @owlmeans/web-log

**Layer:** Web (depends on `@owlmeans/log` and `@owlmeans/consent`)
**Install:** `"@owlmeans/web-log": "^0.1.18-rc.2"` in `dependencies`

The browser half of "analytics are plugins" — see `/log` for the call parameters. A page logs a
business event once; which systems hear it is the set of plugins registered.

```ts
import { addLogPlugin, logger } from '@owlmeans/log'
import { gtmAnalyticsPlugin } from '@owlmeans/web-log'

addLogPlugin(gtmAnalyticsPlugin({ allow: ['project.created', 'sign_in'] }))   // once, at startup

logger('projects').info('Created', { kind: 'web' }, { analytics: 'project.created' })
// → window.dataLayer.push({ event: 'project.created', kind: 'web' }) — if analytics consent is granted
```

## Consent

`consentedAnalyticsPlugin(send, options)` sends only while `consentStore.granted(options.category ?? 'analytics')`
(`@owlmeans/consent`). **An event without consent is dropped, never queued**: a tag manager replays
everything already waiting in its queue when it loads, so a held event would be sent after a later
grant — in a window the visitor never agreed to be measured in. The load of the tag itself is gated
separately (`@owlmeans/web-gtm`'s `'basic'` mode); this gates the events.

| Option | Meaning |
|---|---|
| `name` | plugin name (a second plugin of the name replaces the first) |
| `category` | the consent category required; default analytics |
| `allow` | event names it sends; absent means all |
| `map(event)` | reshape the payload; return `undefined` to drop the event |

The default payload is `{ event, ...data }` (a non-object `data` becomes `value`). A second analytics
system is a second `consentedAnalyticsPlugin(send, { name })` — each plugin filters for itself.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…