Consent Gate and Classification Banners | Kamiwaza Docs

This is documentation for Kamiwaza 0.11.0, which is no longer actively maintained. For the current GA release, see 1.0.1.

Version: 0.11.0

What this provides

Public endpoints

These endpoints are intentionally public (no auth required) so they can be used before login.

Embedding the script

Add the following tag to any app that should mirror Kamiwaza's consent and banner behavior:

<script src="https://<gateway-host>/api/security/embed.js"></script>

The script:

Consent is tracked in session storage for the browser session and is also recorded server-side for audit logs.

Configuration

Environment variables

Set these in env.sh (or your deployment environment) and restart the services:

Variable Description Default
KAMIWAZA_SECURITY_CONSENT_ENABLED Enable the consent gate false
KAMIWAZA_SECURITY_CONSENT_BUTTON_LABEL Custom button label Accept
KAMIWAZA_SECURITY_BANNER_ENABLED Enable classification banners false
KAMIWAZA_SECURITY_BANNER_TOP_TEXT Text for the top banner (none)
KAMIWAZA_SECURITY_BANNER_TOP_COLOR Hex color for top banner (none)
KAMIWAZA_SECURITY_BANNER_BOTTOM_TEXT Text for the bottom banner Defaults to top text
KAMIWAZA_SECURITY_BANNER_BOTTOM_COLOR Hex color for bottom banner Defaults to top color

Consent content file

Consent HTML is loaded from:

$KAMIWAZA_ROOT/config/security/consent.html

If the file is missing, a default short message is used. You can start from the packaged example in config/security/consent-long.html in the platform repo and copy it to the path above.

Operational notes