Repository navigation
feat: configure from Content Sync and filter scopes by permission - #8
Merged
Merged
Conversation
Make the toolkit a complement to Xperience's Content Sync, configured only by it, and show editors only what they can access. - Remove the toolkit's own TargetUrl, Secret and Enabled settings. The target URL, shared secret and each instance's role come from ContentSynchronizationOptions, so the comparison always targets the instance Content Sync pushes to and nothing is configured twice. Only RequestTimeout and InventoryCacheDuration remain toolkit options. - The "not configured" banner now points to Content Sync's source settings. - Filter the admin page's channel and workspace lists by the signed-in user's permissions: website channels by View on the channel's application (or administrator), workspaces by Content hub View in the workspace. - Mark inventory responses Cache-Control: no-store, so a shared cache such as the SaaS CDN never serves them. - Document the SaaS behavior: AddKenticoCloud binds ContentSynchronizationOptions from the configuration Xperience Portal provides, so the same settings apply there. - Update the Usage Guide, Contributing Setup, Architecture and specs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the setup and security gaps found in the foundation design review: the toolkit now takes all of its connection settings from Xperience's Content Sync, and the admin page shows only the channels and workspaces the signed-in user can access.
Changes
TargetUrl,SecretandEnabledsettings, so installers configured a second URL and secret, and the comparison could point at a different instance than the one Content Sync pushes to.ContentSynchronizationOptions(ContentSynchronization:Source/:Target). An instance is a toolkit source exactly when it's a Content Sync source, and answers inventory requests exactly when it's a Content Sync target. OnlyRequestTimeoutandInventoryCacheDurationremain toolkit options.IContentSyncToolkitSettingsresolves the settings once; the HTTP client, the secret validator and the admin page's "not configured" check all read it.IWorkspacePermissionEvaluator).Cache-Control: no-store. Cloudflare, which fronts SaaS, wouldn't cache this route by default, but secret-gated responses must never come from a shared cache.Kentico.Xperience.Cloud31.7.2 showsAddKenticoCloudbindsContentSynchronizationOptionsfrom theCMSContentSynchronizationsection the platform provides, so the toolkit picks up the same settings. Documented in the foundation spec.ContentSynchronization__*variables only.Upgrading
Remove any
ContentSyncToolkit:TargetUrl,:Secretand:Enabledsettings and configure Content Sync instead (which a toolkit installation needs anyway).Testing
ContentSynchronization__*variables on both rig instances:200(withCache-Control: no-store,no-cache) and any other secret with404;