Skip to content

feat: configure from Content Sync and filter scopes by permission - #8

Merged
andresvillenas merged 1 commit into
mainfrom
feat/reuse-content-sync-settings
Oct 1, 2026
Merged

andresvillenas merged 1 commit into
mainfrom
feat/reuse-content-sync-settings

Conversation

@andresvillenas

Copy link
Copy Markdown
Collaborator

Fixes the setup and security gaps found in the foundation design review: the toolkit now takes all of its connection settings from Xperience's Content Sync, and the admin page shows only the channels and workspaces the signed-in user can access.

Changes

  • Content Sync's settings only (breaking).
    • Before: the toolkit had its own TargetUrl, Secret and Enabled settings, so installers configured a second URL and secret, and the comparison could point at a different instance than the one Content Sync pushes to.
    • Now: the target URL, shared secret and each instance's role come from ContentSynchronizationOptions (ContentSynchronization:Source / :Target). An instance is a toolkit source exactly when it's a Content Sync source, and answers inventory requests exactly when it's a Content Sync target. Only RequestTimeout and InventoryCacheDuration remain toolkit options.
    • The new IContentSyncToolkitSettings resolves the settings once; the HTTP client, the secret validator and the admin page's "not configured" check all read it.
    • The "not configured" banner points to Content Sync's source settings.
  • Permission-aware lists. The channel and workspace dropdowns are filtered for the signed-in user:
    • website channels: administrators, or roles with View on the channel's Pages application;
    • workspaces: Content hub View in the workspace (IWorkspacePermissionEvaluator).
  • No caching of inventory responses. The controller sends Cache-Control: no-store. Cloudflare, which fronts SaaS, wouldn't cache this route by default, but secret-gated responses must never come from a shared cache.
  • SaaS. Kentico configures Content Sync automatically for SaaS from Xperience Portal connections. Decompiling Kentico.Xperience.Cloud 31.7.2 shows AddKenticoCloud binds ContentSynchronizationOptions from the CMSContentSynchronization section the platform provides, so the toolkit picks up the same settings. Documented in the foundation spec.
  • Docs.
    • Usage Guide: nothing toolkit-specific to configure; Content Sync settings table; channel and workspace filtering under "Give editors access".
    • Contributing Setup: a single rig flow with ContentSynchronization__* variables only.
    • Architecture: new decision "A complement to Content Sync, configured by it".
    • Foundation and admin page specs: configuration, SaaS, security and scope filtering.

Upgrading

Remove any ContentSyncToolkit:TargetUrl, :Secret and :Enabled settings and configure Content Sync instead (which a toolkit installation needs anyway).

Testing

  • 191 unit tests pass (new: settings resolution from Content Sync, scope services registered per request, the channel application identifier, the no-store attribute).
  • Verified live on 31.7.2 with only ContentSynchronization__* variables on both rig instances:
    • the target answered the Content Sync secret with 200 (with Cache-Control: no-store,no-cache) and any other secret with 404;
    • both tabs loaded without the banner; a source started without Content Sync showed the new banner;
    • the administrator saw all three workspaces; a test editor with access to two saw only those two.
  • Not verified: a real SaaS environment (the contents of the platform's configuration section, and whether the SaaS edge lets the inventory requests through). Kept as a pre-release check.

Make the toolkit a complement to Xperience's Content Sync, configured
only by it, and show editors only what they can access.

- Remove the toolkit's own TargetUrl, Secret and Enabled settings. The
  target URL, shared secret and each instance's role come from
  ContentSynchronizationOptions, so the comparison always targets the
  instance Content Sync pushes to and nothing is configured twice. Only
  RequestTimeout and InventoryCacheDuration remain toolkit options.
- The "not configured" banner now points to Content Sync's source
  settings.
- Filter the admin page's channel and workspace lists by the signed-in
  user's permissions: website channels by View on the channel's
  application (or administrator), workspaces by Content hub View in the
  workspace.
- Mark inventory responses Cache-Control: no-store, so a shared cache
  such as the SaaS CDN never serves them.
- Document the SaaS behavior: AddKenticoCloud binds
  ContentSynchronizationOptions from the configuration Xperience Portal
  provides, so the same settings apply there.
- Update the Usage Guide, Contributing Setup, Architecture and specs.
@andresvillenas
andresvillenas merged commit e74cf59 into main Oct 1, 2026
3 checks passed
@andresvillenas
andresvillenas deleted the feat/reuse-content-sync-settings branch October 1, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant