Repository navigation
Replies: 2 comments
|
Sveltia CMS provides a few integration points: As you noticed, if you just want to use the GitHub API, you can use an access token stored in the local storage. However, authenticating and interacting with other services can be tricky, because Sveltia CMS works entirely in the frontend, and there is no straightforward way to hide API keys. Also, some integrations can’t be implemented due to CORS limitations. Sveltia CMS itself has hit this issue, so DeepL, GitHub PKCE auth and Git LFS are not currently available. GitHub Actions is probably the best way to interact with GitHub and external systems because you can hide API keys and other secrets. A quick example is VHAAntimicrobialStewardship.github.io, which is featured in our showcase and triggers GitHub Actions for every CMS commit. |
|
Thanks that showcase repo is very helpful. Will build an Action. |
Uh oh!
There was an error while loading. Please reload this page.
I am trying to get feedback on my idea below. I need to update an external system after I update content in Sveltia. One idea AI suggested was to use GitHub actions, but it seems a bit error prone and it's difficult to customize when exactly to execute the code. Another idea I thought about after reading the docs again, was to just use the Event Hooks in the Javascript API, which would give us a lot of control over when the external system is called (we can use if/else for different users etc). The thing is that I need to send an API request to the external system and then somehow need to authenticate it. I did notice that Sveltia stores the token in local storage (we are using GitHub PAT). So my idea is to get this token from localstorage in Javscript callback using the Event API, and then sending it as a header to the backend, then verifying this token on the backend. Is this a viable strategy? The backend will also be rate limited. Is this a viable and secure path?
All reactions