cl-cms editor is a separate server with an embedded React + TypeScript interface. People sign in with their git platform over OAuth with PKCE (Gitea, Forgejo, GitHub, GitLab, Bitbucket); the session is an AES-GCM sealed cookie, so the editor stores no accounts. Each person's checkout of a site is made with their own token, then built and checked; the interface lists their sites, a site's pages by collection, drafts, reviews and check results, and shows a page beside its live preview. The editor serves itself with a strict CSP, guards state changes against CSRF, and confines page reads to content/.
19 lines
590 B
TypeScript
19 lines
590 B
TypeScript
import { defineConfig } from 'vite'
|
|
import react from '@vitejs/plugin-react'
|
|
|
|
// The build goes straight into the Go package, which embeds it, so the
|
|
// editor ships as one binary. No inline scripts or styles are emitted: the
|
|
// editor serves itself with a strict Content-Security-Policy.
|
|
export default defineConfig({
|
|
plugins: [react()],
|
|
build: {
|
|
outDir: '../internal/editor/ui/dist',
|
|
emptyOutDir: true,
|
|
assetsInlineLimit: 0,
|
|
modulePreload: { polyfill: false },
|
|
},
|
|
server: {
|
|
proxy: { '/api': 'http://127.0.0.1:8190', '/auth': 'http://127.0.0.1:8190' },
|
|
},
|
|
})
|