Skip to content
andrew.dunn.dev

Sveltia Identity Translator

Source

A translated-identity proxy for Sveltia CMS. Editors sign in with their existing identity provider (Google Workspace, Microsoft, Okta); a single service-account Personal Access Token at the git host holds the only credential that ever touches the API; commits attribute correctly to the editor via git’s author/committer split. Editors save changes without ever creating a GitLab account.

signs inbot tokenEDITORSveltia /admin/no git-host accountWORKERtranslatorOAuth, JWT, proxyGIT HOSTGitLab APIauthor = editor
Editors sign in with their own identity provider, the worker swaps that for one bot token at the git host, and the commit still lands with the editor as author.
TRANSLATOR (WORKER)API callsEDITORSveltia /admin/Workspace accountno git-host account1/oauth/authorize + /callbackverify hd claim, mint 24h JWT2JWT mint (HS256)sub, email, name; 24h expiry3/gitlab/* REST proxyJWT verify → allowlist → swapto PAT → inject author_*4/gitlab/graphqlread-only; mutations → 4035synthesized identity/user, /members/all/0 from JWTIDENTITY PROVIDERGoogle consentOAuth 2.0 + OIDChd: example.orgGIT HOSTGitLab api/v4single bot PATcommit:author = editorcommitter = bot
Five worker routes sit between the editor's browser and the git host, so the identity provider proves who is editing and one bot token makes every API call.

The default git-backed CMS auth model assumes a 1:1 mapping between editor and git-host user. For schools, nonprofits, and other small orgs whose editors live in their existing IdP and shouldn’t be onboarded onto another platform, that assumption breaks. The translator pattern keeps the git host out of the editor’s day entirely while preserving correct git history attribution.

Highlights

  • ~700 LOC TypeScript. Runs on Cloudflare Workers’ free tier.
  • Pluggable Authorizer hook; default impl loads from a YAML allowlist versioned in git.
  • 19-case smoke harness covering OAuth, JWT, REST, GraphQL, and allowlist enforcement.
  • Comprehensive setup walkthrough for Google OAuth, GitLab service account, Cloudflare deploy, and Sveltia config wiring.
  • MIT licensed. Built in collaboration with Andrew DeJong (@adejong5).

The full architectural reasoning, the load-bearing decisions, and the upstream contribution plan are in Enabling Editors to Use Git Without Knowing.